PaymentProcessor v2 sender-spoofing exploit drains 0.7724 WETH from victim wallet; attacker offered whitehat resolution with 72-hour deadline.
Security & Exploits ·
An on-chain message posted to mainnet Ethereum alleges that 0.7724 WETH was extracted from wallet 0x0946bC5c2F9848665CC3811458De403d0A78AD8E through a PaymentProcessor v2 sender-spoofing exploit. The account claims the funds were taken without authorization and has offered a settlement: return of 0.6565 WETH (85% of the amount) within 72 hours, with the remaining 0.1159 WETH (15%) treated as a whitehat bounty.
The message frames the offer as a resolution alternative to litigation or legal reporting. The sender set a 72-hour deadline, after which they indicate intent to escalate the matter to law enforcement and pursue on-chain attribution if no response is received. The funds are allegedly held at address 0xcccc640018f8c2b00fa45f456017ad2378eb3447 on mainnet.
What remains unclear is whether the exploit represents a flaw in PaymentProcessor v2's code, the mechanism that enabled sender-address spoofing, or whether the attacker will respond to the settlement offer. No independent confirmation of the vulnerability or the transaction's legitimacy has been provided.