Renegade protocol exploited for $53.2K USDC via nullifier hash vulnerability; team requests return of $41.1K user funds within 24 hours or faces legal action.
Security & Exploits ·
On August 27, 2026, a bot transferred 53,174.448409 USDC from a Renegade protocol pool, according to an onchain message sent from a Harmony One Protocol address. Of that amount, 41,125.32 USDC belonged to users and 12,049.128409 USDC represented protocol fees. The Renegade team attributed the incident to a vulnerability in the protocol's nullifier hash structure that allowed the contract to accept an invalid or fake hash.
The team formally requested return of the 41,125.32 USDC in user funds to a designated recovery address, while offering the 12,049.128409 USDC in protocol fees as a bounty to the exploiter for identifying the issue. A 24-hour deadline was set for response and fund return, with the team stating it would pursue lawful and formal actions if the request went unmet.
It remains unclear whether the exploiter has responded to the request, whether any funds have been returned, or what further steps the Renegade team may have taken beyond the initial deadline.