Royal suffered a $260K exploit via a legacy smart contract; the team committed to full reimbursement.
Security & Exploits ·
Royal experienced a $260,000 drain of unclaimed royalties from a legacy smart contract deployed approximately five years ago, extracted by what the team characterized as a malicious agent. The organization stated it intends to fully reimburse affected parties and invited those who believe they were impacted to contact royalties@royal.io to report unclaimed amounts owed to them.
The team emphasized that the compromise was isolated to the older contract and involved no cross-contamination with Royal products released after its V1 iteration. The incident was framed as underscoring the importance of security practices in crypto environments, with the organization pledging continued commitment to system hardening as agent sophistication increases.
What remains unclear is the scope of actual affected users, the timeline for reimbursement execution, and whether a formal audit or investigation into the exploit's mechanics will be disclosed.