A vulnerability in TokenWorks’ Fake World Assets (FWA) protocol has allowed an attacker to manipulate an NFT purchase, prompting the team to suspend trading activity and compensate the owner of the affected asset.
According to TokenWorks founder Adam, the exploit involved front-running a Chainlink callback that determined which NFT would be selected from a pooled collection. While the randomness generated by Chainlink itself was not compromised, the attacker reportedly altered the protocol’s state before the callback was finalized, causing the selection to point to CryptoPunk #5450, the highest-value NFT in the pool.
The attacker acquired the CryptoPunk for roughly $66,000 worth of Ether, after which the protocol was immediately placed into withdraw-only mode at block 25452023. The team also took snapshots of FWA token holders, preventing further purchases while allowing depositors to recover their assets.
TokenWorks Pauses Protocol After Exploit
Adam said TokenWorks has contacted the owner of CryptoPunk #5450 and will cover the full ETH loss associated with the incident. He added that the team will spend the coming days investigating the exploit before deciding whether the protocol can safely continue or requires a relaunch.
The incident highlights a recurring challenge in decentralized application design: even when external randomness functions as intended, vulnerabilities can emerge if protocol state can change before that randomness is applied. In this case, the exploit centered on execution timing rather than a failure of Chainlink’s verifiable randomness infrastructure.
TokenWorks has become known for releasing experimental on-chain products that often feature unconventional token mechanics. Several previous launches, including Top Blaster, Cabalcoin, CTO, and Ten Thousand Token, were followed by public post-mortems documenting technical issues or design shortcomings. One notable exception was PunkStrategy, which attracted stronger adoption despite exposing predictable on-chain trading signals.
Although TokenWorks has publicly documented both successful and unsuccessful launches, the incident underscores the risks users face when interacting with early-stage smart contracts, even when developers commit to making affected participants whole after unexpected failures.
READ MORE: Worldcoin Price Breaks Multi-Week Downtrend as Buyers Regain Control