BanklessTimes
TokenWorks Hacked
Home Articles Chainlink Callback Exploit Hits TokenWorks, CryptoPunk Lost

Chainlink Callback Exploit Hits TokenWorks, CryptoPunk Lost

Crispus Nyaga
Crispus Nyaga
Crispus Nyaga
Author:
Crispus Nyaga
Writer
Crispus is a financial analyst with over 9 years in the industry. He covers cryptocurrencies, forex, equities, and commodities for some of the leading brands. He is also a passionate trader who operates his family account. Crispus lives in Nairobi with his wife and son.
Updated: July 3rd, 2026
Editor:
Joseph Alalade
Joseph Alalade
Editor:
Joseph Alalade
News Lead and Editor
Joseph is a content writer and editor who has actively participated in crypto for over 6 years. He enjoys educating others about Web3 and covering its updates, regulatory developments, and exciting stories.
Fact Checker:
Joseph Alalade
Joseph Alalade
Fact Checker:
Joseph Alalade
News Lead and Editor
Joseph is a content writer and editor who has actively participated in crypto for over 6 years. He enjoys educating others about Web3 and covering its updates, regulatory developments, and exciting stories.

A vulnerability in TokenWorks’ Fake World Assets (FWA) protocol has allowed an attacker to manipulate an NFT purchase, prompting the team to suspend trading activity and compensate the owner of the affected asset.

According to TokenWorks founder Adam, the exploit involved front-running a Chainlink callback that determined which NFT would be selected from a pooled collection. While the randomness generated by Chainlink itself was not compromised, the attacker reportedly altered the protocol’s state before the callback was finalized, causing the selection to point to CryptoPunk #5450, the highest-value NFT in the pool.

The attacker acquired the CryptoPunk for roughly $66,000 worth of Ether, after which the protocol was immediately placed into withdraw-only mode at block 25452023. The team also took snapshots of FWA token holders, preventing further purchases while allowing depositors to recover their assets.

TokenWorks Pauses Protocol After Exploit

Adam said TokenWorks has contacted the owner of CryptoPunk #5450 and will cover the full ETH loss associated with the incident. He added that the team will spend the coming days investigating the exploit before deciding whether the protocol can safely continue or requires a relaunch.

The incident highlights a recurring challenge in decentralized application design: even when external randomness functions as intended, vulnerabilities can emerge if protocol state can change before that randomness is applied. In this case, the exploit centered on execution timing rather than a failure of Chainlink’s verifiable randomness infrastructure.

TokenWorks has become known for releasing experimental on-chain products that often feature unconventional token mechanics. Several previous launches, including Top Blaster, Cabalcoin, CTO, and Ten Thousand Token, were followed by public post-mortems documenting technical issues or design shortcomings. One notable exception was PunkStrategy, which attracted stronger adoption despite exposing predictable on-chain trading signals.

Although TokenWorks has publicly documented both successful and unsuccessful launches, the incident underscores the risks users face when interacting with early-stage smart contracts, even when developers commit to making affected participants whole after unexpected failures.

READ MORE: Worldcoin Price Breaks Multi-Week Downtrend as Buyers Regain Control

Follow Bankless Times on Google News

We`ve got crypto covered – every trend, every insight, every move that matters. Add us to your feed and stay ahead of the market.

Contributors

Crispus Nyaga
Writer
Crispus is a financial analyst with over 9 years in the industry. He covers cryptocurrencies, forex, equities, and commodities for some of the leading brands. He is also a passionate trader who operates his family account. Crispus lives in Nairobi with his wife and son.