Vulcan Forged
On December 13, 2021, attackers drained roughly $140 million in PYR, ETH, and MATIC from wallets tied to Vulcan Forged, a Polygon-based NFT gaming platform, according to CoinDesk and Rekt.news. The attacker obtained the private keys of 96 wallets, most belonging to large investors and long-time holders; early reports cited 148 compromised addresses before the figure was revised down (Quadriga Initiative). The stolen 4.5 million PYR — about 9% of circulating supply — pushed the token's price down 20-34% within hours.
How the attack worked
Vulcan Forged relied on Venly (then Arkane Network) to run "MyVulcan," a semi-custodial wallet layer: Venly held users' private keys while the platform's own PIN system controlled access to them. Quadriga Initiative's write-up notes that the key-export requests originated from Vulcan Forged's own IP addresses rather than from Venly's infrastructure — meaning someone with legitimate backend access either intercepted user PINs or reused compromised credentials to pull keys for 96 wallets. That is why our classification reads Private Key Compromised with an unspecified method: the team never publicly confirmed whether this was an external server breach, malware on an employee's machine, or an inside job. Technically nothing was exploited on-chain — no contract bug, no oracle manipulation — the keys themselves were taken out of custody.
What happened next
Vulcan Forged's response was unusually fast: reimbursements in PYR and LAVA from the project treasury started the same night, and by the next morning the team had committed to covering ETH and MATIC losses too, paid out in PYR equivalent (CryptoTimes). This was not a recovery in the usual sense — the attacker never returned anything, and while some flagged addresses were reportedly frozen by exchanges, the stolen funds themselves were not clawed back. The $140 million reimbursement came entirely out of Vulcan Forged's own reserves rather than from the hacker. No arrests or legal proceedings have been publicly reported. Following the incident, the team announced it would move away from Venly's semi-custodial model toward fully non-custodial wallets.
What this means
- The failure point was infrastructure, not a smart contract: a semi-custodial wallet layer where keys nominally belong to the user but are stored and exported through a third-party service creates a single point of failure for hundreds of addresses at once.
- Users had almost no way to see this risk coming — a PIN instead of a seed phrase reads like a convenience feature, but it means compromising one backend compromises every linked wallet simultaneously.
- A fast, full treasury-funded reimbursement is rare and only possible with sufficiently large, liquid reserves; for most projects of comparable size, a loss this size would mean insolvency, not compensation.
- The unresolved "unknown method" is itself a signal: years later Vulcan Forged still hasn't disclosed the exact vector (insider vs. external breach), meaning the same weakness could persist unaddressed in other integrations using the same custody model.
Sources
- Gaming Platform Vulcan Forged Refunds Users After $140M Hack — CoinDesk ↗
- Vulcan Forged Rekt — Rekt.news ↗
- Dec 2021 - Vulcan Forged Venly Wallets Breached - $140m (Global) — Quadriga Initiative ↗
- NFT Marketplace Vulcan Forged Lost $140 Million in Hack — CryptoTimes ↗
Sources checked 07.08.2026
On-chain DeFi carries smart-contract risk. Keep core funds on a regulated exchange.