# "smart contract" (exploit OR hacked OR drained) — X 热门讨论 (2026-09-23 12:15 UTC)

## @PastaBeanFras (FM) · 09-22 19:59 · ♥22 ↻6 💬0 1. Justin, MultiversX core developer Robert Sasu has now explained the bug. Per Sasu, it happened inside a single shard: a state save that wasn't reverted when a later error check failed. A reentrancy flaw in execution order.

Let's hold that up against your "clear explanation."

2. You wrote that this was "a direct consequence of the shortcuts they had to make to bring a sharded chain down to 600ms."

You wrote that sharding splits transfers into a debit and a credit, and "on one path the credit had no debit." Per the person who wrote the code, none of that was involved.

3. You also said this was "clearly a consequence of decoupling execution from consensus! A unique feature of EGLD's design."

A missing revert after an error check is one of the oldest bug classes in smart contract execution. Ethereum contracts have been drained by exactly this pattern for a decade. There's nothing unique about it, and it has nothing to do with consensus.

4. So your thread's central thesis, that EGLD's design is "flawed & reckless" and caused this, rests on a root cause you invented before anyone who could see the code had spoken.

You didn't analyze the bug. You assumed it matched the narrative you already had.

5. The halt: per Sasu, validators coordinated through an emergency channel and each decided to stop. That's the same mechanism Solana has used to restart its network repeatedly.

You called this "highly improbable." It's routine.

6. The fair questions remain, and I'll keep asking them: how much invalid state was created, what did the attacker actually extract, and why did the initial disclosure say so little. The team owes a full report, and it should be thorough.

7. But "the team should disclose more" was never your thread. Your thread was that EGLD's architecture is reckless and caused a collapse. The architecture didn't cause it.

8. 14 years of experience should include waiting for the post-mortem before writing the verdict. Next time, ask the people who can read the code before telling your audience you already know.

You should issue a retraction at the same level of public visibility as your flawed critique. https://x.com/PastaBeanFras/status/2102487898197008690