NFT lending platform Gondi is working to compensate users after a smart contract exploit resulted in the theft of digital collectibles valued at roughly $230,000. The security breach was linked to a recently deployed update to the platform’s Sell & Repay contract, which is designed to allow borrowers to sell escrowed NFTs and automatically repay loans in a single bundled transaction.
According to the platform, a new contract version released on February 20 introduced faulty logic in the “Purchase Bundler” function. The flaw reportedly failed to properly verify whether the caller interacting with the contract was the legitimate owner or borrower of the NFT involved in the transaction.
Blockchain records from Etherscan show that around 78 NFTs were drained through approximately 40 transactions to a wallet now identified as the GONDI Exploiter address.
Stolen NFTs Included High-Value Collections
The stolen assets included multiple well-known digital collectibles such as 44 tokens from Art Blocks, 10 items from Doodles, and two pieces from Beeple’s Spring Collection. One collector reportedly lost around 55 ETH during the exploit, valued at more than $100,000 at the time.
Following the incident, the platform temporarily disabled the Sell & Repay feature while developers worked on a fix. Other marketplace activities, including lending, trading, listing and bidding, remained unaffected throughout the event.
Platform Begins Compensation and Recovery Efforts
The team behind Gondi has started reaching out to affected users and taking steps to restore losses. In several cases, NFTs purchased by buyers who were unaware of the exploit have been tracked and returned to their original owners.
For assets that cannot be recovered, the protocol has begun using platform fees to purchase comparable NFTs from similar collections as compensation. Discussions are also ongoing with collectors who lost unique one-of-one pieces.
Security firms and independent auditors have since reviewed the protocol as the platform works to restore confidence among users and resume normal operations.
Disclaimer
This content is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency trading involves risk and may result in financial loss.

