A random raffle meant to be fair turned out to be hijackable - not by hacking the random number generator itself, but by front-running the final seconds before the outcome was locked in. That is what happened to the TokenWorks protocol earlier this July, when an attacker managed to “win” CryptoPunk #5450, the most valuable asset in the raffle pool, worth around $66,000 or over Rp1 billion.
Not a Chainlink Breach, but the Seconds Before the Callback
TokenWorks operates a product called Fake World Assets (FWA), an NFT pool that uses Chainlink VRF (Verifiable Random Function) to select raffle winners randomly and verifiably. The problem was not with Chainlink’s random generator itself - the VRF operated as designed. What was exploited was the timing gap between when the random number request was sent and when its callback was actually executed on-chain.
The attacker leveraged that window of time to alter the protocol’s state before the callback was finalized, effectively “shifting” the selection mechanism to point to CryptoPunk #5450 - the most expensive item in the pool - instead of the intended random result. “It looks like there was a way to front-run the Chainlink callback, which allowed the attacker to shift which NFT was selected,” said Adam, co-founder of TokenWorks, confirming the findings.
Withdraw-Only Mode, Compensation, and Ongoing Investigation
As soon as the anomaly was detected, the TokenWorks team immediately halted trading activity and locked the protocol into withdraw-only mode at block 25,452,023 - meaning users could only withdraw funds and could not buy or sell. The team also took a snapshot of FWA token holders to prevent follow-up purchases while ensuring all depositor funds could be safely withdrawn.
TokenWorks then contacted the legitimate owner of CryptoPunk #5450 directly and pledged to fully cover the ETH losses resulting from the incident. The protocol is currently undergoing an internal investigation to decide whether FWA can resume with a security patch or must be rebuilt from scratch.
Lessons for NFT Raffle-Based Protocols
This case serves as a reminder that “random” on the blockchain does not automatically mean “secure” - vulnerabilities can arise not from the algorithm itself, but from how the protocol handles the time delay before random results are locked in. For NFT participants in similar raffle pools, the TokenWorks incident highlights the importance of comprehensive audits on the logic surrounding oracles, not just the oracle itself.
Reported by BanklessTimes.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




