At 22:14 UTC on April 18, 2026, the NovaPlay master treasury contract on Polygon executed an upgrade transaction. Forty-two minutes later, every USDT NovaPlay had ever held — $4.2 million across three rate-limited withdrawal paths — was passing through a single Tornado Cash deposit.1 NovaPlay had been rated Listed by Onyx eight months earlier, with a score of 68. This piece is a forensic reconstruction of those 42 minutes, an examination of how the rating came to be wrong, and an explanation of what our methodology will change as a result.
The wallets that initiated the withdrawal — 0x4f2a…, 0x9d2a…, and 0xb441… — were not, on April 18, anonymous to NovaPlay's team. All three were listed in the published treasury registry. All three had legitimate operational reasons to hold balances. The exploit, if it can be called that, was not an exploit of the contract logic. The contract logic worked. The exploit was that the same person could move all three.
The 42 minutes
What follows is reconstructed from the on-chain transaction log, a partial set of internal Discord messages obtained from a former NovaPlay engineer2, and direct correspondence with two of the three named treasury signers — both of whom have stated unequivocally that they did not authorize the April 18 transactions and were not consulted on them.
UpgradeProposed + UpgradeExecutedBlock 19,924,418The first thing to note about the timing: under NovaPlay's own published governance documentation, treasury upgrades were subject to a 72-hour timelock. The April 18 upgrade was both proposed and executed in the same block, twenty-six seconds after the proposal transaction was mined. This was technically possible because the timelock was implemented as a frontend check in the governance dashboard, not as a contract-level constraint. Anyone calling the contract directly could bypass it. This was disclosed nowhere.
A reader familiar with our methodology will recognize this as a failure mode we score for — specifically, the Multi-sig & key management sub-criterion under Security (worth 4 of 25 points). NovaPlay had been awarded 3 of 4 points there. The 1 point we withheld reflected a noted concern about signer concentration. We did not catch that the published timelock was unenforced. That is on us.
The Halborn audit, revisited
NovaPlay's last audit, by Halborn in October 2025, covered the master treasury contract. The report — public, and good — flagged the timelock-as-frontend-check pattern as a "design observation, low severity." Halborn's recommendation was straightforward: enforce the timelock at the contract layer. NovaPlay marked the finding as "accepted, scheduled for v3.1." V3.1 was scheduled for Q2 2026. April 18 happened in Q2 2026, but before V3.1 shipped.
What does this teach us about the methodology? Two things. First: a "low severity" audit finding that affects governance enforceability should be treated as higher severity than the audit firm rated it.3 Audit firms are not in a position to assess organizational follow-through on findings; we are. Second: an accepted-but-unshipped finding should expire from credit if the proposed remediation date passes. We were giving NovaPlay credit for shipping a fix they had not shipped.
The project page, before and after
The rating was revoked on May 19 — five days before this piece was published, and one month after the events it documents. Removal, in the Onyx methodology, is the most severe action available; under Section 13 of the methodology document, it precludes re-rating under any version, including by a successor entity using shared infrastructure. The reason cited was team-identity falsification, not the exit itself.4 The exit, on its own, would have warranted downgrade and watchlist; the identity falsification is what made the rating itself a misleading signal.
What the methodology will change
The Q3 2026 methodology release will include three changes, drafted in response to this case and one other that will be published later this quarter:
One. All published timelocks must be contract-enforceable and tested under direct-call conditions to receive credit under Security/Multi-sig. Frontend-only timelocks will receive zero credit and a flag in the methodology report.
Two. Accepted audit findings with a project-stated remediation date that has passed will expire from credit on the date of the missed deadline, not on the date of next audit.
Three. Treasury signer identity verification will be lifted from a documentary check to a contemporaneous one: every quarter, we will independently re-contact the named treasury signers via an out-of-band channel and confirm continued affiliation with the project. The two signers who repudiated the NovaPlay transactions, when contacted, had not been employed by NovaPlay for over fourteen months. They had been listed in our public registry the entire time.
None of these changes recover the $4.2M. They are not meant to. They are meant to mean that the NovaPlay rating, which existed for eight months on this site with our name attached to it, is the last rating to be wrong in this particular way.
The harder question
There is a question this piece has not addressed and should: is independent ratings a sufficient defense against this category of failure, or do credibility platforms like ours create the false-confidence environment that makes failures like this possible? I have a view, and it is too long for this piece. We will publish it as a follow-up.5
What is settled is that NovaPlay was rated by Onyx for eight months, that the rating was wrong in ways the methodology did not catch, and that we are publishing this account so that the next person evaluating a similar project knows what to look for. That is the bargain. We will not always be right. We will always show our working.