The security firm SlowMist identified the vulnerability as a failure in the protocol’s price verification logic. The affected Hypervisor contracts relied on the Uniswap V3 slot0 spot price without implementing time-weighted average price (TWAP) checks, external oracles, or basic slippage protection. This oversight allowed the attacker to use large swaps to artificially shift the pool's tick information, creating a temporary pricing discrepancy.
Once the pool state was distorted, the attacker exploited the flawed calculations for LP share values, repeatedly draining funds through a sequence of deposits and withdrawals. The security firm traced the activity to address 0xaea29218262dc6b0904ca077f6527c49dfd426d9, noting that the exploit specifically targeted two vulnerable contracts, 0x85cbed523459b7f6f81c11e710df969703a8a70c and 0xc86b1e7fa86834cac1468937cdd53ba3ccbc1153. The incident underscores a recurring trend in decentralized finance, where attackers utilize flash loans to provide the massive capital required to force price movements that trigger vulnerabilities in unshielded smart contract logic.

Comments (0)
No comments yet. Be the first!