In section Cryptocurrency

Float Protocol loses $28,000 in Uniswap V3 flash loan exploit

Float Protocol suffered a $28,000 loss after an attacker leveraged a flash loan to manipulate Uniswap V3 spot prices. By distorting liquidity pool data, the exploiter tricked Hypervisor contracts into calculating inflated share values, allowing for a series of profitable deposit and withdrawal cycles within a single transaction.

Float Protocol loses $28,000 in Uniswap V3 flash loan exploit

The security firm SlowMist identified the vulnerability as a failure in the protocol’s price verification logic. The affected Hypervisor contracts relied on the Uniswap V3 slot0 spot price without implementing time-weighted average price (TWAP) checks, external oracles, or basic slippage protection. This oversight allowed the attacker to use large swaps to artificially shift the pool's tick information, creating a temporary pricing discrepancy.

Once the pool state was distorted, the attacker exploited the flawed calculations for LP share values, repeatedly draining funds through a sequence of deposits and withdrawals. The security firm traced the activity to address 0xaea29218262dc6b0904ca077f6527c49dfd426d9, noting that the exploit specifically targeted two vulnerable contracts, 0x85cbed523459b7f6f81c11e710df969703a8a70c and 0xc86b1e7fa86834cac1468937cdd53ba3ccbc1153. The incident underscores a recurring trend in decentralized finance, where attackers utilize flash loans to provide the massive capital required to force price movements that trigger vulnerabilities in unshielded smart contract logic.

Share:on TelegramXFacebook

Subscribe to our newsletter

Once a week — the best stories from our editors, no ads or push notifications. Delivered Sunday morning.

Comments (0)

Leave a comment

No comments yet. Be the first!