A DeFi attacker drained about $72,000 from MALT after exploiting a flaw in the protocol’s swap function, security firm SlowMist reported.
The attacker used a small amount of input to trigger the faulty swap. They then received more MALT than the transaction should have allowed. SlowMist said the exploit involved DAI supplied by MALT’s treasury, allowing the attacker to extract funds from the protocol.
Swap Flaw Lets Attacker Tap Treasury Funds
SlowMist said the flaw affected MALT’s swap(uint256,uint256,address) function. The function recorded the trader’s input and pool reserves before calling an external rebalancing function.
Related: Bitget Rebuilds $300M+ Protection Fund, Withdrawals Resumed
That function then withdrew DAI from MALT’s Capital Source and returned it to the pool. Consequently, the swap treated the treasury-funded DAI as trader-supplied funds during its validity check.
This allowed the attacker to provide only a small amount while benefiting from protocol-funded liquidity. Moreover, the flaw failed to separate user funds from capital added during rebalancing.
MALT Exploit Adds to DeFi Losses
The MALT exploit follows several recent attacks targeting DeFi projects. NEAR Intents halted services after an Oct. 1 exploit caused about $3.8 million in losses.The team said it fixed the contract flaw and would fully compensate affected users.
Separately, a FlashLoopAdapter exploit drained about $305,000 from two Safe wallets using Aave V3 positions. However, the attack targeted the custom module rather than Aave V3’s core contracts.
DeFi hacks have caused more than $21 billion in losses, according to the DeFiLlama data. About $9.28 billion came from DeFi protocols, while bridges accounted for $3.69 billion.
Related: Blast Announces Shutdown With October 26 Withdrawal Deadline
Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.