Arrakis Finance's deprecated 2021 legacy vault was exploited via spot-price manipulation for ~2.94 WETH; current Arrakis Pro products unaffected.
Security & Exploits ·
Arrakis Finance's V1 legacy vault, a Uniswap V3 liquidity-manager contract tied to the ENS–WETH pair, was exploited via spot-price manipulation, allowing an attacker to extract approximately 2.94 WETH in a single transaction. The vault lacked safeguards on its mint and burn functions against instantaneous pool price distortion; while the contract included a time-weighted average price check for manager rebalances, that protection did not extend to user deposits and withdrawals.
The attacker executed a permissionless flash-loan sequence: borrowing 1,800 WETH from Morpho Blue, swapping roughly 145 WETH for ENS to artificially shift the pool's tick, depositing into the vault at the skewed valuation, reversing the price move, and then redeeming shares for a token mix richer than the initial deposit. The entire operation required no special access or privileges.
The exploit targeted only the deprecated 2021 vault; Arrakis Pro products remain unaffected. The affected vault contract and attacker address are publicly visible on-chain, but broader details about the scope of user exposure or remediation steps have not yet been disclosed.