dTRINITY exploited for $257K due to rounding vulnerability in Aave v3 fork's cbBTC aToken math; similar flaw affected HypurrFi in March.
Security & Exploits ·
dTRINITY's dLEND pool, an Aave v3 fork, suffered a $257K exploit due to a rounding vulnerability in its cbBTC aToken math. The attacker used flash loans to deposit approximately $772 USDC valued as $4.8M in collateral, borrowed $257K dUSD, and then executed 127 deposit and withdrawal cycles through a helper contract. Each cycle extracted slightly more cbBTC than was deposited, ultimately netting roughly $257K after gas costs despite the pool's total value locked being only around $435K.
The vulnerability stems from identical half-up rounding logic applied to both mint and burn operations in the aToken share math. At high liquidity indices, this allowed withdrawals to exceed deposits. The underlying issue appears to parallel a structural rounding flaw affecting Aave v3 versions prior to 3.5, which HypurrFi publicly disclosed on March 5 following its own exploitation through the same pattern.
The exploit's feasibility depends on three conditions: high per-unit token price, low decimals, and low gas fees—all of which apply to cbBTC. It remains unclear whether dLEND was running a patched version of Aave v3 or had remained vulnerable despite the publicly known issue surfacing just 12 days prior.