Float Protocol exploited for $28k through Uniswap V3 spot price manipulation via flash loans.
Security & Exploits ·
Float Protocol suffered an exploit resulting in approximately $28,000 in losses after attackers manipulated Uniswap V3 spot pricing through flash loans. Security researchers identified the attack and traced the attacker address to 0xaea29218262dc6b0904ca077f6527c49dfd426d9, with the attack contract at 0xb46655eb5b77de277063a75586d1883e951b6c54.
The vulnerability stemmed from Hypervisor contracts that lacked validation against oracle manipulation. Attackers exploited this by executing large swaps on the Uniswap V3 pool to distort the slot0 price feed, then repeatedly deposited and withdrew liquidity using artificially inflated share values. The critical functions involved in LP share pricing did not incorporate TWAP checks or slippage protections against such spot price distortions.
The attack demonstrates a recurring pattern: protocols relying on real-time Uniswap V3 prices without oracles or time-weighted averages remain vulnerable to flash loan manipulation. Float Protocol's Hypervisor contracts—including addresses 0x85cbed523459b7f6f81c11e710df969703a8a70c and 0xc86b1e7fa86834cac1468937cdd53ba3ccbc1153—appear to have lacked these standard safeguards, leaving them susceptible to exploitation.