Guru.fund delegated fund-management protocol on Ethereum exploited for $96K via whitelisted deposit adapter vulnerability that allowed vault self-drainage.
Security & Exploits ·
Guru.fund, a delegated fund-management protocol on Ethereum, suffered a $96,000 loss on July 24, 2026, when attackers exploited a whitelisted deposit adapter to force vaults into approving their own drainage. The incident unfolded across seven transactions, with attackers realizing roughly $61,500 while targeting eight of the protocol's sixteen active funds over approximately 85 minutes. Real-time detection flagged the first drain while most protocol value remained recoverable, but a pause came 67 minutes later when only dust was left.
The protocol's architecture enabled the flaw: Guru.fund routes all fund operations through a shared controller, meaning a vulnerability in any deposit mechanism affects every fund simultaneously. The permissionless deposit function accepts externally supplied calls executed through whitelisted adapters, including one at address 0x5e0234 that permits arbitrary token approvals. Attackers deposited minimal amounts, leveraged this adapter to grant themselves unlimited allowance over vault holdings, then transferred the assets out after deposit confirmation.
A secondary adapter enabled the attack's mechanics: a Uniswap V2 wrapper deposited dust quantities that bypassed minimum-amount validation checks. Whether Guru.fund has recovered funds, patched the vulnerability, or compensated affected users remains undisclosed. The team received notification via Telegram but provided no immediate public response.