Juicebox's REVLoans contract exploited via unverified terminal logic, resulting in ~21.77 ETH ($51.9K) drained from revnet #3 treasury.
Security & Exploits ·
Juicebox's REVLoans contract, an add-on that permits token holders to borrow against their holdings, suffered a logic vulnerability that exposed roughly 21.77 ETH (approximately $51.9K) from revnet #3's treasury. The vulnerability centered on the borrowFrom function, which accepted a caller-supplied terminal reference without verifying it was actually registered to the revnet, allowing a fraudulent terminal contract to be injected into the borrowing process.
An MEV bot exploited this gap by front-running legitimate borrowing calls with its own borrowFrom invocations using a fake terminal and minimal collateral, successfully draining funds from the treasury. The victim contract and attacker's counterfeit terminal remain publicly visible on-chain, documenting the attack path.
What remains unclear is whether the Juicebox team has issued a patch, whether other revnets faced similar exposure, and the full scope of losses beyond revnet #3. A whitehat bounty message was also recorded on-chain, but its contents and any compensation offered have not been disclosed in available reporting.