Reddio exploited for approximately 9.25 ETH due to a cross-vault asset double-counting vulnerability.
Security & Exploits ·
Reddio suffered a loss of approximately 9.25 ETH through an exploit targeting a vulnerability in its vault architecture. The attack leveraged a flaw in which stETH deposits registered in a permissionless vault were simultaneously counted within the ETH vault's asset balance calculation, allowing the same stETH to collateralize two separate derivative tokens.
An attacker executed a flash loan transaction to deposit stETH, artificially inflating the share price of one derivative token, then redeemed it for excess ETH. The same stETH was subsequently redeemed again through the second derivative token layer, completing the double-spend. A 2% withdrawal cap in place on the protocol proved insufficient to block the manipulation sequence, leaving both vaults exposed to the attack vector.
The attacker's address and the affected vault implementation addresses have been identified on-chain. Whether additional safeguards have been deployed or whether further funds remain at risk remains unclear.