SingularityFinance.ai vault on Base exploited for ~$413K via invalid Uniswap V3 oracle fee tier configuration that broke reserve pricing.
Security & Exploits ·
SingularityFinance.ai's dynBaseUSDCv3 vault on Base suffered an estimated $413K loss on April 26, 2026, after an oracle misconfiguration enabled share inflation and fund drainage. The vault prices non-USDC reserves through a Uniswap V3 oracle, but on January 19, 2026, the protocol admin registered six yield-token oracle routes using an invalid Uniswap V3 fee tier of 42—a value outside the protocol's supported tiers of 100, 500, 3000, and 10000. This misconfiguration caused all direct price lookups to fail silently, returning null pool addresses, while fallback WETH pools contained zero liquidity, leaving the vault's pricing mechanism to count only approximately $100 of idle USDC in total reserves.
An attacker exploited this broken pricing by flash-loaning 100,000 USDC from Morpho, depositing the sum into the vault to mint roughly 99.99% of the vault's token supply at the artificially depressed exchange rate. The attacker then redeemed those tokens, receiving a proportional share of the vault's actual underlying yield token balances independent of the oracle's valuation, effectively draining the assets.
The project announced that a detailed post-mortem would follow. The transaction has been documented on-chain, and the incident remains under preliminary research with official findings pending.