Vault4626 ERC-4626 yield vault drained via double-payment logic error in WETH redemption across Base and Arbitrum, totaling ~34 WETH ($53K).
Security & Exploits ·
Vault4626, a custom ERC-4626 Uniswap V3 liquidity provider yield vault, lost approximately 34 WETH (roughly $53,000) across three vault instances deployed on Base and Arbitrum due to a logic error in its redemption mechanism. The vulnerability allowed redemption to double-pay the WETH component of the underlying liquidity position, effectively releasing both a quoted value in USDC and the actual WETH tokens simultaneously.
The attack exploited the contract's redemption logic by flash-loaning 1.755 million USDC via Morpho and 12.92 WETH via Balancer. The attacker deposited the borrowed USDC to acquire nearly all shares of a vault worth approximately $10,000, then donated the WETH to inflate the idle balance that would be paid out twice. Upon redemption, the attacker drained the entire Uniswap V3 position held by the vault, extracting roughly 23 WETH on Base and approximately 10.7 WETH on Arbitrum.
The root cause stemmed from the redeem() function calling convertToAssets() to establish redemption value—which already computed the WETH leg in USDC terms via time-weighted average price—while a subsequent step transferred the actual WETH tokens, bypassing the deduplication. The exact number of affected users or total value locked in the affected vault prior to the exploit remains unclear from available reports.