DeFi Attacker Drains $72K from MALT's Treasury via Flawed Swap Function
DeFi attacker exploits MALT protocol's flawed swap function, draining $72,000 from its treasury. The exploit targeted the DAI supplied by MALT's treasury, allowing the attacker to extract funds from the protocol.
SlowMist reported that the flaw affected MALT's swap(uint256,uint256,address) function, which records the trader's input and pool reserves before calling an external rebalancing function. This allowed the attacker to provide only a small amount while benefiting from protocol-funded liquidity.
The exploit follows several recent attacks targeting DeFi projects, including a $3.8 million loss at NEAR Intents due to a bug in its Omni deposit and withdrawal infrastructure interaction with its smart contract.