Float Protocol Hit by $28K Flash Loan Attack Through Uniswap V3 Manipulation
A recent flash loan attack on Float Protocol exploited vulnerabilities in its Hypervisor contracts, causing an estimated loss of $28,000. The attackers manipulated Uniswap V3's spot price to distort currentTick() and getTotalAmounts(), allowing them to calculate inflated LP share values.
The exploit relied on large trades that changed the ratio of assets within a pool, creating temporary liquidity for arbitrage or liquidations. However, this same mechanism can be used against vulnerable DeFi applications.
SlowMist identified missing price checks in Float Protocol's contracts as part of the attack path. The absence of TWAP or oracle validation allowed the attackers to manipulate prices without detection.