Float Protocol Hit by $28K Flash Loan Attack via Uniswap V3 Manipulation
Float Protocol has been hit by a flash loan attack that exploited vulnerabilities in its Hypervisor contracts. The attack, which occurred on August 31, resulted in losses of approximately $28,000 or 10.71 ETH. According to SlowMist, the attacker manipulated the Uniswap V3 spot price using large swaps, causing affected Hypervisor contracts to calculate incorrect LP share values.
The attacker repeatedly deposited and withdrew funds from the affected contracts, taking advantage of the inflated share values. The attack highlighted a critical weakness in Float Protocol's contracts, which relied on a manipulable spot price without adequate checks or validation. SlowMist noted that the absence of TWAP (time-weighted average price) or oracle verification allowed the attacker to distort the Uniswap V3 pool's slot0 value.
The incident is not an isolated case, with several other DeFi attacks in recent months exploiting similar vulnerabilities. In July, Allbridge Core was hit by a $1.12 million USDC flash loan attack that caused approximately $1.65 million in losses. The Float Protocol attack serves as a reminder of the importance of robust security measures and proper validation in DeFi contracts.