Float Protocol Hit with $28K Loss from Flash Loan Attack Exploiting Uniswap V3
Float Protocol has fallen victim to a flash loan attack that exploited Uniswap V3 price manipulation, resulting in a loss of $28,000. The attacker manipulated the spot price to calculate inflated liquidity provider (LP) share values using Float's Hypervisor contracts.
The lack of time-weighted average price (TWAP) or oracle verification and slippage protection in critical contract functions allowed the attacker to distort the pool's current price and repeatedly deposit and withdraw funds based on incorrect LP share values.
This incident highlights vulnerabilities in DeFi protocols that rely on spot prices without robust price checks, underscoring the need for improved security measures to prevent similar exploits.