RedSonic Vault Flaw Allows Thief to Steal ETH with No Upfront Capital
An attacker exploited a flaw in Ethereum's RedSonic Vault to steal 9.25 ETH, using a flash loan from Balancer that required no initial capital.
The exploit involved inflating the share price of a second asset class by registering it as having the same underlying collateral as the first one, via a permissionless function.
The attack was carried out with a 1,139 WETH flash loan from Balancer, which was repaid within the same transaction. This incident highlights vulnerabilities in DeFi protocols relying on raw balance pricing and unrestricted asset registration.