← Radar

Incident case file

Sign in to watch

Atomic Green — Uniswap V3 LP Signature Replay Exploit

Incident date 2026-08-07Last updated Aug 20, 2026

1 views

ContainedArbitrumSmart contract exploit — Signature replayCluster: ATG-SIG-2026-08

Estimated loss

$30.0K

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

50%

Facts and investigation

Ledger

Attacker

0xf8803DaE13A6757E53711214769B5fb52Ec26C7E (EOA — confirmed Arbiscan; funded pre-attack from 0x93900a94...7f05ae49e with 0.01867 ETH at block 492090819)

Funds moved to

MISSING — 29,984.27 USDC received by attacker EOA from attack contract (tx 0xbd4a009c..., block 492104035). Three subsequent USDC OUT transfers (blocks 492104707, 492105627, 492106103) visible on Arbiscan but final destination not publicly traced. Manual recovery: https://arbiscan.io/address/0xf8803DaE13A6757E53711214769B5fb52Ec26C7E — Token Transfers tab — filter Aug 8 2026.

Linked

Attacker EOA: 0xf8803DaE13A6757E53711214769B5fb52Ec26C7E | Attack contract (deployed by attacker): 0x44d2D34E148e1Da5c4291C110f6ff0E472037255 | Exploit tx: 0xbd4a009cd609a05f1a64458969a1e2c2065472f0ee06a322246f155be12e3a9a (block 492104035, Arbitrum — confirmed Arbiscan) | Victim business proxy: 0x51fF48f2d43966bE796692BdDdfaE96A435242a8 | Vulnerable logic contract: 0x62cc552215303341f9651e89db40e7336a394a0a | Position Manager Proxy (victim): 0xf617a3ad1f0ab9d9fe39e48d688bfe44562769d9 | Deploy

Chronology

6 beats
  1. August 8, 2026 — Atomic Green, a non-custodial leveraged trading protocol on Arbitrum, was drained of 29,984.27 USDC via a signature replay attack combined with a flashloan price manipulation.

  2. Pre-attack staging: Attacker EOA (0xf8803DaE...) funded with 0.01867 ETH from 0x93900a94...7f05ae49e at block 492090819. Attack contract (0x44d2D34E...) deployed at block 492103439 (tx 0xf1a61ec6...).

  3. T0 — Block 492104035 (exact UTC not published publicly): Single-transaction exploit executed (tx 0xbd4a009c...). The attacker flash-borrowed ARB tokens via Aave V3, manipulated the spot price of the ARB/USDC Uniswap V3 pool, then replayed the same manager signature across 21 distinct LP position IDs. The signed digest lacked binding for position ID, position manager address, caller, nonce, deadline, and chain ID — making a single valid signature reusable against every LP position. The replayed signature authorized unauthorized partialBurn calls on each of the 21 positions. ARB profit was swapped to USDC: 29,984.27 USDC extracted to the attack contract, then transferred to attacker EOA.

  4. Post-exploit: Three USDC OUT transfers from attacker EOA recorded at blocks 492104707, 492105627, 492106103. Destination of final cash-out not publicly traced.

  5. Alerts: SlowMist_Team and SolidityScan published technical alerts on August 8, 2026. Media coverage by KuCoin News, PricePredictions, Coinfomania, RootData, and Binance Square on August 8–9.

  6. No official post-mortem from Atomic Green. No recovery or bounty announced. No patch commit confirmed publicly.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)