Incident case file
Sign in to watchChi Protocol — ArbitrageV5 burn() Peg Check Bypass (Flash Loan)
0 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: Attacker EOA: 0xF7105F68085294B6A45DD7231A6987b070E1AbaF (funded 0.1 ETH from Tornado.Cash 5 days pre-attack). Helper contract 1: 0x2da918cfef4b52adfcd154141955341de395d33a (Created in exploit tx). Helper contract 2: 0xc97dfc27769cb0ac8266b301c935cb492c75668c.
Timeline: July 3, 2026 (~5 days pre-attack): attacker EOA 0xF7105F68... funded 0.1 ETH from Tornado.Cash. July 8, 2026 block 25520523: attacker deploys 2 helper contracts (0x2da918cf... and 0xc97dfc27...) and executes a single atomic exploit tx 0x4a665f8e... The exploit chain in one transaction: flash loan 5 WETH from Balancer Vault → buy 17,342 USC on the illiquid Uniswap V2 USC 9 pool at ~$0.29 per USC (heavily depegged vs $1 target) → 3 burn cycles against Chi Protocol's ReserveHolder 0xc36303ef... redeeming full-value collateral (1.712 weETH + 2.820 stETH + 3.898 WETH totaling ~$15,860) → LST-to-WETH swaps via Uniswap V3 weETH 2 and Lido Curve Farming Pool → repayment of 5 WETH flash loan to Balancer → net profit 4.663 WETH (~$8,597) to attacker EOA. Root cause verbatim (@DefimonAlerts, powered by Decurity + SlowMist AI): 'Chi Protocol's ArbitrageV5.burn() redeems reserve collateral valuing USC at the hardcoded USC_TARGET_PRICE ($1) — reserveAmountToRedeem = amount * $1 / reservePrice — with NO check that USC is actually at peg (unlike mint(), which enforces _almostEqualAbs(uscSpotPrice, USC_TARGET_PRICE)). The attacker flash-loaned 5 WETH from Balancer, bought heavily-depegged USC cheaply from a thin USC/WETH Uniswap V2 pool, then burned it 1:1 against the ReserveHolder to redeem full-value weETH/stETH/WETH collateral, netting ~4.66 WETH. Note: reserves are nearly drained (protocol TVL ~$883), so remaining opportunity is limited.' Vector class: asymmetric mint/burn logic — burn() did not verify USC was at peg while mint() did. July 9, 2026 (day after the exploit): attacker unwraps WETH to ETH via Approve + Withdraw, then executes 11 consecutive Tornado.Cash Router deposits in a few minutes (4× 1 ETH + 7× 0.1 ETH = 4.7 ETH fully laundered). Attacker EOA balance drops to ~0.0288 ETH (~$53). July 13, 2026: DefimonAlerts publishes the full technical breakdown on X — public disclosure of the incident. SlowMist Hacked database lists Chi Protocol with the July 13 date (disclosure date convention, aligned with the tier-1 tracker ecosystem). Post-incident: Chi Protocol residual TVL ~$883, protocol effectively dead — Reserves nearly fully drained, no restart planned. Note on date convention: on-chain exploit occurred July 8, but public disclosure occurred July 13 — this radar entry uses the disclosure date consistent with SlowMist Hacked and other tier-1 trackers. Small absolute damage ($8,597) but the incident is included because the damage-to-reserves ratio is nearly 100% — a textbook 'small exploit, dead protocol' case study of asymmetric mint/burn peg check vulnerabilities.
Sources and coverage
- Articlex.comhttps://x.com/DefimonAlerts
- Articleetherscan.iohttps://etherscan.io/tx/0x4a665f8eeada74552bd2dc466e5549731951f2f6180bbe865fa1d7b4be8ae96f
- Articleetherscan.iohttps://etherscan.io/address/0xF7105F68085294B6A45DD7231A6987b070E1AbaF
- Articleetherscan.iohttps://etherscan.io/address/0xc36303ef9c780292755b5a9593bfa8c1a7817e2a
- Articleetherscan.iohttps://etherscan.io/address/0x594f4983df88c3d84caa6eb30c18fba1986ed6f1
- Articlehacked.slowmist.iohttps://hacked.slowmist.io/
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)