← Radar

Incident case file

Sign in to watch

ether.fi Liquid AtomicQueue Missing Access Control — $38.1K, Fully Reimbursed

Incident date Sep 10, 2026Last updated Sep 24, 2026

0 views

ResolvedEthereumMissing access control (solver check)Cluster: ETHERFI-LIQUID-2026-09

Estimated loss

$38.1K

Affected users

11
Group joining is coming soon.

Investigation

100%

Facts and investigation

Ledger

Attacker

TODO

Funds moved to

Extracted via forced solver role abuse in the legacy AtomicQueue contract; all 11 affected users were fully reimbursed by the protocol.

Linked

Legacy AtomicQueue contract (Veda-based, deprecated). Copycat attempts also observed on Arbitrum. Attacker address not publicly disclosed.

Chronology

1 beat
  1. On September 11, 2026, an attacker exploited a missing access control check in the solve() function of a legacy AtomicQueue contract used by ether.fi's Liquid product (built on the Veda framework). The function failed to verify that the caller (solver) matched the expected msg.sender, allowing the attacker to force already-approved addresses to act as solvers and drain funds via transferFrom. Approximately 15.45 ETH (~$38,130 on mainnet, with a wider ~$43,260 figure including copycat attempts on Arbitrum) was extracted, affecting 11 users, several using EIP-7702 smart wallets. SlowMist conducted responsible disclosure prior to public reporting. All affected users were fully reimbursed by the protocol.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)