Incident case file
Sign in to watchFloat Protocol Flash Loan Hypervisor Attack — $28K Loss
0 views
Estimated loss
Affected users
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
1 beatOn August 31, 2026, an attacker used a flash loan to manipulate the Uniswap V3 spot price (slot0) feeding Float Protocol's Hypervisor contracts, which lacked TWAP or oracle validation and slippage protection. Using large swaps to distort currentTick() and getTotalAmounts(), the attacker caused the Hypervisor contracts to calculate inflated LP share values, then repeatedly deposited and withdrew against the incorrect valuation, extracting approximately $28,000 (10.71 ETH). The attacker's wallet received the funds directly from the attack contract and moved 10 ETH into Tornado Cash Router within minutes of the exploit. The remaining balance was later diversified across five chains (Base, Ethereum, Robinhood Chain, BNB Chain, Arc), totaling roughly $18,799 as last observed. The underlying Hypervisor framework had experienced a similar spot-price exploit in January 2024, and Gamma Strategies had previously published mitigation guidance that Float Protocol's contracts did not incorporate.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)