← Radar

Incident case file

Sign in to watch

Float Protocol Flash Loan Hypervisor Attack — $28K Loss

Incident date Aug 30, 2026Last updated Sep 24, 2026

0 views

ContainedEthereumFlash loan / spot-price oracle manipulationCluster: FLOAT-ETH-2026-08

Estimated loss

$28K

Affected users

1
Group joining is coming soon.

Investigation

90%

Facts and investigation

Ledger

Attacker

0xAEA29218262dc6b0904Ca077f6527C49dfd426D9

Funds moved to

10.71 ETH received directly from the attack contract, of which 10 ETH was moved to Tornado Cash Router within minutes. Remaining balance diversified across Base, Ethereum, Robinhood Chain, BNB Chain and Arc (~$18,799 total as last observed).

Linked

Attacker: 0xAEA29218262dc6b0904Ca077f6527C49dfd426D9. Attack contract: 0xb46655Eb5b77De277063A75586D1883E951B6C54.

Chronology

1 beat
  1. On August 31, 2026, an attacker used a flash loan to manipulate the Uniswap V3 spot price (slot0) feeding Float Protocol's Hypervisor contracts, which lacked TWAP or oracle validation and slippage protection. Using large swaps to distort currentTick() and getTotalAmounts(), the attacker caused the Hypervisor contracts to calculate inflated LP share values, then repeatedly deposited and withdrew against the incorrect valuation, extracting approximately $28,000 (10.71 ETH). The attacker's wallet received the funds directly from the attack contract and moved 10 ETH into Tornado Cash Router within minutes of the exploit. The remaining balance was later diversified across five chains (Base, Ethereum, Robinhood Chain, BNB Chain, Arc), totaling roughly $18,799 as last observed. The underlying Hypervisor framework had experienced a similar spot-price exploit in January 2024, and Gamma Strategies had previously published mitigation guidance that Float Protocol's contracts did not incorporate.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)