Incident case file
Sign in to watchHaedal Vault — Cross-Version AUM Mismatch Exploit
2 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: Attacker address 1 (SUI-USDC vault): 0xbcec4942fe70bbadc211137c617517fcb1d28fba023b78a7e352152b1fd8438e Attacker address 2 (SUI-DEEP, SUI-WAL, SUI-CETUS, SUI-LBTC, ETH-USDC vaults): 0x15dc1cc8b53774559fb04babc01f91ee540d3a0a928e2135416474cc16b386c1 206 related transactions across both addresses.
Timeline: On June 9, 2026, two attackers exploited a cross-version logic inconsistency in Haedal Vault's LP share minting mechanism across six vault pools on Sui. The root cause was a forced upgrade gap: when Haedal published the v3 Vault package on December 23, 2025, older deposit entrypoints were not fully deprecated and remained callable. The v1/v2 deposit path used an understated AUM calculation for CLMM/DLMM liquidity positions, causing it to mint more LP shares than the actual deposited value warranted. The v3 withdrawal path, however, redeemed LP shares against the Vault's real underlying assets. By depositing through the old path and withdrawing through the new one, the attackers received a larger share of real assets than they deposited. The two addresses executed 206 total transactions across the six affected pools. Total direct loss: $915,179.68 across USDC, SUI, CETUS, DEEP, WAL, LBTC, and ETH. Haedal detected the unusual liquidity decline, paused vault contracts before further deterioration, and published a full post-mortem the same day. All losses will be covered by Haedal Foundation reserves. A patched version is under development and will undergo re-audit before deployment.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)