← Radar

Incident case file

Sign in to watch

Reddio RedSonic Vault Double-Counting Exploit — $22.8K Loss

Incident date Sep 4, 2026Last updated Sep 24, 2026

0 views

ContainedEthereumCollateral double-counting / flash loan exploitCluster: REDDIO-ETH-2026-09

Estimated loss

$22.8K

Affected users

1
Group joining is coming soon.

Investigation

85%

Facts and investigation

Ledger

Attacker

0x70f2333d21Ed7E7D105F6578227A9A747687982C

Funds moved to

9.252513 ETH remained in the attacker's wallet as of the last check; Etherscan used this exploit as its own public demo case for its new 'Etherscan Flow' transaction-tracing tool.

Linked

Attacker: 0x70f2333d21Ed7E7D105F6578227A9A747687982C. RedSonic Vault contract: 0x4315990d9eeaffdfafd49958b4851f203fa1126f.

Chronology

1 beat
  1. On September 5, 2026, an attacker exploited two chained vulnerabilities in Reddio's RedSonic Vault on Ethereum. First, the permissionless registerErc20() function allowed anyone to register a new asset class; the attacker registered stETH as a second share class (rsvstETH). Second, the vault's share-price calculation read raw token balances rather than tracking backing per share class, so the same underlying stETH balance was counted toward both rsvETH and rsvstETH shares simultaneously. The attacker flash-loaned 1,139 WETH from Balancer with zero starting capital, deposited to acquire roughly 99% of outstanding rsvETH shares, inflated the share price via the double-counting bug, redeemed at the inflated rate, repaid the flash loan, and kept the difference — a total of 9.252513 ETH (~$22,800), representing the entirety of the vault's holdings. The exploit contract self-destructed at the end of execution to complicate later forensic review. As of the last check, the stolen ETH remains unmoved in the attacker's wallet, and no team statement on recovery or compensation has been made public.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)