Incident case file
Sign in to watchReddio RedSonic Vault Double-Counting Exploit — $22.8K Loss
0 views
Estimated loss
Affected users
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
1 beatOn September 5, 2026, an attacker exploited two chained vulnerabilities in Reddio's RedSonic Vault on Ethereum. First, the permissionless registerErc20() function allowed anyone to register a new asset class; the attacker registered stETH as a second share class (rsvstETH). Second, the vault's share-price calculation read raw token balances rather than tracking backing per share class, so the same underlying stETH balance was counted toward both rsvETH and rsvstETH shares simultaneously. The attacker flash-loaned 1,139 WETH from Balancer with zero starting capital, deposited to acquire roughly 99% of outstanding rsvETH shares, inflated the share price via the double-counting bug, redeemed at the inflated rate, repaid the flash loan, and kept the difference — a total of 9.252513 ETH (~$22,800), representing the entirety of the vault's holdings. The exploit contract self-destructed at the end of execution to complicate later forensic review. As of the last check, the stolen ETH remains unmoved in the attacker's wallet, and no team statement on recovery or compensation has been made public.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)