← Radar

Incident case file

Sign in to watch

Spiral (SpiralCom) SpiralHookV2 Oracle Manipulation — $26.8K

Incident date Sep 13, 2026Last updated Sep 24, 2026

0 views

ContainedEthereumSpot-price oracle manipulation (Uniswap V4 hook)Cluster: SPIRAL-ETH-2026-09

Estimated loss

$26.8K

Affected users

Number of affected users is not confirmed
Group joining is coming soon.

Investigation

45%

Facts and investigation

Ledger

Attacker

TODO

Funds moved to

TODO — no attacker address publicly disclosed.

Linked

A technical proof-of-concept reconstruction of the exploit exists in the DeFiHackLabs GitHub repository. No attacker address has been publicly disclosed.

Chronology

1 beat
  1. On September 14, 2026, an attacker exploited SpiralHookV2, a Uniswap V4 hook belonging to the SpiralCom protocol. The hook's borrow() function valued collateral using getSlot0(), Uniswap's raw spot price, with no TWAP or other manipulation resistance. A same-block swap guard intended to prevent this (keyed by tx.origin) was bypassed by splitting the attack across 6 separate externally-owned accounts within the same block. The attacker extracted approximately 10.7 ETH (~$26,800). A technical proof-of-concept exists publicly on GitHub via DeFiHackLabs.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)