Incident case file
Sign in to watchSpiral (SpiralCom) SpiralHookV2 Oracle Manipulation — $26.8K
Incident date Sep 13, 2026Last updated Sep 24, 2026
0 views
ContainedEthereumSpot-price oracle manipulation (Uniswap V4 hook)Cluster: SPIRAL-ETH-2026-09
Estimated loss
$26.8K
Affected users
Number of affected users is not confirmed
Group joining is coming soon.
Investigation
45%
Facts and investigation
Ledger
Attacker
TODO
Funds moved to
TODO — no attacker address publicly disclosed.
Linked
A technical proof-of-concept reconstruction of the exploit exists in the DeFiHackLabs GitHub repository. No attacker address has been publicly disclosed.
Chronology
1 beatOn September 14, 2026, an attacker exploited SpiralHookV2, a Uniswap V4 hook belonging to the SpiralCom protocol. The hook's borrow() function valued collateral using getSlot0(), Uniswap's raw spot price, with no TWAP or other manipulation resistance. A same-block swap guard intended to prevent this (keyed by tx.origin) was bypassed by splitting the attack across 6 separate externally-owned accounts within the same block. The attacker extracted approximately 10.7 ETH (~$26,800). A technical proof-of-concept exists publicly on GitHub via DeFiHackLabs.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)