← Radar

Incident case file

Sign in to watch

Thetanuts Finance Legacy Vault Exploit — Whitehat Recovery

Incident date June 15, 2026

2 views

ContainedEthereum L1Smart contract exploit — legacy vault redemption math flawCluster: THN-ETH-2026-06

Estimated loss

$105K

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

90%

Facts and investigation

Attacker: 0x30498e4466789E534c72e03B52A16c978655b41e

Funds moved to: Gross drain ~$2.1M in option tokens via tx 0xbba9f138fe39503bfd1aa62932dbd6ab35d37d23d48e4b7bf2988a9d5dc39fec. ~$2M recovered by a whitehat and returned to the protocol. Attacker retained $105K, swapped to ~60 ETH. Net realized loss: ~$105,000.
Victim contract: deprecated Index Vault 0xC2C3AE0a7b405058558C9b4a63b373486CB86Ac7. Flash loan used to manipulate totalSupply near zero, exploiting the backing x amount / totalSupply redemption formula. Thetanuts confirmed this is a vault 'migrated from years ago' with no relation to current active products.

Timeline: On June 15, 2026, an attacker exploited Thetanuts Finance's deprecated legacy Index Vault by using a flash loan to drive the vault's totalSupply close to zero, then abusing the resulting division-by-near-zero in the redemption formula (backing x amount / totalSupply) to mint and redeem disproportionate payouts. The attacker drained approximately $2.1M in option tokens via transaction 0xbba9f138fe39503bfd1aa62932dbd6ab35d37d23d48e4b7bf2988a9d5dc39fec from victim contract 0xC2C3AE0a7b405058558C9b4a63b373486CB86Ac7. PeckShieldAlert issued the first public alert the same day, noting that approximately $2M of the drained option tokens had already been whitehatted. Blockaid's community alert independently confirmed the exploiter and contract addresses. Thetanuts Finance confirmed on X: 'this is once again, a deprecated vault that we have migrated from years ago. It has no relation to any of our current contracts or products.' Security researcher ExVul published the technical root-cause breakdown the same day: 'The root cause is a flaw in the legacy vault's redemption math, which used a backing * amount / totalSupply formula to calculate share payouts, allowing the attacker to withdraw more funds than they were entitled to.' The attacker swapped the retained $105K USDC portion for approximately 60 ETH; the whitehat-recovered $2M was returned to the protocol. No formal attribution has been made by any security firm.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)