Incident case file
Sign in to watchUSM Protocol — Split-Invariance Flash Loan Exploit
3 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
6 beatsAugust 9, 2026, 08:12:47 UTC — USM Protocol, a minimalist ETH-backed stablecoin with no governance, was exploited for 70.83 ETH (~$136,000) via a split-invariance arithmetic vulnerability in its redemption function.
Vulnerability: The ethFromDefund() function inside defund() computes the ETH to return using the arithmetic mean of the current FUM sell price and the estimated final FUM sell price for a single large redemption. This lacks 'split invariance' — the property that redeeming N FUM in one call should yield the same ETH as redeeming it across N separate calls. Combined with the per-redemption state contraction factor (adjShrinkFactor) and integer rounding, splitting a large redemption into many small calls extracts more ETH than the single-call equivalent.
08:12:47 UTC, block 25716150: Single-transaction exploit (tx 0xfae5e751...): 1. Flash-borrow 11,579.978 WETH from Morpho 2. Call fund() once to mint ~62,184,299 FUM and manipulate USM's internal pricing 3. Execute 64 sequential defund() calls with equal FUM amounts — each extracting slightly more ETH than the proportional share, due to the arithmetic/geometric mismatch and adjShrinkFactor accumulation 4. Net extraction: 70.830977367697708372 ETH (transferred to profit receiver 0xE3C6346b...) 5. Repay Morpho flash loan (11,579.978 WETH returned)
Post-exploit: 70 ETH moved to 0x8BF0E85c..., then deposited in 4 transactions to XT.com (0x60988d3B...). Residual ~0.8 ETH routed via Relay to Solana, converted to ~1,400 USDT.
Aug 10: SlowMist_Team (tweet 2086644725143183639) and SolidityScan (tweet 2086713636291068114) publish technical analysis. KuCoin News and Coinfomania cover the incident.
No official post-mortem from USM. No patch announced. No recovery.
Sources and coverage
- Articlehacked.slowmist.iohttps://hacked.slowmist.io/?c=ETH
- Articlex.comhttps://x.com/SlowMist_Team/status/2086644725143183639
- Articlex.comhttps://x.com/SolidityScan/status/2086713636291068114
- Articleetherscan.iohttps://etherscan.io/tx/0xfae5e751b8ce01457cbb6b529839f24a0cff50faaabcbd0fd02ca0cf559b050e
- Articleetherscan.iohttps://etherscan.io/address/0xb92b2E47680c89DA8f951B8963ef469f461a50Fc
- Articleetherscan.iohttps://etherscan.io/address/0x2a7FFf44C19f39468064ab5e5c304De01D591675
- Articlekucoin.comhttps://www.kucoin.com/news/flash/usm-contract-vulnerability-leads-to-theft-of-70-83-eth
- Articlecoinfomania.comhttps://coinfomania.com/usm-suffers-70-83-eth-loss-due-to-pricing-logic-flaw
- Articlecryptotimes.iohttps://www.cryptotimes.io/2026/08/16/crypto-whale-loses-25-6m-again-as-weekly-hacks-cross-37m/
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)