← Radar

Incident case file

Sign in to watch

USM Protocol — Split-Invariance Flash Loan Exploit

Incident date 2026-08-08Last updated Aug 20, 2026

3 views

ContainedEthereum L1Smart contract exploit — Arithmetic split-invariance violationCluster: USM-ARI-2026-08

Estimated loss

$136K

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

75%

Facts and investigation

Ledger

Attacker

EOA: 0xb92b2E47680c89DA8f951B8963ef469f461a50Fc (confirmed Etherscan — initiated exploit tx at block 25716150, 08:12:47 UTC Aug 9) | Attack contract: 0x5a5e29ba89663a3558273354E990426F3cAc7de7

Funds moved to

70.830977367697708372 ETH transferred to profit receiver: 0xE3C6346b6F282029312d2CAf4677EF39BeaBBF99 (confirmed Etherscan internal tx). Cash-out path: 70 ETH → 0x8BF0E85c2655D4b6051024a7c47B20190C786aAC → 4 deposits to XT.com (0x60988d3B4D3DfFe2C9A5277945968E61993594Eb). Residual ~0.8 ETH → Relay bridge → Solana → ~1,400 USDT (4Su98ndN1kCRrHsFL7nFhytj2m8vEQCSrEddNa33erWD). Flash loan (11,579.978 WETH from Morpho) repaid within same transaction.

Linked

Attacker EOA: 0xb92b2E47680c89DA8f951B8963ef469f461a50Fc | Attack contract: 0x5a5e29ba89663a3558273354E990426F3cAc7de7 | Victim (USM contract): 0x2a7FFf44C19f39468064ab5e5c304De01D591675 (confirmed — matches official USM v1 GitHub) | FUM token: 0x86729873e3b88de2ab85ca292d6d6d69d548edf3 | Profit receiver: 0xE3C6346b6F282029312d2CAf4677EF39BeaBBF99 | Exploit tx: 0xfae5e751b8ce01457cbb6b529839f24a0cff50faaabcbd0fd02ca0cf559b050e (block 25716150, 08:12:47 UTC, confirmed Etherscan — 201 log even

Chronology

6 beats
  1. August 9, 2026, 08:12:47 UTC — USM Protocol, a minimalist ETH-backed stablecoin with no governance, was exploited for 70.83 ETH (~$136,000) via a split-invariance arithmetic vulnerability in its redemption function.

  2. Vulnerability: The ethFromDefund() function inside defund() computes the ETH to return using the arithmetic mean of the current FUM sell price and the estimated final FUM sell price for a single large redemption. This lacks 'split invariance' — the property that redeeming N FUM in one call should yield the same ETH as redeeming it across N separate calls. Combined with the per-redemption state contraction factor (adjShrinkFactor) and integer rounding, splitting a large redemption into many small calls extracts more ETH than the single-call equivalent.

  3. 08:12:47 UTC, block 25716150: Single-transaction exploit (tx 0xfae5e751...): 1. Flash-borrow 11,579.978 WETH from Morpho 2. Call fund() once to mint ~62,184,299 FUM and manipulate USM's internal pricing 3. Execute 64 sequential defund() calls with equal FUM amounts — each extracting slightly more ETH than the proportional share, due to the arithmetic/geometric mismatch and adjShrinkFactor accumulation 4. Net extraction: 70.830977367697708372 ETH (transferred to profit receiver 0xE3C6346b...) 5. Repay Morpho flash loan (11,579.978 WETH returned)

  4. Post-exploit: 70 ETH moved to 0x8BF0E85c..., then deposited in 4 transactions to XT.com (0x60988d3B...). Residual ~0.8 ETH routed via Relay to Solana, converted to ~1,400 USDT.

  5. Aug 10: SlowMist_Team (tweet 2086644725143183639) and SolidityScan (tweet 2086713636291068114) publish technical analysis. KuCoin News and Coinfomania cover the incident.

  6. No official post-mortem from USM. No patch announced. No recovery.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)