
The protocol said the exploit hit a deprecated legacy vault and did not affect current contracts, while SlowMist linked the incident to an integer division truncation flaw and said most funds were recovered.
Thetanuts Finance said an exploit drained about $2.1 million from a legacy vault the protocol had abandoned years ago, while maintaining that the incident was unrelated to its current contracts or products. SlowMist said about $2 million of the affected position appears to have been recovered by a white-hat hacker, limiting the apparent net loss. The security firm attributed the exploit to integer division truncation in the vault’s mint function, adding a more specific technical explanation to earlier assessments that pointed to faulty vault logic. Earlier on-chain analysis from PeckShieldAlert said the remaining funds, about $105,000 in USDC, were swapped for around 60 ETH and that the attacker still held about $34,000 in USDC-denominated option tokens. Blockaid also detected the attack and issued an alert on Ethereum. The case highlights a recurring DeFi risk: deprecated smart contracts can remain exploitable long after a protocol has migrated away from them.