Float Protocol loses $28,000 in Uniswap V3 flash-loan exploit

  • Float Protocol lost funds after an attacker manipulated Uniswap V3 pricing in Hypervisor contracts.
  • 10.71 ETH, worth approximately $28,000, was extracted through repeated deposits and withdrawals.
  • SlowMist cited missing TWAP validation, oracle safeguards and slippage protection.

Float Protocol lost approximately $28,000, or 10.71 ETH, after an attacker used flash loans and large swaps to manipulate a Uniswap V3 spot price relied on by its Hypervisor contracts. The distorted slot0 data changed values returned by currentTick() and getTotalAmounts(), allowing the attacker to repeat deposits and withdrawals at incorrect liquidity-provider share valuations. SlowMist said the affected functions lacked time-weighted average price (TWAP) validation, oracle safeguards and slippage protection, despite Uniswap V3 having a native TWAP oracle. Security researcher Sprunky said the contracts followed a Hypervisor vault design associated with Gamma Strategies, which experienced a similar spot-price exploit in January 2024, and described Float’s incident as the fifth price-discovery failure recorded in five days. Float Protocol has not issued an official statement or provided comment. CertiK reported approximately $215 million in confirmed crypto losses during August 2026, including $144.6 million involving DeFi protocols and $131.6 million attributed to price manipulation.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.