🚨 EXPLOIT ALERT: @spir8l_com drained for ~10.7 $ETH

Root cause? Classic oracle manipulation.

SpiralHookV2.borrow() trusted Uniswap V4 spot price (poolManager.getSlot0()) with zero TWAP or sanity checks. Attacker pumped collateral value, borrowed against it, dumped—all in one block.

The protocol had a noSameBlockSwap guard, but it was keyed by tx.origin. Attacker just spun up 6 different EOAs and bypassed it like it wasn't even there.

Attacker EOA:
0x859E69A29244A10800A34eE66919426C02aFa2f0

Attack Contract:
0x0c23c8bc3b7c565f3f9f4ac691a4dc4275086f86

Vulnerable Contract:
0x1725577dC9B1ee2D95dB49c2193226471594aacc

If your protocol uses spot price for anything critical, you're one MEV bot away from being exit liquidity.

TWAP or bust. No exceptions.