🚨 EXPLOIT ALERT: @spir8l_com drained for ~10.7 $ETH
Root cause? Classic oracle manipulation.
SpiralHookV2.borrow() trusted Uniswap V4 spot price (poolManager.getSlot0()) with zero TWAP or sanity checks. Attacker pumped collateral value, borrowed against it, dumped—all in one block.
The protocol had a noSameBlockSwap guard, but it was keyed by tx.origin. Attacker just spun up 6 different EOAs and bypassed it like it wasn't even there.
Attacker EOA:
0x859E69A29244A10800A34eE66919426C02aFa2f0
Attack Contract:
0x0c23c8bc3b7c565f3f9f4ac691a4dc4275086f86
Vulnerable Contract:
0x1725577dC9B1ee2D95dB49c2193226471594aacc
If your protocol uses spot price for anything critical, you're one MEV bot away from being exit liquidity.
TWAP or bust. No exceptions.
Root cause? Classic oracle manipulation.
SpiralHookV2.borrow() trusted Uniswap V4 spot price (poolManager.getSlot0()) with zero TWAP or sanity checks. Attacker pumped collateral value, borrowed against it, dumped—all in one block.
The protocol had a noSameBlockSwap guard, but it was keyed by tx.origin. Attacker just spun up 6 different EOAs and bypassed it like it wasn't even there.
Attacker EOA:
0x859E69A29244A10800A34eE66919426C02aFa2f0
Attack Contract:
0x0c23c8bc3b7c565f3f9f4ac691a4dc4275086f86
Vulnerable Contract:
0x1725577dC9B1ee2D95dB49c2193226471594aacc
If your protocol uses spot price for anything critical, you're one MEV bot away from being exit liquidity.
TWAP or bust. No exceptions.