๐Ÿšจ EXPLOIT ALERT: $SET Protocol just got drained for ~5.08 $ETH

Attack vector? Rounding manipulation in actualizeFee()

The function recalculated unitShares with upward rounding (4,927 โ†’ 4,928) even though NO fee was actually minted. Attacker issued tokens before the update, redeemed same amount after, and pocketed the collateral from the rounding delta.

Scaled via Uniswap v4 flash accounting for max impact.

๐Ÿ“ Attacker EOA: 0x506440728d84eb22809dc9464bc8189618a1c5b6
๐Ÿ“ Attack Contract: 0x016feaaa25ab8325e233bc8a2c25055bee0b2f6e
๐Ÿ“ Victim Vault: 0x5b67871c3a857de81a1ca0f9f7945e5670d986dc
๐Ÿ“ Vulnerable Contract: 0x54e8371c1ec43e58fb53d4ef4ed463c17ba8a6be

Another day, another rounding bug. DeFi devs: audit your math libs or get rekt.

via @SlowMist_Team