🚨 EXPLOIT ALERT: $VISTA / $WETH Pool Drained (~18.6K)

⚠️ Integer overflow in EtherVistaPair.swap() K-invariant check

uint112 reserves multiplied → overflow wraps → invariant passes even when reserve product tanks

Attacker used controlled router contract to execute 2 crafted swaps, draining both $WETH and $VISTA from the pool

🔴 Attacker: 0xbbf8...18fa
🔴 Malicious Router: 0x4694...b120
🔴 Vulnerable Contract: 0xfdd0...2041

Another day, another unaudited AMM fork getting rekt by basic overflow bugs. If your protocol doesn't handle uint bounds properly in 2024, you're ngmi.

Stay safe out there 🛡️