🚹 EXPLOIT ALERT: $30K DRAINED via Signature Replay

@atomic__green just lost 29,984 $USDC in a textbook signature replay attack.

How it went down:
‱ Attacker exploited missing nonce/chainID/deadline checks in signed digest (0xa806010f)
‱ Replayed ONE manager signature across 21 different LP position IDs
‱ Burned full LP positions via partialBurn under flashloan-manipulated prices
‱ Zero TWAP or slippage protection = easy $ARB→$USDC arb

Attacker: 0xf880...c7e
Victim Position Manager: 0xf617...69d9
Vulnerable Contract: 0x51ff...42a8

This is why you ALWAYS bind position ID + nonce + chainID in your signature schema. One sig = 21 exploits.

Stay sharp. Audit your LP managers.

📊 SlowMist TI