🚨 $MALT just got drained for ~$72k

Attacker exploited a critical rebalancing hook vulnerability in their swap function. Here's the alpha:

The swap() function records caller input + reserves, then fires an external rebalanceHook BEFORE transferring output. Hook pulls DAI from Capital Source and deposits into the same pool. Swap validates invariant against final balances, treating protocol-funded DAI as caller-supplied.

Result? Attacker provides near-zero input, triggers treasury liquidity injection, extracts disproportionate $MALT.

Classic case of not isolating caller funds from protocol rebalancing capital.

Attacker: 0x8F103B6A0aD705bcE6357842A5fefEB49e8D83Ef
Victim Contract: 0xF0d314849A3Bc9270a79110F25dBA2c8325A2AAC
Vulnerable: 0xfe6C096a2871337d4f6F7DD04Ebda733E94D7A13

Another day, another hook exploit. DYOR on protocol-level swap logic before aping.