🚨 EXPLOIT ALERT: $14K drained from BitBay vault

Attacker abused a critical flaw in the _withdraw() function. When liquidity hits zero, the contract dumps its entire token balance instead of just the user's share.

The play:
→ Force liquidity to 0 via reposition()
→ Redeem 1 minimal share
→ Drain ~14,838 $DAI

Attacker: 0x59Ae...9884B
Victim Contract: 0x048E...2e5A0

Another day, another vault rekt by sloppy withdrawal logic. If your protocol doesn't cap withdrawals to actual user shares, you're exit liquidity.