en
Back to the list

MALT Loses $72K After Flawed Swap Lets Attacker Tap Treasury DAI

source-logo  coinedition.com 1 h
image

A DeFi attacker drained about $72,000 from MALT after exploiting a flaw in the protocol’s swap function, security firm SlowMist reported.

The attacker used a small amount of input to trigger the faulty swap. They then received more MALT than the transaction should have allowed. SlowMist said the exploit involved $DAI supplied by MALT’s treasury, allowing the attacker to extract funds from the protocol.

🚨SlowMist TI Alert🚨

💸 MALT Loss: ~$72k

🔍 Root Cause: swap(uint256,uint256,address) records the caller’s input and pre-swap reserves, then invokes an external rebalanceHook before transferring the requested output. The hook withdraws $DAI from the Capital Source and deposits…

— SlowMist (@SlowMist_Team) October 3, 2026
app-logo

Know when your
coins move

Alerts, real-time prices, and market news — all in one app
4.8 based on 40K reviews in the App Store and Google Play

Swap Flaw Lets Attacker Tap Treasury Funds

SlowMist said the flaw affected MALT’s swap(uint256,uint256,address) function. The function recorded the trader’s input and pool reserves before calling an external rebalancing function.

Related: Bitget Rebuilds $300M+ Protection Fund, Withdrawals Resumed

That function then withdrew $DAI from MALT’s Capital Source and returned it to the pool. Consequently, the swap treated the treasury-funded $DAI as trader-supplied funds during its validity check.

This allowed the attacker to provide only a small amount while benefiting from protocol-funded liquidity. Moreover, the flaw failed to separate user funds from capital added during rebalancing.

MALT Exploit Adds to DeFi Losses

The MALT exploit follows several recent attacks targeting DeFi projects. $NEAR Intents halted services after an Oct. 1 exploit caused about $3.8 million in losses.The team said it fixed the contract flaw and would fully compensate affected users.

Earlier today $NEAR Intents services were stopped after a security incident was detected. The incident was caused by a bug in the Omni deposit and withdrawal infrastructure interaction with $NEAR Intents smart contract.

The preliminary report indicates the total loss of…

— $NEAR Intents (@near_intents) October 1, 2026

Separately, a FlashLoopAdapter exploit drained about $305,000 from two Safe wallets using Aave V3 positions. However, the attack targeted the custom module rather than Aave V3’s core contracts.

DeFi hacks have caused more than $21 billion in losses, according to the DeFiLlama data. About $9.28 billion came from DeFi protocols, while bridges accounted for $3.69 billion.

Related: Blast Announces Shutdown With October 26 Withdrawal Deadline

coinedition.com