SlowMist|Oct 09, 2026 05:24
🚨SlowMist TI Alert🚨
💸 @ethervista Loss: ~18.6K
🔍 Root Cause: The EtherVistaPair.swap() function suffers from an integer overflow in its K-invariant check. Since both reserves are uint112, their multiplication overflows and wraps around, allowing the invariant check to pass even when the actual reserve product decreases significantly. The attacker exploited this flaw through an attacker-controlled contract registered as the authorized router, executing two crafted swaps to drain WETH and VISTA from the pool.
📌 Attacker: 0xbbf8f3fe8e4fdf6b594e6107144d78293d2018fa
📌 Attack Contract (Router): 0x469424b628a9d2036e41496e814db500d683b120
📌 Vulnerable Contract: 0xfdd05552f1377aa488afed744c8024358af02041
Powered by http://SlowMist.AI
Tx: https://etherscan.io/tx/0xb2c7332d9e1be6a86d9d37083aa4cc0d94b60eb95cc9b29494555a3c09764930
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink