SlowMist says MALT protocol was exploited through rebalance hook flaw, with about $72,000 lost

SlowMist says MALT protocol was exploited through rebalance hook flaw, with about $72,000 lost

N
News Editor
2026-10-03 16:22:27
SlowMist said the MALT protocol was attacked because of a flaw tied to the rebalanceHook used in its swap function, with losses estimated at about $72,000. According to the security firm, the attacker was able to put in only a very small amount of capital, trigger the protocol treasury to inject liquidity, and then withdraw a disproportionately large amount of MALT tokens. SlowMist said the issue stemmed from the way the swap(uint256,uint256,address) function recorded user input and pre-swap reserves before calling an external rebalance hook. That hook pulled DAI from a funding source and deposited it into the same liquidity pool. The swap function then checked invariants against the pool’s final balance and mistakenly treated the protocol-injected DAI as if it had been supplied by the caller. SlowMist also disclosed the attacker address, victim address, and the vulnerable contract address.

Security firm SlowMist said on X that the MALT protocol was exploited because of a flaw in the rebalanceHook used by its swap function, with losses of about $72,000.

According to SlowMist, the attacker used the bug to trigger a liquidity injection from the protocol treasury while supplying only a very small amount of input capital, then withdrew a disproportionately large amount of MALT tokens.

How the flaw worked

SlowMist said the issue was rooted in the swap(uint256,uint256,address) function. The function recorded the caller’s input and the reserves before the swap, then called an external rebalance hook before transferring the requested output.

That hook pulled DAI from a funding source and deposited it into the same liquidity pool. The swap function later checked its invariant against the pool’s final balance and mistakenly counted the protocol-injected DAI as funds provided by the caller.

Addresses disclosed

SlowMist identified the attacker address as 0x8F103B6A0aD705bcE6357842A5fefEB49e8D83Ef, the victim address as 0xF0d314849A3Bc9270a79110F25dBA2c8325A2AAC, and the vulnerable contract address as 0xfe6C096a2871337d4f6F7DD04Ebda733E94D7A13.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.