Odaily reported that USM lost roughly 70.83 ETH in an attack. The incident centers on the contract's defund() redemption function. Within it, ethFromDefund() contains a pricing flaw: each redemption is valued by taking the arithmetic mean of the current FUM sell price and an estimated terminal FUM sell price. The problem is that this calculation is not split-invariant. With the state shrink coefficient adjShrinkFactor and integer rounding applied to each redemption, an identical amount of FUM can be submitted as 64 separate small redemptions instead of one large redemption. As a result, the total amount of ETH that can be extracted is far larger than what a single redemption would yield. The exploit relies on this discrepancy between one large redemption and many small ones, and it stems from the averaging formula rather than from any single anomalous transaction. The report does not specify additional details about the attacker or when exactly the attack took place.
Odaily reported that USM lost about 70.83 ETH in an attack. The vulnerability sits in the defund() redemption function of the contract, specifically in the ethFromDefund() pricing logic.
The function determines the consideration for a single redemption by calculating the arithmetic mean of the current FUM sell price and the estimated terminal FUM sell price. That pricing algorithm lacks split invariance. When the state shrink coefficient adjShrinkFactor and integer rounding are combined with each redemption, the same amount of FUM assets, if split into 64 small redemption operations, ultimately allows far more Ethereum to be withdrawn than a single one-time large redemption would return.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.