Key Highlights
- Float Protocol lost 10.71 ETH, worth approximately $28,000, after an attacker manipulated the Uniswap V3 spot price used by its Hypervisor contracts.
- SlowMist identified the root cause as direct reliance on Uniswap V3’s slot0 data without TWAP validation or adequate slippage protection.
- The attacker used flash loans and large swaps to distort the pool’s spot price, allowing repeated deposits and withdrawals at manipulated LP share valuations.
Float Protocol suffered a loss of 10.71 ETH, valued at approximately $28,000, after an attacker manipulated the Uniswap V3 spot price in underlying pools linked to its Hypervisor contracts.
In an X post on Monday, Blockchain security firm SlowMist reported the incident, identifying the root cause as the use of Uniswap V3’s slot0 data without time-weighted average price (TWAP) validation or slippage protection.
The attacker address is listed as 0xa…6d9. The attack contract as 0xb…c54, and the vulnerable contracts include 0x8…a70c and 0xc…153. The underlying pool is 0xe…0ac.
Float Protocol has not published any official statement regarding the exploit. The Crypto Times team tried to reach out to Float Protocol for a comment on the matter but did not receive one at the time of publication.
Attack sequence and mechanics
According to SlowMist, the attacker used flash loans to execute large swaps on the Uniswap V3 pool. These swaps distorted the slot0 value, which determines the current tick and total amounts reported by the Hypervisor contracts. Functions that calculate LP share pricing relied directly on this manipulated spot data.
With inflated values returned by currentTick() and getTotalAmounts(), the attacker repeatedly deposited and withdrew liquidity. Each cycle minted or redeemed shares at distorted prices, extracting value from the vaults. The process mirrors patterns observed in other recent incidents involving iterative deposit-withdraw loops.
Security researcher identifies price-discovery failure
A security researcher, Sprunky, highlighted the matter further and noted that the affected contracts follow the Hypervisor vault design originally associated with Gamma Strategies.
That framework experienced a similar exploit in January 2024, in which LP shares were minted against the spot price of a Uniswap V3 pool. Gamma Strategies later published guidance on Uniswap V3 risk mitigation that addressed the absence of TWAP checks and slippage controls. The Float Protocol contracts did not incorporate those measures.
Sprunky further observed that the Float Protocol loss represents the fifth price-discovery failure recorded in five days. The small size of the extraction is consistent with automated scanning activity that targets multiple hypervisor-style vaults lacking oracle safeguards. Uniswap V3 includes a native TWAP oracle; direct reliance on slot0 remains the point of exposure.
Monthly Loss in DeFi
On August 31, CertiK reported that confirmed incidents in August 2026 produced approximately $215 million in losses. Of that total, roughly $41.5 million was attributed to phishing. DeFi protocols accounted for $144.6 million. About $110.7 million in funds were later classified as returned or frozen.
CertiK’s category breakdown listed price manipulation at $131.6 million, phishing at $41.5 million, code vulnerabilities at $20.6 million, wallet compromise at $11.8 million, and governance incidents at $8.5 million. The largest single entry was the tectonic incident on August 30, recorded at $120.4 million.
The Float Protocol event falls within the price-manipulation category and involves the same class of spot-price dependency previously documented in Hypervisor implementations. SlowMist’s alert and the on-chain addresses provide the primary record of the transaction sequence and the contracts involved.
Also Read: Arbitrator Clears Gemini Over Earn Collapse, but Interest Claims Remain Open
