Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Price Analysis
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Elon Musk and SpaceX composite image with the Indian flag and Bitcoin
    India vs Elon Musk: Starlink’s Global Wall of Bans, and the Crypto Thread Running Through It
    Physical gold Bitcoin (BTC) token standing in front of the US Capitol Building and the American flag
    Why Are U.S. Government Wallets Still Routing Seized Crypto to Coinbase?
    Charlie Lee, creator of Litecoin, standing in front of a blue Litecoin corporate logo wall
    Litecoin Turns 15: Original Bitcointalk Records Show How Charlie Lee Launched LTC in 2011
    Elon Musk with folded arms flanked by a giant Bitcoin coin, Tesla electric car, and SpaceX rocket launch
    Elon Musk’s Tesla and SpaceX Still Hold Over 30,000 Bitcoin: Why Is He Not Selling?
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto What the Record Actually Shows
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto? What the Record Actually Shows
  • Opinion
    OpinionShow More
    Donald Trump speaking at a presidential podium with the White House and U.S. Capitol building in the background.
    Trump Just Declared the Super Intelligence Era in the “Unites States.” So Who Controls It?
    Comparison of Bybit 12-hour, Bitget 85-hour, and WazirX 463-day response timers
    Bitget, Bybit Paid in Hours; WazirX Lost Least in Hacks at $235M, Held Users Hostage for 463 Days
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Price Analysis
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

SlowMist Flags BitBay and EtherVista Hacks as Attackers Drain $32,600 From DeFi Vault & Pool

One attacker exploited a zero-liquidity withdrawal bug on Polygon, while another bypassed EtherVista’s swap safeguards through an integer overflow, exposing two distinct DeFi security flaws.

Written By Dishita Malvania
Edited by Divya Mistry
Published 45 minutes ago·Updated 41 minutes ago
Make The Crypto Times preferred on GoogleGoogle
BitBay and EtherVista logo display blocks in front of an illuminated metallic SlowMist logo on a dark wall

Two decentralized finance (DeFi) protocols, BitBay and EtherVista, lost about $32,600 in total on October 9, 2026, after attackers exploited two unrelated smart contract flaws. Blockchain security firm SlowMist flagged both incidents within two hours of each other. 

In both cases, the code paid out more tokens than the attacker owned, either because a withdrawal function mishandled zero liquidity or because a safety check broke under an integer overflow.

AI Summary
Show
Developers will likely audit zero‑liquidity functions to prevent similar vault drains across DeFi platforms.
Integer overflow checks may become mandatory, prompting upgrades to larger integer types in smart contracts.
Regulators could tighten disclosure rules, forcing protocols to report breaches and compensation plans promptly.

BitBay Polygon Vault Drained Through Zero-Liquidity Flaw

SlowMist published its BitBay alert at 03:28 Coordinated Universal Time (UTC) on October 9. The affected contract was BitBay’s DAI/USDC vault on Polygon, an Ethereum-compatible blockchain network. DAI and USD Coin (USDC) are both stablecoins designed to maintain a 1:1 peg to the US dollar. Follow-up incident reports refer to the contract as UsdcDaiV4Vault.

The attacker took roughly 14,838.47 DAI from the vault. SlowMist’s Hacked database lists the BitBay StableVault loss at $14,000 and classifies it as a smart contract vulnerability.

The flaw sat in the vault’s _withdraw() function. When the vault’s liquidity stood at zero, the function transferred the contract’s entire token balance to the caller. It should have limited the payout to the caller’s proportional share of the vault.

The attacker exploited this in two steps. First, they called the reposition() function to force the vault’s liquidity to zero. Next, they redeemed a single minimal share unit and received the full vault balance in return. Blockchain compliance publication PublicAML described the same attack sequence and loss figure in a later note.

SlowMist identified the attacker address as 0x59A..884B. The firm listed 0x048..F2e5A0 as both the victim and the vulnerable contract.

EtherVista Pool Hit by Integer Overflow in Swap Check

About two hours later, the second alert at 05:20 UTC shows this time for EtherVista, a decentralized exchange (DEX) protocol. The firm estimated the loss at about $18,600 in Wrapped Ether (WETH), a token version of Ether (ETH), and VISTA, EtherVista’s native token. The Hacked database records the same $18,600 figure under a smart contract vulnerability entry.

The root cause was an integer overflow in the K-invariant check inside the EtherVistaPair.swap() function. Many DEX liquidity pools follow a constant product rule, where the product of the pool’s two token reserves, known as K, must not decrease after a trade. This check stops traders from withdrawing more value than they deposit.

EtherVista stores both reserves as uint112 values, meaning unsigned integers capped at 112 bits. When the contract multiplies the two reserves, the result can exceed the maximum value the calculation can hold and wrap around to a much smaller number. As a result, the check can pass even when the real product of the reserves has fallen.

The attacker first registered a contract under their own control as an authorized router, the component that sends trades to the pool, and then executed two crafted swaps that drained the pool. The attacker address is 0xbb..18fa, and the attack contract, which also acted as the router, is 0x46…3b120. The vulnerable contract is 0xfdd…02041.

Small Losses, Familiar Weakness

Both losses are minor compared with recent large-scale incidents that SlowMist has investigated. These include the $387.5 million Bitget hot wallet hack, which SlowMist and Mandiant traced to a zero-day attack, and the Liquid Network flaw that minted 3,998 unbacked L-BTC.

Still, the two October 9 cases follow a pattern SlowMist has highlighted before. In each, withdrawal or invariant logic failed at an edge case: zero liquidity at BitBay and a uint112 overflow at EtherVista, and the contract released more funds than the caller owned. Neither contract enforced a check that tied the payout to the attacker’s actual ownership or to the pool’s true reserves.

No Recovery Statement Yet

Neither BitBay nor EtherVista had issued an official statement on fund recovery, attacker negotiations, or user compensation at the time of publication. The alerts and the follow-up reports reviewed for this article do not include independent fund-flow data beyond the loss figures SlowMist has already published.

Also Read: 79thVault Hack: $12.5M Drained From 79AU Pool on BNB Chain

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:Crypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

DWF Labs Takes BitGo to Court Over $141M Token Lock-Up Dispute
DWF Labs Takes BitGo to Court Over $141M Token Lock-Up Dispute
Netflix "The Altruists" series poster featuring Sam Bankman-Fried and Caroline Ellison characters
Netflix Revisits FTX’s $8B Scandal in ‘The Altruists’ Trailer
Starknet (STRK) Price Jumps 40.1% as Network Weighs Move Beyond Ethereum
Starknet (STRK) Price Jumps 40.1% as Network Weighs Move Beyond Ethereum
Physical MicroStrategy (MSTR) token coin standing on a reflective dark surface in front of a financial candlestick price chart
MSTR Stock Falls 11% From Weekly High as Bitcoin Rejects $87,000 for the Third Time
Physical gold Bitcoin (BTC) and silver Ethereum (ETH) coins standing side by side against a financial chart background
Bitcoin, Ethereum Options Expiry: $2.16B Settles Today as BTC Trades Below $84K Max Pain

Find Us on Socials

You may also like

Laptop screen displaying 79Vault logo next to BNB coins spilling from a wallet and a phone showing a CertiK warning symbol

79thVault Hack: $12.5M Drained From 79AU Pool on BNB Chain

Hooded hacker working on a laptop displaying Uranium Finance branding next to a system breach alert.

US Jury Convicts Uranium Finance Hacker Over $54 Million Crypto Theft

Gold frog memecoin medallion set against a Singapore skyline at dusk with red market charts.

Crypto Trader Frogman Loses Over $4M in Wallet Hack in Singapore During TOKEN2049

Hooded figure using a laptop near an Ethereum coin and a MakerDAO logo displaying a red warning symbol.

Dormant MakerDAO Keeper Drained of $538K, Core Remains Intact

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Masthead
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram
© 2026 The Crypto Times | Protocols And Tokens Pvt Ltd.
DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information