Two decentralized finance (DeFi) protocols, BitBay and EtherVista, lost about $32,600 in total on October 9, 2026, after attackers exploited two unrelated smart contract flaws. Blockchain security firm SlowMist flagged both incidents within two hours of each other.
In both cases, the code paid out more tokens than the attacker owned, either because a withdrawal function mishandled zero liquidity or because a safety check broke under an integer overflow.
BitBay Polygon Vault Drained Through Zero-Liquidity Flaw
SlowMist published its BitBay alert at 03:28 Coordinated Universal Time (UTC) on October 9. The affected contract was BitBay’s DAI/USDC vault on Polygon, an Ethereum-compatible blockchain network. DAI and USD Coin (USDC) are both stablecoins designed to maintain a 1:1 peg to the US dollar. Follow-up incident reports refer to the contract as UsdcDaiV4Vault.
The attacker took roughly 14,838.47 DAI from the vault. SlowMist’s Hacked database lists the BitBay StableVault loss at $14,000 and classifies it as a smart contract vulnerability.
The flaw sat in the vault’s _withdraw() function. When the vault’s liquidity stood at zero, the function transferred the contract’s entire token balance to the caller. It should have limited the payout to the caller’s proportional share of the vault.
The attacker exploited this in two steps. First, they called the reposition() function to force the vault’s liquidity to zero. Next, they redeemed a single minimal share unit and received the full vault balance in return. Blockchain compliance publication PublicAML described the same attack sequence and loss figure in a later note.
SlowMist identified the attacker address as 0x59A..884B. The firm listed 0x048..F2e5A0 as both the victim and the vulnerable contract.
EtherVista Pool Hit by Integer Overflow in Swap Check
About two hours later, the second alert at 05:20 UTC shows this time for EtherVista, a decentralized exchange (DEX) protocol. The firm estimated the loss at about $18,600 in Wrapped Ether (WETH), a token version of Ether (ETH), and VISTA, EtherVista’s native token. The Hacked database records the same $18,600 figure under a smart contract vulnerability entry.
The root cause was an integer overflow in the K-invariant check inside the EtherVistaPair.swap() function. Many DEX liquidity pools follow a constant product rule, where the product of the pool’s two token reserves, known as K, must not decrease after a trade. This check stops traders from withdrawing more value than they deposit.
EtherVista stores both reserves as uint112 values, meaning unsigned integers capped at 112 bits. When the contract multiplies the two reserves, the result can exceed the maximum value the calculation can hold and wrap around to a much smaller number. As a result, the check can pass even when the real product of the reserves has fallen.
The attacker first registered a contract under their own control as an authorized router, the component that sends trades to the pool, and then executed two crafted swaps that drained the pool. The attacker address is 0xbb..18fa, and the attack contract, which also acted as the router, is 0x46…3b120. The vulnerable contract is 0xfdd…02041.
Small Losses, Familiar Weakness
Both losses are minor compared with recent large-scale incidents that SlowMist has investigated. These include the $387.5 million Bitget hot wallet hack, which SlowMist and Mandiant traced to a zero-day attack, and the Liquid Network flaw that minted 3,998 unbacked L-BTC.
Still, the two October 9 cases follow a pattern SlowMist has highlighted before. In each, withdrawal or invariant logic failed at an edge case: zero liquidity at BitBay and a uint112 overflow at EtherVista, and the contract released more funds than the caller owned. Neither contract enforced a check that tied the payout to the attacker’s actual ownership or to the pool’s true reserves.
No Recovery Statement Yet
Neither BitBay nor EtherVista had issued an official statement on fund recovery, attacker negotiations, or user compensation at the time of publication. The alerts and the follow-up reports reviewed for this article do not include independent fund-flow data beyond the loss figures SlowMist has already published.
Also Read: 79thVault Hack: $12.5M Drained From 79AU Pool on BNB Chain
