Key Highlights:
- A logic flaw in MALT’s swap function allowed an attacker to siphon treasury funds by misclassifying protocol-funded DAI as user-deposited collateral.
- The breach joins a string of decentralized finance incidents, including a $3.8 million exploit on NEAR Intents and a $305,000 FlashLoopAdapter drain.
- Cumulative losses from DeFi exploits have surpassed $21 billion, according to tracking data from DeFiLlama.
Smart Contract Vulnerability Enables Treasury Drain in MALT Protocol
Blockchain security firm SlowMist has uncovered a critical vulnerability in MALT’s smart contract infrastructure that enabled an attacker to exploit the protocol’s liquidity reserves. The flaw resided within MALT’s swap(uint256,uint256,address) function, which improperly handled internal accounting between trader inputs and automated treasury rebalancing mechanisms.
According to technical analysis by SlowMist, the vulnerability stemmed from the sequence in which the contract processed transactions. The swap function recorded the trader’s initial input and pool reserves prior to triggering an external rebalancing routine. Once executed, that secondary function pulled DAI from MALT’s Capital Source and injected it directly back into the liquidity pool.
Consequently, the contract’s validity check failed to separate the user’s supplied tokens from the liquidity added during the rebalancing phase. Because the protocol counted the treasury-funded DAI as part of the trader’s own contribution, the attacker was able to commit only a minimal amount of capital while walking away with substantial protocol-backed liquidity.
DeFi Ecosystem Battles Wave of Smart Contract Exploits
The attack on MALT comes amid a resurgence of security breaches targeting decentralized finance protocols. In a separate incident on October 1, decentralized trading protocol NEAR Intents was forced to suspend its operations after suffering an exploit that resulted in approximately $3.8 million in losses.
Following the breach, the NEAR Intents development team announced that the underlying smart contract flaw had been resolved and confirmed that impacted users would be made whole. Outlining the source of the failure, the team stated:
Earlier today $NEAR Intents services were stopped after a security incident was detected. The incident was caused by a bug in the Omni deposit and withdrawal infrastructure interaction with $NEAR Intents smart contract.The preliminary report indicates the total loss of…
In another targeted assault, a vulnerability in the FlashLoopAdapter custom module resulted in the theft of roughly $305,000 from two Safe multi-signature wallets holding Aave V3 positions. Security findings confirmed that the compromise was isolated specifically to the third-party adapter rather than Aave V3’s primary protocol contracts.
Why This Matters
The MALT and FlashLoopAdapter exploits highlight ongoing challenges surrounding complex smart contract interactions, state-machine synchronization, and third-party integrations in decentralized finance. When auxiliary routines—such as automated rebalancing tools or custom execution adapters—interact with core asset pools, any failure to isolate protocol equity from external user inputs can create catastrophic arbitrage or draining vectors.
Data compiled by DeFiLlama underscores the staggering financial impact of these security failures across the sector. Historical losses from decentralized finance hacks have now crossed the $21 billion mark. Out of this total, core DeFi protocols account for roughly $9.28 billion in lost capital, while cross-chain bridges represent approximately $3.69 billion of the total stolen assets.
Frequently Asked Questions
What caused the MALT protocol exploit?
The exploit was caused by a logic flaw in MALT’s swap(uint256,uint256,address) function. The function did not separate trader-deposited assets from DAI drawn from MALT’s Capital Source during an external rebalancing step, allowing an attacker to claim treasury-provided funds as their own deposit during the swap’s validity check.
Were Aave V3 core contracts affected in the FlashLoopAdapter exploit?
No. Security analysis confirmed that the core smart contracts of Aave V3 were not compromised. The exploit specifically targeted the external FlashLoopAdapter custom module used in connection with two Safe wallets.
What is the status of the funds lost in the NEAR Intents breach?
The NEAR Intents team patched the contract bug in its Omni deposit and withdrawal infrastructure and announced that all affected users would receive full compensation for the estimated $3.8 million in losses.




