Crypto news

16.06.2026
07:47

Thetanuts Finance: $2.1 million exploit of legacy vault and fund recovery

The DeFi protocol Thetanuts Finance was attacked. The attacker withdrew approximately $2.1 million from a long-unused contract. However, according to blockchain analysts, almost the entire amount was returned.

The incident affected an old vault that the protocol stopped using several years ago. Thetanuts emphasized that this contract is not connected to current products or active infrastructure. This is an important nuance that alleviates some concern for users of existing liquidity pools.

How the hack occurred

Security specialists were the first to raise the alarm. The SlowMist team identified that the vulnerability lay in an integer division error within the smart contract's internal mint function. Due to rounding peculiarities in deposit calculations, the formula began returning zero. This allowed the hacker to mint tokens literally out of thin air — in unlimited quantities.

According to PeckShield data, the attacker exchanged $105,000 in USDC for approximately 60 ETH. At the time of analysis, their wallet still contained option tokens worth about $34,000. However, notably, "white hat hackers" returned approximately $2 million of the stolen funds. This suggests the attack may have been part of a bounty hunt or coordinated community efforts to rescue assets.

The Thetanuts team publicly commented on the situation: "Our preliminary analysis shows that this involves an outdated vault that we stopped working with long ago. This incident is in no way connected to active smart contracts or current products. After clarifying the details, we will publish a detailed report."

Trend of attacks on forgotten contracts

The Thetanuts case is part of a concerning series of attacks on forgotten or outdated smart contracts. Even after support is discontinued, such contracts often continue to operate, remaining "time bombs." We previously observed a similar situation with Aztec Connect, from which about $2.1 million was withdrawn, and with Raydium liquidity pools, which lost approximately $1.3 million.

My opinion: This incident is yet another reminder to the entire industry of the critical importance of auditing and timely withdrawal of funds from outdated contracts. DeFi protocols need to implement procedures for "destroying" or fully blocking old vaults, rather than simply discontinuing their support. Otherwise, we risk seeing a whole wave of such exploits, where hackers hunt for "digital corpses."