Thetanuts Finance Hack: $2.1 million from an abandoned vault and fund recovery
The decentralized finance (DeFi) protocol Thetanuts Finance suffered an attack, resulting in the withdrawal of approximately $2.1 million. However, in an unexpected turn of events, white hat hackers returned most of the stolen funds — about $2 million. The incident affected an outdated vault that the project stopped using several years ago.
How the attack occurred
Companies specializing in blockchain project security were the first to signal the incident. SlowMist analysts determined that the cause of the hack was an integer division error in the internal minting function of the smart contract. After the funds were withdrawn, the deposit formula began returning zero due to rounding characteristics in integer division. This allowed the attacker to mint tokens in unlimited quantities without any cost.
According to PeckShield, the hacker exchanged $105,000 in USDC for approximately 60 Ethereum (ETH). The attacker's wallet still contains option tokens worth about $34,000.
The Thetanuts team publicly commented on the situation:
"Our initial analysis shows: again, this involves an outdated vault that we stopped working with long ago. This incident is in no way related to current smart contracts and active products. After clarifying the details, we will publish a detailed report."
Alarming trend: attacks on 'dead' contracts
The Thetanuts case is not isolated. It is part of a series of attacks on forgotten or outdated smart contracts. Even after support is discontinued, such contracts often continue to function on the network, remaining vulnerable. Previously, a similar incident occurred with the Aztec Connect protocol, from which about $2.1 million was withdrawn, as well as with Raydium liquidity pools, which lost approximately $1.3 million.
Expert opinion: This hack is a stark reminder that 'dead code' on the blockchain does not disappear without a trace. Projects need to implement practices of completely destroying or locking old contracts, rather than simply leaving them unsupported. Otherwise, these 'digital ghosts' will continue to attract attackers, and users may suffer due to assets that, seemingly, are no longer in use.