Go to app

Thetanuts Finance $2.1M Exploit — June 15, 2026

Published 6/16/2026, 1:37:55 AM

On June 15, 2026, Thetanuts Finance suffered an exploit draining approximately $2.1 million from a deprecated legacy vault on Ethereum. The attack was not a traditional flash loan attack in the classic reentrancy sense — it was a rounding vulnerability in the vault's redemption logic, amplified by flash-loaned capital.


Attack Mechanics

ComponentDetail
Vulnerable ContractDeprecated "Cash Settled Covered Call BTC/USD" vault on Ethereum
Root CauseFlawed share payout formula: backing × amount / totalSupply
Attack VectorRounding error exploitation during redemption
Capital AmplificationFlash-loaned 10 WBTC from Morpho to magnify the exploit [Note: Morpho supports WBTC borrowing per its documentation, but the specific flash loan transaction in this exploit was not independently confirmed]
Research AttributionSecurity researcher ExVul identified the redemption math flaw on X

The attacker flash-loaned 10 WBTC from Morpho, then exploited the rounding vulnerability in the deprecated vault's share calculation mechanism. By carefully manipulating the backing, amount, and totalSupply variables during redemption, the attacker withdrew more funds than their actual share entitlement warranted.


Fund Flow & Disposition

CategoryAmountStatus
Total Exploited$2.1MDrained from deprecated vault
Whitehat Recovered~$2MOption tokens recovered post-attack
Attacker Converted~$105K USDC → ~60 ETHSwapped before whitehat could intervene
Attacker Remaining~$34KUSDC-denominated option tokens still held

Detection & Timeline

  • Blockaid's exploit detection system independently flagged active exploitation, sharing both the exploiter's address and the exploited contract address in a community alert.
  • PeckShieldAlert was first to publicly flag the incident, reporting ~$2M in option tokens appeared recovered via whitehat.
  • Thetanuts Finance confirmed within hours via X, stating the vault was "deprecated years ago" and had "no relation to any of our current contracts or products."

Broader Context

This was not Thetanuts' first exploit in 2026. On April 20, 2026, a First Depositor Attack on a newly deployed vault contract drained ~$50,000 by exploiting share calculation logic when totalAssets and totalSupply were both 0 at initialization. That was a separate vulnerability in initialization logic — not the same flaw.

The June incident adds to a pattern of deprecated/abandoned protocols being targeted:

  • Aztec Connect (privacy bridge, abandoned 2023): Lost $2.1M through a separate verification flaw in immutable contracts.
  • Both Aztec and Thetanuts had renounced admin keys, leaving no ability to patch or pause code.

Key Takeaways

  1. "Deprecated" ≠ "Safe" — Abandoned code with no admin control remains a liability.
  2. Rounding vulnerabilities in share-based vault redemption math can be exploited with flash loans to amplify damage.
  3. Whitehat effectiveness — 95% of stolen funds ($2M) were recovered through whitehat efforts.
  4. No current product impact — Thetanuts v3 contracts and the upcoming v4 RFQ architecture were unaffected.
  5. Industry-wide risk — DeFi protocols collectively crossed ~$46 million in mid-June 2026 exploit losses, with deprecated contracts a growing attack surface.

Claims Resolution

ClaimStatusNotes
c1: $2.1M loss from flash loan exploitPartially SupportedLoss amount confirmed; the attack used a flash loan but was fundamentally a rounding vulnerability, not a classic flash loan attack
c2: Flash loan mechanics + protocol vulnerabilitySupportedFlash loan from Morpho amplified a redemption math flaw
c3: Token price manipulation vs. logic flawPartially SupportedLogic flaw (rounding vulnerability) confirmed; token price manipulation was not identified

Note on citations: The research output references sources labeled "Web search result1", "Web search result2", etc., but does not include actual URLs. The technical details above are drawn from the research content, but verifiable source URLs were not provided in the skill outputs for citation.


Suggested Next Steps

  1. Monitor the attacker address for any movement of the remaining ~$34K in option tokens — on-chain alerts can be set up to track this wallet.
  2. Audit deprecated vault exposure across your portfolio or watched addresses, since this incident highlights that abandoned contracts remain attack surfaces even years after deprecation.