Thetanuts Finance $2.1M Exploit — June 15, 2026
Published 6/16/2026, 1:37:55 AM
On June 15, 2026, Thetanuts Finance suffered an exploit draining approximately $2.1 million from a deprecated legacy vault on Ethereum. The attack was not a traditional flash loan attack in the classic reentrancy sense — it was a rounding vulnerability in the vault's redemption logic, amplified by flash-loaned capital.
Attack Mechanics
| Component | Detail |
|---|---|
| Vulnerable Contract | Deprecated "Cash Settled Covered Call BTC/USD" vault on Ethereum |
| Root Cause | Flawed share payout formula: backing × amount / totalSupply |
| Attack Vector | Rounding error exploitation during redemption |
| Capital Amplification | Flash-loaned 10 WBTC from Morpho to magnify the exploit [Note: Morpho supports WBTC borrowing per its documentation, but the specific flash loan transaction in this exploit was not independently confirmed] |
| Research Attribution | Security researcher ExVul identified the redemption math flaw on X |
The attacker flash-loaned 10 WBTC from Morpho, then exploited the rounding vulnerability in the deprecated vault's share calculation mechanism. By carefully manipulating the backing, amount, and totalSupply variables during redemption, the attacker withdrew more funds than their actual share entitlement warranted.
Fund Flow & Disposition
| Category | Amount | Status |
|---|---|---|
| Total Exploited | $2.1M | Drained from deprecated vault |
| Whitehat Recovered | ~$2M | Option tokens recovered post-attack |
| Attacker Converted | ~$105K USDC → ~60 ETH | Swapped before whitehat could intervene |
| Attacker Remaining | ~$34K | USDC-denominated option tokens still held |
Detection & Timeline
- Blockaid's exploit detection system independently flagged active exploitation, sharing both the exploiter's address and the exploited contract address in a community alert.
- PeckShieldAlert was first to publicly flag the incident, reporting ~$2M in option tokens appeared recovered via whitehat.
- Thetanuts Finance confirmed within hours via X, stating the vault was "deprecated years ago" and had "no relation to any of our current contracts or products."
Broader Context
This was not Thetanuts' first exploit in 2026. On April 20, 2026, a First Depositor Attack on a newly deployed vault contract drained ~$50,000 by exploiting share calculation logic when totalAssets and totalSupply were both 0 at initialization. That was a separate vulnerability in initialization logic — not the same flaw.
The June incident adds to a pattern of deprecated/abandoned protocols being targeted:
- Aztec Connect (privacy bridge, abandoned 2023): Lost $2.1M through a separate verification flaw in immutable contracts.
- Both Aztec and Thetanuts had renounced admin keys, leaving no ability to patch or pause code.
Key Takeaways
- "Deprecated" ≠ "Safe" — Abandoned code with no admin control remains a liability.
- Rounding vulnerabilities in share-based vault redemption math can be exploited with flash loans to amplify damage.
- Whitehat effectiveness —
95% of stolen funds ($2M) were recovered through whitehat efforts. - No current product impact — Thetanuts v3 contracts and the upcoming v4 RFQ architecture were unaffected.
- Industry-wide risk — DeFi protocols collectively crossed ~$46 million in mid-June 2026 exploit losses, with deprecated contracts a growing attack surface.
Claims Resolution
| Claim | Status | Notes |
|---|---|---|
| c1: $2.1M loss from flash loan exploit | Partially Supported | Loss amount confirmed; the attack used a flash loan but was fundamentally a rounding vulnerability, not a classic flash loan attack |
| c2: Flash loan mechanics + protocol vulnerability | Supported | Flash loan from Morpho amplified a redemption math flaw |
| c3: Token price manipulation vs. logic flaw | Partially Supported | Logic flaw (rounding vulnerability) confirmed; token price manipulation was not identified |
Note on citations: The research output references sources labeled "Web search result1", "Web search result2", etc., but does not include actual URLs. The technical details above are drawn from the research content, but verifiable source URLs were not provided in the skill outputs for citation.
Suggested Next Steps
- Monitor the attacker address for any movement of the remaining ~$34K in option tokens — on-chain alerts can be set up to track this wallet.
- Audit deprecated vault exposure across your portfolio or watched addresses, since this incident highlights that abandoned contracts remain attack surfaces even years after deprecation.