PublicAML

BitBay StableVault Exploited for $14,000

BitBay's Polygon DAI/USDC vault was exploited, resulting in a loss of approximately $14,000.

On October 9, 2026, BitBay’s Polygon DAI/USDC vault, known as UsdcDaiV4Vault, was exploited. The attacker executed a call to the reposition() function, which forced the vault’s liquidity to zero. Following this, the attacker redeemed a minimal share of the vault, triggering a flaw in the withdrawal mechanism.

The exploit took advantage of the fact that when liquidity is zero, the _withdraw() function sends the entire token balance of the contract instead of the user’s proportional share. As a result, approximately 14,838.47 DAI, equivalent to roughly $14,000, was drained from the vault. The incident highlights a critical vulnerability in the contract's withdrawal logic that allowed for this significant loss.

Sources

Share:XTelegramLinkedIn
BitBay StableVault Exploited for $14,000 | PublicAML