PublicAML

EtherVista liquidity pool exploited for $18,600

EtherVista suffered a loss of approximately $18,600 due to an exploit in its liquidity pool. The attack involved an integer overflow in the K-invariant check during token swaps.

The incident involved EtherVista's liquidity pool being exploited through a vulnerability in the K-invariant check within the EtherVistaPair.swap() function. This vulnerability arose from the use of uint112 for both reserves, allowing the product of the reserves to wrap around, which enabled the check to pass even when the actual reserve product significantly decreased. The attacker took advantage of this flaw by registering a self-controlled contract as an authorized router.

The attacker executed two carefully crafted swaps that drained both WETH and VISTA from the liquidity pool. The total loss incurred from this exploit was approximately $18,600. The mechanism of the attack highlights the risks associated with integer overflow vulnerabilities in smart contracts, particularly in liquidity pools where reserve calculations are critical.

The incident occurred on the Ethereum chain, which means that the transactions can be traced through its public ledger. However, specific addresses involved in the exploit were not provided in the description. The on-chain record would reflect the transactions made by the self-controlled contract, detailing the movement of funds from the liquidity pool.

Sources

Share:XTelegramLinkedIn
EtherVista liquidity pool exploited for $18,600 | PublicAML