Float Protocol Loses $28,000 in Flash Loan Attack via Uniswap Manipulation
How Hypervisor Contracts Enabled the Price Skew
Float Protocol suffered a financial loss of approximately $28,000, equivalent to 10.71 ETH, following a sophisticated on-chain attack. The incident occurred on August 31, 2026, when an unidentified hacker targeted the protocol’s liquidity mechanisms. The attacker exploited a vulnerability in how the system calculated rewards for liquidity providers. This event highlights ongoing security challenges in decentralized finance infrastructure.
Breaking news:
The exploit centered on the manipulation of spot prices within Uniswap V3. The attacker executed a flash loan, borrowing funds temporarily without collateral. They used this borrowed capital to skew the price data on the Uniswap pool. This artificial distortion affected the oracle readings used by Float Protocol. Consequently, the protocol’s Hypervisor contracts miscalculated the value shares owed to liquidity providers. The attacker then settled the transaction, capturing the difference between the manipulated value and the true market rate.
Why Did the Flash Loan Strategy Succeed?
The core of the vulnerability lay in the interaction between external price feeds and internal contract logic. Float Protocol relies on Uniswap V3 pools to determine asset valuations for its liquidity sharing model. The Hypervisor contracts are responsible for distributing these shares among participants. When the attacker injected a large volume of trades into the Uniswap pool, they created a temporary imbalance. This imbalance shifted the spot price away from its equilibrium state. The Hypervisor read this skewed price as accurate market data. It then adjusted the share calculations based on this incorrect input. The attacker closed the position immediately, reversing the trade to restore normal pricing. However, the damage was done because the share distribution had already been finalized during the manipulation window.
Flash loans allow users to borrow assets, execute complex transactions, and repay the loan within a single block. If the final balance is positive, the transaction succeeds; otherwise, it reverts. In this case, the attacker leveraged that atomicity to their advantage. They did not need to hold the borrowed funds long-term. Instead, they needed only enough time to trigger the price manipulation and lock in the erroneous share calculation. The speed of the attack meant that standard monitoring tools might have missed the anomaly until the transaction was confirmed. The lack of a price impact threshold or deviation check in the Hypervisor logic allowed the exploit to proceed without interruption.
The loss of $28,000 represents a significant but manageable setback for Float Protocol. While the amount is modest compared to major DeFi hacks, the mechanism reveals a critical design flaw. Developers must now review how external price sources are integrated into reward calculations. Future updates may include circuit breakers or multi-source oracle verification to prevent similar skews. Investors should monitor the protocol for patches that address this specific vector. The incident serves as a reminder that even established protocols remain vulnerable to clever exploitation of their underlying assumptions. Security audits will likely focus on strengthening the link between spot prices and share accounting in the coming weeks.
Frequently Asked Questions
How much did the attacker profit from the exploit? The attacker gained approximately $28,000, which equals 10.71 ETH. This amount reflects the discrepancy created by the manipulated spot price during the transaction.
Which component of Float Protocol was compromised? The Hypervisor contracts were the primary target. These contracts failed to account for the temporary price distortion caused by the flash loan on Uniswap V3.
More stories: