Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnAISquareMore
RedSonic Vault exploited for 9.25 ETH with flash loan, ExVulSec reveals root flaw

RedSonic Vault exploited for 9.25 ETH with flash loan, ExVulSec reveals root flaw

CointurkCointurk2026/09/05 20:24
By:Cointurk

A vulnerability in the RedSonic Vault on Ethereum enabled an attacker to drain 9.25 ETH using a complex flash loan exploit in a single transaction. Blockchain security firm ExVulSec identified and analyzed the incident, outlining how the vault’s dual-asset pricing flaw was entirely compromised.

Flash loan powers single-transaction exploit

The attacker launched their operation by borrowing 1,139 WETH from Balancer through a flash loan, which allowed the necessary capital without tying up their own funds. Flash loans are commonly used in decentralized finance (DeFi) to borrow significant sums, as long as the funds are returned within the same transaction, making them useful for both legitimate arbitrage and malicious exploits.

ExVulSec reported that the vulnerability lay in the RedSonic Vault’s registerErc20 function, which carried no access restrictions. This made the function permissionless, enabling anyone to register a new asset or share class within the vault, undermining protection against unauthorized manipulations.

By leveraging this function, the attacker registered stETH as a second asset under a new share class called rsvstETH. This setup allowed both rsvETH and rsvstETH shares to draw value from the same underlying stETH balance.

ETH
SOL
BSC
ROBINHOOD
PAY
USDT
RECEIVE
AAPL

ExVulSec traced the operation in detail, showing that each step from the asset registration to the unwinding of the flash loan was performed within a single, self-contained blockchain transaction. The malicious smart contract used for the exploit self-destructed at the end of execution, a tactic often used to hinder post-incident on-chain tracking.

Mini dictionary: ExVulSec – A blockchain security research group specializing in post-mortem analysis of smart contract exploits and real-time incident response for DeFi vulnerabilities.

Vault pricing flaw allows double withdrawal

The exploit began when the attacker deposited 1,130 ETH to obtain nearly all of the rsvETH shares in the vault. This move positioned them to benefit from further manipulations in the vault’s asset balance.

Subsequently, the attacker deposited 9.34 stETH, which increased the raw stETH balance in the vault but did not mint new rsvETH shares, a result of how the pricing function getTotalAssetBalance was designed. Since rsvETH share price was tied to the raw balance, this action artificially inflated the share value.

With the rsvETH price boosted, the attacker redeemed their shares to receive 1,139.5 ETH, effectively extracting the profit. They also redeemed the newly created rsvstETH shares for stETH, exploiting the vault’s dual-asset mechanism to perform a double withdrawal against the same underlying collateral.

Step Action Result
1 Flash loan 1,139 WETH from Balancer Secured capital for exploit
2 Deposit 1,130 ETH Acquired nearly all rsvETH shares
3 Register stETH as new share class (rsvstETH) Enabled dual access to same collateral
4 Deposit 9.34 stETH Artificially inflated rsvETH price
5 Redeem rsvETH for ETH Extracted 1,139.5 ETH
6 Redeem rsvstETH for stETH Double withdrawal from same pool
7 Swap recovered stETH for ETH on Curve Finalized profits
8 Repay Balancer loan Secured 9.25 ETH net profit

ExVulSec’s investigation revealed that the attacker inflated the vault’s share price by artificially increasing the stETH balance, then redeemed both the original and duplicate shares for separate withdrawals from the same collateral pool.

After securing the funds, the attacker used Curve, a decentralized exchange protocol known for efficient stablecoin and token swaps, to exchange stETH back to ETH and repay the original Balancer flash loan, wrapping up the attack in one transaction.

The attack was publicly documented, with the main transaction traceable on Etherscan under the hash 0xe3cba90e865c6cba950ebce36a52607f51f1fd33cd9fb920c78803f19b57791a. Key contracts and wallets involved include the RedSonic Vault contract at 0x4315990d9eeaffdfafd49958b4851f203fa1126f and the attacker’s wallet 0x70f2333d21Ed7E7D105F6578227A9A747687982C.

ExVulSec cautioned that self-destructing exploit contracts complicate subsequent forensic reviews, as they erase on-chain code references immediately after the attack completes.

Investigators detail that both the initial deposit and asset registration combined with a flash loan enabled the attacker to fully extract and swap their gains before contract self-destruction obscured further evidence.

0
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

Understand the market, then trade.
Bitget offers one-stop trading for cryptocurrencies, stocks, and gold.
Trade now!