DeFiTuna Hack
What happened
On July 16, 2026, the Solana-based lending protocol DeFiTuna suffered a smart contract exploit targeting its USDC lending pool, resulting in a loss of approximately $570,000 and leaving the lending pool at a direct deficit.
The exploit targeted a critical logic and mathematical truncation flaw in the protocol's position solvency check. In DeFiTuna's architecture, if a position's total calculated assets evaluated to zero, the contract's fallback logic automatically assumed the position was empty and perfectly healthy. The attacker exploited this by opening a spot position with zero collateral and using the integrated router to borrow $570,000 USDC from the lending pool.
They immediately swapped this USDC for a tiny fraction of TUNA tokens inside a highly illiquid, custom-seeded pool. Due to the extreme price skew, the asset value of the resulting TUNA tokens was so small that when converted to an integer via the protocol's fixed-point math routine, it truncated and rounded down to exactly zero. Because the total asset calculation returned zero, the contract skipped further health checks and deemed the position safe, allowing the attacker to cleanly walk away with the borrowed USDC.
The stolen funds were bridged from Solana to Ethereum via Mayan, where a portion was shielded through Railgun and the rest converted to DAI.
Intermediary Ethereum Wallet: 0x509b9d094a6c26d716aac131e8adee5b16b86d3e
Case & protocol details
Security review history
- Sec3 Report
Evidence & learning
Sources and on-chain records
- report Report x.com
- report Report x.com
- report Report x.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.