Impermax V3 Hack
Incident Overview
On April 27–28, 2025, Impermax V3 suffered an exploit resulting in a loss of approximately $300K, with an additional $300K–$350K at risk if borrowers repay loans and unlock vulnerable liquidity.
The attacker exploited a misvaluation in how Impermax handled uncollected trading fees used as collateral. By manipulating a low-liquidity Uniswap V3 pool and inflating the uncollected fee value through multiple swaps, they were able to borrow against this artificially high collateral. They then auto-compounded the fees at an incorrect price tick, reducing real collateral value due to impermanent loss, before reverting the tick to extract value.
The attacker repeated this process to drain available liquidity and dilute lenders via the restructureBadDebt() function, securing stolen funds before legitimate users could react.
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Impermax V3, these are the critical security checks that could have prevented this incident (April 2025).
- Verify all logic paths related to Flashloan Exploit / Other are guarded by proper access controls and input validation - see the Flash Loans Attacks attack class for patterns
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialRelated Attack Classes
The technique used in this hack maps to these vulnerability classes in our security curriculum:
Sources & References
Learn to Prevent the Next Impermax V3
The Impermax V3 hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.