MALT Hack
What happened
On October 3, 2026, the MALT protocol on Polygon was exploited for ~$72,000 USD due to a smart contract state-ordering flaw that misattributed treasury-funded rebalancing capital as user-supplied swap liquidity.
The vulnerability was caused by an input attribution and state snapshot flaw within the swap(uint256,uint256,address) function of contract 0xfe6C, which snapshotted pre-swap pool reserves and caller input before executing an external rebalanceHook prior to output transfer. During execution, the hook withdrew DAI from the protocol's Capital Source and deposited it directly into the pool; however, the swap function then validated its invariant against the pool's final balances without separating caller-supplied tokens from protocol-funded rebalancing capital. Exploiting this lack of isolation, the attacker supplied a negligible input to trigger the mid-swap treasury liquidity injection and subsequently withdrew a disproportionately large payout of MALT tokens from pool 0xF0d3.
Attack Transaction Hash: 0x915eccb5…e8445b
Attacker Address: 0x8F103B6A…8D83Ef
Victim / Pool Address: 0xF0d31484…5A2AAC
Vulnerable Contract: 0xfe6C096a…4D7A13
Protocol details
Evidence
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.