MALT Hack

Reported loss $72K
Other

What happened

On October 3, 2026, the MALT protocol on Polygon was exploited for ~$72,000 USD due to a smart contract state-ordering flaw that misattributed treasury-funded rebalancing capital as user-supplied swap liquidity.

The vulnerability was caused by an input attribution and state snapshot flaw within the swap(uint256,uint256,address) function of contract 0xfe6C, which snapshotted pre-swap pool reserves and caller input before executing an external rebalanceHook prior to output transfer. During execution, the hook withdrew DAI from the protocol's Capital Source and deposited it directly into the pool; however, the swap function then validated its invariant against the pool's final balances without separating caller-supplied tokens from protocol-funded rebalancing capital. Exploiting this lack of isolation, the attacker supplied a negligible input to trigger the mid-swap treasury liquidity injection and subsequently withdrew a disproportionately large payout of MALT tokens from pool 0xF0d3.

Attack Transaction Hash: 0x915eccb5…e8445b

Attacker Address: 0x8F103B6A…8D83Ef

Victim / Pool Address: 0xF0d31484…5A2AAC

Vulnerable Contract: 0xfe6C096a…4D7A13

Protocol details

Classification Exchange (DEX)
Protocol Type Exploit/Other

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.