MetaSea Hack

Reported loss $110K
Arbitrum
Withdrawal

What happened

On May 17, 2026, MetaSea's SEA round product on Arbitrum was exploited for approximately $110,000 across the attacker's repeated transactions. The attacker drained SEA rewards from a shared distributor by opening and redeeming positions in the same transaction.

Technical root cause

MetaSea's redeemPosition flow made SEA yield immediately claimable in the same block as position creation and sized the payout from a shared distributor without a time- or participation-weighted limit, so flash-loan-funded open-and-redeem cycles extracted more SEA than they contributed.

How it happened

The attacker used a 3,300 USDT Aave flash loan, repeatedly opened 3,000-USDT positions, immediately redeemed them, and sold the resulting SEA. The focal transaction netted approximately 13,905 USDT and the attacker repeated the pattern across eight transactions.

Protocol details

Classification Protocol Logic
Protocol Type DeFi Protocol
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.