Visor Finance Hack

TOTAL LOST $976K
Low Flash Loan Attacks ethereum

What happened

Visor Finance's OHM-ETH 1% Uniswap V3 Hypervisor was exploited at 13:18 UTC on November 25, 2021. The source record uses November 26, while the protocol's incident material records the execution on November 25 UTC. The attacker used temporary WETH liquidity to move the concentrated-liquidity spot price, mint receipt shares at an inflated rate, restore the price, and redeem the oversized shares.

Published value estimates vary; the record retains the incident-database estimate of about $975,720.

Technical Root Cause

The receipt-share calculation for a single-sided concentrated-liquidity deposit trusted an atomically manipulable Uniswap V3 current spot price. A flash-funded trade could move that price during the deposit and make the protocol mint too many shares. Such systems need manipulation-resistant valuation, bounded price deviation, and tests that traverse sparse concentrated-liquidity ticks with temporary liquidity.

Case & protocol details

Classification Uniswap V3 Spot-Price / Receipt-Share Manipulation
Protocol Type Exploit/Flash Loan Attack
Affected asset / contract VISR
Smart Contract Language Solidity
Official Website www.visor.finance/
Protocol Twitter/X @visorfinance

Attack Timeline

The attacker obtained 615 WETH, swapped 606.12 WETH for OHM, and moved the Uniswap V3 spot price through a thin liquidity range. They deposited only 10 OHM while the Hypervisor's share-minting path used the manipulated current tick, receiving 49.77 LP shares at roughly 68 times the appropriate rate. After restoring the price, they redeemed the oversized shares for OHM and WETH and repaid the temporary liquidity.

The operation was repeated with diminishing returns; the protocol reported that affected-user funds were secured.

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.