Revisiting The Redemption Flashloan Attack
ID: 49eaa6aa-191c-5b33-8509-565a817d9c48
STIX ID: report--49eaa6aa-191c-5b33-8509-565a817d9c48
Feed Name: CertiK Blog
On April 18, 2022 a coordinated flash-loan attack exploited a design flaw in the RedemptionPair (a modified Uniswap V2 pair) that allowed repeated flash-loan operations to remove tokens from the pool, artificially inflate the 2OMB price in the Redemption LP, and extract approximately 4 million 2OMB (~$1.6M). The report provides transaction-level analysis, identifies the root cause (controller fee paid after the K invariant check and a zero/default feeAmount), and enumerates affected LP contracts—issues that would likely be detected in a targeted audit of the nonstandard pair implementation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
