logo

Revisiting The Redemption Flashloan Attack

ID: 49eaa6aa-191c-5b33-8509-565a817d9c48

STIX ID: report--49eaa6aa-191c-5b33-8509-565a817d9c48

Feed Name: CertiK Blog

Threat Score
72/100

Date Published: 2022-07-04

Date Updated: 2026-06-11

...
...

On April 18, 2022 a coordinated flash-loan attack exploited a design flaw in the RedemptionPair (a modified Uniswap V2 pair) that allowed repeated flash-loan operations to remove tokens from the pool, artificially inflate the 2OMB price in the Redemption LP, and extract approximately 4 million 2OMB (~$1.6M). The report provides transaction-level analysis, identifies the root cause (controller fee paid after the K invariant check and a zero/default feeAmount), and enumerates affected LP contracts—issues that would likely be detected in a targeted audit of the nonstandard pair implementation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.