Weex Thetanuts Finance Vault Exploit Results in $2.1M Loss
Article Content
- •Thetanuts Finance lost $2.1 million due to an exploit of a deprecated vault.
- •A vulnerability in the vault's redemption logic was identified as the attack vector.
- •The incident reflects a broader trend of attacks on deprecated DeFi protocols.
Thetanuts Finance confirmed an exploit on June 15, 2026, draining $2.1 million from a deprecated vault. The vault, which had been migrated years ago, was compromised due to a vulnerability in its redemption logic. PeckShieldAlert reported that approximately $2 million in option tokens were recovered by whitehat efforts, while the attacker converted $105,000 in USDC to around 60 ETH. The remaining funds include $34,000 in USDC-denominated option tokens held by the attacker. The incident highlights the risks associated with deprecated protocols, as similar attacks have occurred recently, including one on Aztec Connect. Thetanuts Finance reassured users that current contracts are not affected and plans to release a full post-mortem report. The total value hacked in DeFi for June has surpassed $46 million, indicating a concerning trend in security incidents.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Aztec Connect in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…