NewsCryptoMALT Loses $72K After Flawed Swap Function Lets Attacker Tap Treasury DAI

MALT Loses $72K After Flawed Swap Function Lets Attacker Tap Treasury DAI

Author: CryptoNewsNet·

Key Takeaways

  • •An attacker drained approximately $72,000 from MALT by exploiting a flaw in the protocol's swap function, as reported by blockchain security firm SlowMist.
  • •The vulnerability stemmed from a rebalanceHook that moved treasury-funded DAI into the pool mid-swap, allowing the swap's validity check to treat protocol-owned liquidity as the trader's input.
  • •The flaw failed to separate user funds from capital added during rebalancing, so the attacker supplied only a minimal amount while extracting excess MALT funded by the protocol's treasury.
  • •Recent comparable incidents include NEAR Intents halting services after an Oct. 1 exploit with about $3.8 million in losses, and a FlashLoopAdapter attack that drained roughly $305,000 from two Safe wallets holding Aave V3 positions without touching Aave's core contracts.
  • •DeFiLlama data shows cumulative DeFi hack losses exceeding $21 billion, including about $9.28 billion from DeFi protocols and $3.69 billion from bridges, and no response from the MALT team has been detailed.
MALT Loses $72K After Flawed Swap Function Lets Attacker Tap Treasury DAI

A decentralized finance (DeFi) attacker drained approximately $72,000 from MALT by exploiting a flaw in the protocol's swap function, according to blockchain security firm SlowMist.

The attacker supplied only a small amount of input to trigger the faulty swap, then received more MALT than the transaction should have allowed. SlowMist said the exploit involved $DAI supplied by MALT's treasury, allowing the attacker to extract funds directly from the protocol.

🚨SlowMist TI Alert🚨
💸 MALT Loss: ~$72k
🔍 Root Cause: swap(uint256,uint256,address) records the caller's input and pre-swap reserves, then invokes an external rebalanceHook before transferring the requested output. The hook withdraws $DAI from the Capital Source and deposits…

— SlowMist (@SlowMist_Team) October 3, 2026

Swap Flaw Lets Attacker Tap Treasury Funds

According to SlowMist, the flaw affected MALT's swap(uint256,uint256,address) function. The function recorded the trader's input and the pool's pre-swap reserves before calling an external rebalancing hook.

That hook then withdrew $DAI from MALT's Capital Source and deposited it back into the pool. As a result, the swap treated the treasury-funded $DAI as trader-supplied funds during its validity check.

This meant the attacker needed to provide only a minimal amount of input while benefiting from liquidity funded by the protocol itself. The flaw, SlowMist noted, also failed to properly separate user funds from capital added during rebalancing.

The incident underscores how DeFi vulnerabilities can emerge from the interaction between custom components rather than from swap mechanics alone. Because the rebalancing hook moved treasury capital into the pool mid-swap, the protocol's own liquidity could satisfy a check meant to validate a trader's contribution — the kind of gap that opens when user funds and protocol-owned funds share the same accounting path.

MALT Exploit Adds to DeFi Losses

The MALT incident follows a series of recent attacks targeting DeFi projects.

$NEAR Intents halted its services after an Oct. 1 exploit that caused losses of approximately $3.8 million. The team said it has since fixed the contract flaw and will fully compensate affected users.

Earlier today $NEAR Intents services were stopped after a security incident was detected. The incident was caused by a bug in the Omni deposit and withdrawal infrastructure interaction with $NEAR Intents smart contract. The preliminary report indicates the total loss of…

— $NEAR Intents (@near_intents) October 1, 2026

Separately, a FlashLoopAdapter exploit drained about $305,000 from two Safe wallets holding Aave V3 positions. The attack, however, targeted the custom adapter module rather than Aave V3's core contracts.

As with MALT's exploit, the FlashLoopAdapter incident centered on custom protocol-level code rather than the core contracts of a widely used lending market.

DeFi hacks have caused more than $21 billion in total losses, according to DeFiLlama data. About $9.28 billion of that figure came from DeFi protocols, while bridges accounted for $3.69 billion.

MALT's roughly $72,000 loss is small against those cumulative figures. SlowMist's alert did not detail any response from the MALT team, and the NEAR Intents handling — a service halt, a fixed contract flaw and a commitment to full compensation — illustrates the remediation steps projects have taken in comparable incidents, leaving it to be seen whether MALT will take similar measures.