The Arrakis V1 / G-UNI ENS-WETH liquidity-manager vault was drained via Uniswap V3 spot-price manipulation on August 23, 2026. An attacker used a flash loan to distort the pool's price, mint vault shares, and then redeem them for a profit of approximately 2.94 WETH.
Atomic Green was exploited due to a signature replay vulnerability on Arbitrum, resulting in a loss of approximately $29,984. The attacker replayed manager signatures across Uniswap V3 LP positions, triggering unauthorized LP burns.
A third-party Gnosis Safe module named SquidRouterModule was exploited on Ethereum and Base, draining approximately $3.2 million from 86 wallets. The module had improper access control, allowing unauthorized token spending.
Singularity Finance vaults were exploited due to an oracle misconfiguration where an unsupported fee tier caused the oracle to value non-USDC reserves at zero. An attacker used a flash loan to mint vault shares at this incorrect ratio and redeemed them for actual assets, draining approximately $413,000. The misconfiguration had been present for about three months.
Aperture LM was exploited for approximately $3.67 million across Ethereum, Base, Arbitrum, and BSC due to an arbitrary-call vulnerability in its contracts. Attackers abused existing user token and Uniswap V3 LP NFT approvals to drain funds. The team paused affected features and urged users to revoke approvals.