Uniswap V3 security incidents
-
Arrakis V1 hacked
The Arrakis V1 / G-UNI ENS-WETH liquidity-manager vault was drained via Uniswap V3 spot-price manipulation on August 23, 2026. An attacker used a flash loan to distort the pool's price, mint vault shares, and then redeem them for a profit of approximately 2.94 WETH.
-
Atomic Green — Signature Replay
Atomic Green was exploited due to a signature replay vulnerability on Arbitrum, resulting in a loss of approximately $29,984. The attacker replayed manager signatures across Uniswap V3 LP positions, triggering unauthorized LP burns.
-
Third-party Gnosis Safe Module (SquidRouterModule) hacked
A third-party Gnosis Safe module named SquidRouterModule was exploited on Ethereum and Base, draining approximately $3.2 million from 86 wallets. The module had improper access control, allowing unauthorized token spending.
-
Singularity Finance hacked
Singularity Finance vaults were exploited due to an oracle misconfiguration where an unsupported fee tier caused the oracle to value non-USDC reserves at zero. An attacker used a flash loan to mint vault shares at this incorrect ratio and redeemed them for actual assets, draining approximately $413,000. The misconfiguration had been present for about three months.
-
Aperture LM — Token Approval Abuse
Aperture LM was exploited for approximately $3.67 million across Ethereum, Base, Arbitrum, and BSC due to an arbitrary-call vulnerability in its contracts. Attackers abused existing user token and Uniswap V3 LP NFT approvals to drain funds. The team paused affected features and urged users to revoke approvals.