Web3 Daily Exploits — 06 Sep 2026: Reddio ~9.25 ETH Vault Double-Count + Autonolas Gov Attempt
A quiet window produced one confirmed low-value vault exploit and one blocked governance attempt. Reddio’s RedSonic Vault lost approximately 9.25 ETH to a cross-vault double-counting flaw; a malicious Autonolas proposal targeting ~40 ETH remains unexecuted.

A quiet window produced one confirmed low-value vault exploit and one blocked governance attempt. Reddio’s RedSonic Vault lost approximately 9.25 ETH to a cross-vault double-counting flaw; a malicious Autonolas proposal targeting ~40 ETH remains unexecuted.
Security monitors recorded limited new activity in the past 24 hours. The Reddio incident is confirmed on-chain. The Autonolas proposal has been flagged and the team intends to vote it down. No major bridge, oracle, or high-value protocol drains were newly reported or materially updated in the window. Older incidents such as Notional and Dream Health Chain fall outside the strict 24-hour cutoff and are not re-covered here.
Reddio RedSonic Vault — ~9.25 ETH (Ethereum) — Confirmed
What happened: An attacker drained approximately 9.25 ETH from Reddio’s RedSonic Vault by exploiting a cross-vault asset double-counting vulnerability combined with a flash loan.
Protocol / chain / asset: Reddio (RedSonic Vault / rsvETH) on Ethereum. Assets involved: ETH / WETH and stETH.
Loss: ~9.25 ETH (roughly $23k at contemporaneous prices). No recovery or rollback reported at time of writing.
Attack type: Accounting flaw / permissionless asset registration + shared collateral double-counting + flash-loan price inflation.
Technical details: The ETH vault’s getTotalAssetBalance(ETH) included the raw stETH balance of the vault. Because registerErc20() was permissionless, the attacker registered stETH as a second asset (rsvstETH). The same stETH therefore backed both rsvETH and rsvstETH share classes. Flow (single transaction): flash-loan ~1,139 WETH from Balancer → deposit majority of ETH to control rsvETH shares → register and deposit ~9.34 stETH (inflating rsvETH share price) → redeem inflated rsvETH for excess ETH → redeem rsvstETH to recover the stETH → repay loan. The 2% withdrawal cap did not prevent the share-price manipulation.
Explorer links:
- Attacker: https://etherscan.io/address/0x70f2333d21ed7e7d105f6578227a9a747687982c
- Victim Diamond: https://etherscan.io/address/0x4315990d9eeaffdfafd49958b4851f203fa1126f
- Vulnerable implementation: https://etherscan.io/address/0x92ecc5deacb14937867686ca8b85dd8a65b74704
- Main attack tx: https://etherscan.io/tx/0xe3cba90e865c6cba950ebce36a52607f51f1fd33cd9fb920c78803f19b57791a
Status: Confirmed. Funds moved; no public recovery announcement.
Sources: https://x.com/SlowMist_Team/status/2096439593403089077, https://x.com/exvulsec/status/2096277307757572517
Autonolas Treasury — Malicious Governance Proposal (~40 ETH / ~$100k at risk) — Unexecuted / Flagged
What happened: A Tornado-funded attacker submitted a governance proposal titled “Owner migration: transfer treasury ownership from old timelock to Safe updater.” Execution would have transferred treasury ownership to an attacker-controlled contract, enabling withdrawal of the treasury balance.
Protocol / chain / asset: Autonolas on Ethereum. Treasury holding ~40.196 ETH.
Loss: None realized. ~$100k equivalent still at risk until the proposal is defeated.
Attack type: Malicious governance proposal / social-engineering style ownership transfer.
Technical details: Attacker registered the ENS name “autonolas-deployer.eth” and submitted the proposal. If executed, ownership would move from the legitimate Autonolas Timelock to the attacker contract. Community and monitors have three days to vote it down. Defimon shared the alert in the project’s community chat; the team has indicated it will vote the proposal down.
Status: Unexecuted. Team aware and planning to reject.
Sources: https://x.com/DefimonAlerts/status/2096432367908933790
Also noted
- No additional confirmed high-impact incidents first reported or materially updated in the strict last-24-hour window after cross-checks of DefimonAlerts, SlowMist, CertiKAlert, Phalcon, GoPlus, PeckShield, BlockSec, Lookonchain, and related monitors.
Sources & references
- https://x.com/SlowMist_Team/status/2096439593403089077
- https://x.com/exvulsec/status/2096277307757572517
- https://x.com/DefimonAlerts/status/2096432367908933790
- https://etherscan.io/tx/0xe3cba90e865c6cba950ebce36a52607f51f1fd33cd9fb920c78803f19b57791a
Editor’s note: Quiet day. All figures are live losses after any known reversals; no how-to details are included. Always verify on-chain before acting on alerts.
Read more

Web3 Daily Exploits — 07 Sep 2026: Liquid $320M Whitehat Peg-Out + Cozy $170K
Liquid Network sees ~4,000 BTC (~$320M) unauthorized peg-out claimed as whitehat; Cozy Finance loses ~$170k on Optimism via UMA oracle abuse; Secured Finance ~$104k price-manipulation drain on Ethereum; Rocket $287k update.

Web3 Daily Exploits — 05 Sep 2026: Notional $1.7M Overflow + Dream Health $72k Logic Drain
Notional Finance lost ~$1.73M on Ethereum via an unsafe uint128 downcast in free-collateral checks. A separate ~$72k logic flaw drained Dream Health Chain awards on BSC.

Web3 Daily Exploits — 04 Sep 2026: Notional $1.7M integer overflow drain
Notional Finance lost ~$1.7M on Ethereum via an unsafe uint128 downcast in free-collateral checks. Attacker minted extreme fCash pairs and drained escrow before mixing via Tornado Cash.

Web3 Daily Exploits — 03 Sep 2026: Quiet window with governance alert and small drain
No major new exploits confirmed in the last 24 hours. Smaller alerts include a Yam Finance governance takeover attempt and a ~6 ETH GebProxyActions drain on Ethereum.

