Web3 Daily Exploits — 06 Sep 2026: Reddio ~9.25 ETH Vault Double-Count + Autonolas Gov Attempt

A quiet window produced one confirmed low-value vault exploit and one blocked governance attempt. Reddio’s RedSonic Vault lost approximately 9.25 ETH to a cross-vault double-counting flaw; a malicious Autonolas proposal targeting ~40 ETH remains unexecuted.

Web3 Daily Exploits — 06 Sep 2026: Reddio ~9.25 ETH Vault Double-Count + Autonolas Gov Attempt

A quiet window produced one confirmed low-value vault exploit and one blocked governance attempt. Reddio’s RedSonic Vault lost approximately 9.25 ETH to a cross-vault double-counting flaw; a malicious Autonolas proposal targeting ~40 ETH remains unexecuted.

Security monitors recorded limited new activity in the past 24 hours. The Reddio incident is confirmed on-chain. The Autonolas proposal has been flagged and the team intends to vote it down. No major bridge, oracle, or high-value protocol drains were newly reported or materially updated in the window. Older incidents such as Notional and Dream Health Chain fall outside the strict 24-hour cutoff and are not re-covered here.

Reddio RedSonic Vault — ~9.25 ETH (Ethereum) — Confirmed

What happened: An attacker drained approximately 9.25 ETH from Reddio’s RedSonic Vault by exploiting a cross-vault asset double-counting vulnerability combined with a flash loan.

Protocol / chain / asset: Reddio (RedSonic Vault / rsvETH) on Ethereum. Assets involved: ETH / WETH and stETH.

Loss: ~9.25 ETH (roughly $23k at contemporaneous prices). No recovery or rollback reported at time of writing.

Attack type: Accounting flaw / permissionless asset registration + shared collateral double-counting + flash-loan price inflation.

Technical details: The ETH vault’s getTotalAssetBalance(ETH) included the raw stETH balance of the vault. Because registerErc20() was permissionless, the attacker registered stETH as a second asset (rsvstETH). The same stETH therefore backed both rsvETH and rsvstETH share classes. Flow (single transaction): flash-loan ~1,139 WETH from Balancer → deposit majority of ETH to control rsvETH shares → register and deposit ~9.34 stETH (inflating rsvETH share price) → redeem inflated rsvETH for excess ETH → redeem rsvstETH to recover the stETH → repay loan. The 2% withdrawal cap did not prevent the share-price manipulation.

Explorer links:

Status: Confirmed. Funds moved; no public recovery announcement.

Sources: https://x.com/SlowMist_Team/status/2096439593403089077, https://x.com/exvulsec/status/2096277307757572517

Autonolas Treasury — Malicious Governance Proposal (~40 ETH / ~$100k at risk) — Unexecuted / Flagged

What happened: A Tornado-funded attacker submitted a governance proposal titled “Owner migration: transfer treasury ownership from old timelock to Safe updater.” Execution would have transferred treasury ownership to an attacker-controlled contract, enabling withdrawal of the treasury balance.

Protocol / chain / asset: Autonolas on Ethereum. Treasury holding ~40.196 ETH.

Loss: None realized. ~$100k equivalent still at risk until the proposal is defeated.

Attack type: Malicious governance proposal / social-engineering style ownership transfer.

Technical details: Attacker registered the ENS name “autonolas-deployer.eth” and submitted the proposal. If executed, ownership would move from the legitimate Autonolas Timelock to the attacker contract. Community and monitors have three days to vote it down. Defimon shared the alert in the project’s community chat; the team has indicated it will vote the proposal down.

Status: Unexecuted. Team aware and planning to reject.

Sources: https://x.com/DefimonAlerts/status/2096432367908933790

Also noted

  • No additional confirmed high-impact incidents first reported or materially updated in the strict last-24-hour window after cross-checks of DefimonAlerts, SlowMist, CertiKAlert, Phalcon, GoPlus, PeckShield, BlockSec, Lookonchain, and related monitors.

Sources & references

Editor’s note: Quiet day. All figures are live losses after any known reversals; no how-to details are included. Always verify on-chain before acting on alerts.