Flash Loan Exploit Drains RedSonic Vault of 9.25 ETH
Blockchain security firm ExVulSec has detailed how an attacker drained 9.25 ETH from Ethereum's RedSonic Vault using a flash loan, all within a single transaction and without putting up any of their own capital. The attacker borrowed 1,139 WETH from Balancer, deposited it to acquire nearly all outstanding rsvETH shares, then exploited a flaw in how the vault priced its assets.
The core problem was that RedSonic's vault allowed anyone to register new asset classes through a function called registerErc20, which had no access restrictions. The attacker used this to register stETH as a second asset class, creating share type rsvstETH that drew from the same underlying stETH balance as the original vault. By depositing a small amount of stETH directly, the attacker inflated the balance used to price shares without minting new shares, allowing them to cash out at an inflated value. The exploit contract self-destructed once finished, a tactic researchers note can complicate tracing efforts.
This incident highlights how a single missing access control on a seemingly minor function can undermine an entire pricing mechanism, especially when combined with flash loans that let attackers operate without real capital at risk.