A sybil farming attack on WUSD.fi and GLOVE drained roughly $200K from Uniswap V3 liquidity pools on Ethereum. No audit caught the reward mechanic flaw. SomebodyA sybil farming attack on WUSD.fi and GLOVE drained roughly $200K from Uniswap V3 liquidity pools on Ethereum. No audit caught the reward mechanic flaw. Somebody

WUSD.fi Sybil Farming Attack Drains $200K from GLOVE Pools

2026/05/27 06:00
2분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 [email protected]으로 연락주시기 바랍니다

A sybil farming attack on WUSD.fi and GLOVE drained roughly $200K from Uniswap V3 liquidity pools on Ethereum. No audit caught the reward mechanic flaw.

Somebody figured out the math before the protocol did. On May 25, a single attacker walked away with roughly $200K from two Uniswap V3 pools tied to the WUSD.fi and GLOVE protocol on Ethereum. Not a bug in the contract code exactly. More a case of a reward mechanism that never asked who it was rewarding.

WUSD.fi Sybil Farming Attack Drains $200K from GLOVE Pools

Blockchain security researcher exvulsec flagged the incident on X, laying out the full on-chain trail. The attacker used a flash loan, cycled through fresh wallets, and dumped harvested GLOVE tokens into the liquidity pools before anyone caught it.

The Mechanic Nobody Stress-Tested

Inside WUSD.fi’s contract sits a function called WUSD._englove. According to exvulsec on X, any fresh wallet wrapping at least 100 WUSD while holding under 2 GLOVE could call Glove.mintCreditless and receive up to 2 GLOVE tokens. No identity check. No rate limit. Nothing.

The attacker deployed EIP-7702 helper contracts, pulled a Morpho USDT flash loan, then ran repeated wrap and unwrap cycles across fresh wallet addresses. Each new address qualified again. GLOVE kept minting.

Harvested GLOVE went straight into Uniswap V3. The GLO-USDC pool lost 11,702 USDC in observable drains. The GLO-USDT pool shed 8,079 USDT. Both figures confirmed via Etherscan at time of reporting.

What the Community Clocked

SecureAI on X put it plainly: the exploit was not the contract itself. It was the reward mechanism design. Audits tend to look at code logic. They rarely stress-test economic incentive paths the way an attacker will.

Chinese-language crypto account aegixe_cn on X called it another incentive abuse attack and warned users to understand a protocol’s mechanics before putting money in. That kind of reminder lands differently when $200K has already left the pool. DeFi exploits have been stacking up this year, with May alone seeing multiple liquidity-layer incidents across Ethereum.

No oracle manipulation. No reentrancy. Just a minting function handing out tokens to anyone who showed up with a fresh address. The attack kept going as long as new addresses kept qualifying. And they did, part of a pattern that has cost DeFi nearly $770M in 2026. Per the filings.

The post WUSD.fi Sybil Farming Attack Drains $200K from GLOVE Pools appeared first on Live Bitcoin News.

시장 기회
WSPN 로고
WSPN 가격(WUSD)
$0.9976
$0.9976$0.9976
-0.06%
USD
WSPN (WUSD) 실시간 가격 차트

Predict & Trade to Win Rewards

Predict & Trade to Win RewardsPredict & Trade to Win Rewards

Guaranteed rewards with $500,000 prize pool

면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, [email protected]으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

RealStocks Now Live

RealStocks Now LiveRealStocks Now Live

Trade real U.S. stock via regulated brokerage