Thetanuts Finance loses $2.1M in exploit targeting abandoned vault

Source Cryptopolitan

Thetanuts Finance, the DeFi options protocol, has confirmed that it has suffered an exploit that drained $2.1 million from a legacy vault tied to it. 

According to Thetanuts, the compromised contract had been deprecated years ago. 

Blockchain security firm PeckShieldAlert, which flagged the incident before Thetanuts confirmed the exploit, reported that it seemed $2 million in option tokens appeared to have been recovered through whitehat efforts. 

The remaining funds, about $105,000 in USDC, were swapped by the exploiter for approximately 60 ETH, according to PeckShieldAlert’s on-chain analysis. The attacker also holds $34,000 in USDC-denominated option tokens.

What led to the exploit of Thetanuts Finance legacy vault?

A vulnerability in the vault’s redemption logic is the root of the exploit, according to security researcher ExVul, who published a breakdown on X.

Thetanuts Finance responded within hours, writing on X, “Our preliminary investigation indicates that this is once again, a deprecated vault that we have migrated from years ago.” 

The protocol stated, “It has no relation to any of our current contracts or products,” while adding that it would publish a full post-mortem once it gathers more details.

Blockaid’s exploit detection system also picked up the attack independently, issuing a community alert flagging active exploitation of the Thetanuts contract on Ethereum. The security platform also shared the exploiter’s address and the exploited contract’s address as well.

Are deprecated protocols under attack?

The Thetanuts incident adds to a growing list of deprecated protocols that have been attacked recently.

The most recent, apart from Thetanuts, is Aztec Connect, a privacy bridge abandoned since 2023, which lost $2.1 million through a separate verification flaw in its immutable smart contracts, as Cryptopolitan reported. In that case, the team had renounced all admin keys, leaving no one able to patch or pause the code.

So far in the month of June, the total value hacked in terms of DeFi exploits has crossed $46 million, and it is only midway into the month. At this pace, it may rival or exceed May, which saw its own fair share of protocol breaches.

Thetanuts has tried to assure its users of its current contracts that they are not at risk; however, the latest events have made it clear to users that abandoned code is not safe code, and so are the funds tied to them.

Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Hedera Price Analysis: HBAR defies $50B market dip as Nvidia confirms AI partnershipHedera maintains strength above $0.15, signaling investor confidence as NVIDIA’s AI integration boosts long-term bullish sentiment and breakout potential.
Author  FXStreet
Apr 09, 2025
Hedera maintains strength above $0.15, signaling investor confidence as NVIDIA’s AI integration boosts long-term bullish sentiment and breakout potential.
placeholder
3 Massive Things That Could Happen After SpaceX Goes Public in June 2026SpaceX’s June 12 listing is triggering a parallel pricing race in crypto. Synthetic perpetuals on Hyperliquid already imply a $2 trillion valuation for the rocket and satellite-internet group.Three fo
Author  Cryptopolitan
May 28, Thu
SpaceX’s June 12 listing is triggering a parallel pricing race in crypto. Synthetic perpetuals on Hyperliquid already imply a $2 trillion valuation for the rocket and satellite-internet group.Three fo
placeholder
US Attacks Iran Amid the “Ceasefire”: Bitcoin, Gold, and Oil ReactThe United States launched strikes against Iran on Tuesday after a US Apache helicopter was downed over the Strait of Hormuz, breaking the fragile ceasefire previously announced by President Donald Tr
Author  Beincrypto
Jun 10, Wed
The United States launched strikes against Iran on Tuesday after a US Apache helicopter was downed over the Strait of Hormuz, breaking the fragile ceasefire previously announced by President Donald Tr
placeholder
Elon Musk Projects $1 Trillion SpaceX Revenue by 2030: Practical or a Long Shot?Elon Musk says SpaceX revenue could reach roughly $1 trillion a year by 2030, and likely more in 2031. That projection sits far above the forecasts of the bankers who just took his company public.Musk
Author  Beincrypto
23 hours ago
Elon Musk says SpaceX revenue could reach roughly $1 trillion a year by 2030, and likely more in 2031. That projection sits far above the forecasts of the bankers who just took his company public.Musk
placeholder
SpaceX Paid Just 0.7% in IPO Fees, Yet Wall Street Banks Rushed InSpaceX paid Wall Street about $500 million in underwriting fees on its $75 billion listing, near 0.7% of the deal. That ranks among the lowest rates ever for a mega-IPO.Goldman Sachs and Morgan Stanle
Author  Beincrypto
23 hours ago
SpaceX paid Wall Street about $500 million in underwriting fees on its $75 billion listing, near 0.7% of the deal. That ranks among the lowest rates ever for a mega-IPO.Goldman Sachs and Morgan Stanle
goTop
quote