DeFi Protocol MALT Exploited for $72K Through Faulty Swap Function
A vulnerability in MALT's swap function allowed an attacker to extract approximately $72,000 by exploiting how the system counted treasury-supplied DAI as user-contributed funds. The flaw failed to distinguish between external capital added during rebalancing and actual trader input, enabling the attacker to withdraw excess MALT tokens with minimal legitimate contribution. This incident is part of a larger pattern of DeFi exploits that have resulted in over $21 billion in cumulative losses across the sector.
MALT's vulnerability stemmed from a critical accounting failure in its token exchange mechanism. When the protocol initiated an internal rebalancing operation, it injected additional DAI reserves from its own treasury into the liquidity pool. However, the swap function's validation logic treated these protocol-supplied funds identically to genuine customer deposits, creating an asymmetry that an attacker could exploit by depositing minimal capital while claiming access to the artificially inflated pool reserves.
The timing of this incident reflects broader systemic challenges in decentralized finance infrastructure. According to DeFiLlama data, the sector has accumulated substantial cumulative losses across multiple vulnerability categories, with protocol-specific exploits and cross-chain bridge compromises each representing multi-billion dollar risk vectors.
This incident may heighten scrutiny among retail and institutional participants evaluating DeFi protocol safety, potentially affecting capital allocation decisions within the sector. The vulnerability also underscores risks faced by liquidity providers and token holders who depend on accurate internal accounting systems. Developers and auditors could face increased pressure to implement more rigorous validation mechanisms, which may slow protocol deployment timelines while potentially increasing transaction costs for users.