DeFiTuna, a Solana-based DeFi protocol, lost 569601 USDC in an exploit on July 16. The attacker created a TUNA/USDC pool with very low liquidity and swapped borrowed USDC through Jupiter routing within this pool, receiving a minimal amount of TUNA. This triggered a rounding error in the protocol's asset valuation, causing the total asset value to be calculated as zero and bypassing solvency checks. The attacker withdrew the USDC through a controlled liquidity position, distributing the stolen funds to multiple addresses. CertiK identified a flaw in the solvency check logic as the root cause, which incorrectly validated a position as normal despite its asset value being zero under extreme conditions.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.





























