HypurrFi discloses the "rounding error" vulnerability in the early version of Aave V3 and has suspended new lending and borrowing for the XAUT0 and UBTC markets
HyperEVM's native non-custodial lending protocol HypurrFi stated on platform X that there is a "rounding error" vulnerability in versions prior to Aave V3 3.5. Under specific conditions, an attacker could extract underlying tokens by repeatedly executing supply/extract and borrow/repay loop operations.
The affected markets are XAUT0 and UBTC in HypurrFi Pooled. Currently, user funds are not at risk. To ensure safety, related markets have suspended new supply and lending operations, while withdrawal and repayment functions remain operational, and other markets are running normally. HypurrFi added that it quickly identified the issue on-chain through its internal monitoring system and promptly froze the affected markets. They are also collaborating with other Aave deployers and security researchers to address the issue and have invited other Aave fork projects to reach out for more security information.
You may also like

How to exit after asset tokenization?

The foundation of SpaceX's trillion-dollar valuation: Who is dividing Musk's annual capital expenditure of tens of billions?

France vs Senegal World Cup 2026: Mbappe’s New Era Begins Against a Historic Rival

SharpLink CEO: How to understand that Ethereum developers have just surpassed 1 million?

Morning Report | MiCA grace period expires on July 1; Kalshi's trading volume in the first week of the World Cup breaks $5.1 billion, setting a record

What is the connection between Huang Zheng of Pinduoduo and blockchain?

Morning Report | Prediction market platforms like Kalshi and Polymarket jointly sue Kentucky over 14.25% trading tax; Bridgewater founder discusses decision-making in the AI era: principled thinking should run parallel to AI, human insight remains irre...

If the AI bubble has already burst, who will truly remain?

Paul Graham: How to Make a Billion Dollars

After 18 years, blockchain has finally started to head towards the main channel

Claude enforces "facial recognition for household registration," starting in July, no ID card means no access?

On the day of SpaceX's IPO, the first real test of the three perpetual mechanisms

Value Distribution of Stablecoins

Galaxy Deep Dive: Is the Bitcoin Four-Year Cycle Still Valid?

SpaceX IPO, Nvidia, and Bitcoin: Why Traders Are Watching More Than Just Crypto in 2026

The other side of Musk's trillion-dollar fortune: 85% cannot be sold

The U.S. government prohibits foreigners from using Fable 5, Anthropic issues a rebuttal





