Wednesday, October 7, 2026

Legacy Set Protocol Product Hit by Rounding Exploit

Neon DeFi dashboard showing a rounding error draining ETH from a digital vault.

A legacy Set Protocol product on Ethereum was exploited through a rounding flaw in its fee-accounting logic, allowing excess collateral to be extracted during redemptions. According to SlowMist’s security incident tracker, the vulnerable actualizeFee() function increased unitShares from 4,927 to 4,928 even though no fee had been minted, creating a small accounting discrepancy that could be amplified through repeated issuance and redemption. SlowMist estimated the incident at approximately $13,700.

Separate onchain monitoring identified a broader impact of approximately 8.11 WETH across two transactions involving ETHMACOAPY, an older Set Protocol product. The second transaction reportedly removed around 4.062 WETH and left the affected Set with little remaining collateral. The two figures appear to reflect different tracking scopes, so the 8.11 WETH total should not simply replace SlowMist’s narrower estimate without qualification.

Rounding Error Increased Redeemable Collateral

SlowMist’s reconstruction shows that the attacker first issued shares before calling the vulnerable fee-update path. When actualizeFee() recalculated the Set’s accounting, rounding pushed the number of underlying units represented by those shares slightly higher despite no corresponding fee issuance. Redeeming the same quantity afterward therefore returned more collateral than the shares had economically represented before the recalculation. Temporary liquidity supplied through Uniswap v4 flash accounting allowed the attacker to scale a discrepancy that would otherwise have been small.

The affected logic belongs to an older generation of Set infrastructure rather than demonstrating a compromise of Ethereum or Uniswap. Set Protocol’s original contract repository was archived in January 2023, and its historical contracts include the actualizeFee() interface used by legacy rebalancing Set products. The security boundary is therefore the legacy Set contract and its accounting logic, not the Ethereum base layer or the flash-liquidity venue used during execution.

That legacy distinction has become increasingly relevant across DeFi. An older Arrakis Finance V1 vault recently lost 2.94 WETH through an accounting and liquidity manipulation, while a deprecated Scallop rewards contract was exploited months earlier despite no compromise of its current lending stack. Arrakis Finance V1 vault lost 2.94 WETH in a legacy exploit Scallop exploit exposed risks in deprecated smart-contract infrastructure Immutable contracts can retain economic exposure long after the products around them stop receiving active development.

Small Accounting Errors Can Become Extractable Value

The mechanics differ from the Hinkal Protocol exploit that drained roughly $820,000, where attackers repeatedly withdrew USDC after a “proofless deposit” sequence. Yet both incidents demonstrate how deterministic smart-contract behavior can turn a narrow logic error into repeatable extraction once an attacker identifies a profitable cycle. The important security issue is not the nominal size of the arithmetic discrepancy, but whether it can be repeated or leveraged with temporary capital.

A similar legacy-risk pattern emerged when attackers began preparing copies of the Notional Finance V1 exploit on BNB Chain after the original vulnerability became public. SlowMist later identified copycat attempts against Notional’s legacy V1 infrastructure Older contracts can remain attackable even when a protocol’s current development has moved elsewhere, particularly when assets, approvals or callable accounting functions remain onchain.

No formal Set Protocol post-mortem or recovery announcement was found in the project’s publicly accessible channels as of October 7. The currently verifiable picture is consequently limited to the security researchers’ findings: a rounding defect in legacy fee accounting allowed collateral belonging to the affected Set to be extracted, with public estimates ranging from SlowMist’s approximately $13,700 incident record to roughly 8.11 WETH across two tracked transactions. Until the affected product’s operators publish a definitive reconciliation, those amounts should remain separately attributed rather than presented as a single confirmed loss.

Scroll to Top
Chain Report
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.