Reddio RedSonic Vault Share Inflation
An attacker abused a permissionless asset-registration function and a Balancer flash loan to double-count collateral in Reddio's RedSonic Vault, draining 9.25 ETH (about $23,000) on Ethereum.
- Date
- Victim
- Reddio
- Chain(s)
- Status
- Funds Stolen
- Attribution
- 0x70f2333d21Ed7E7D105F6578227A9A747687982C
On September 5, 2026, the RedSonic Vault — a liquid-staking vault linked to the Reddio project — was drained of a net 9.25 ETH (about $23,000) on Ethereum through a single-transaction flash-loan attack that doubled the value of the vault's shares.
What happened
RedSonic issued rsvETH shares representing a claim on a pooled stETH balance, and priced those shares by reading the vault's raw underlying balance. Two design mistakes combined to make that fatal. First, the share price was computed from the raw balance, so a direct token transfer could inflate it without minting shares. Second, the vault exposed a permissionless registerErc20 function with no access control.
In one transaction the attacker:
- Flash-borrowed 1,139 WETH from Balancer.
- Deposited about 1,130 ETH, taking roughly 99% of all rsvETH shares.
- Called the open
registerErc20to register stETH as a second share class (rsvstETH) drawing on the same underlying stETH balance. - Deposited 9.34 stETH directly, inflating the shared balance — and thus the share price — without minting new shares.
- Redeemed both share classes, which paid out twice from the one pooled balance, swapped on Curve, and repaid the flash loan — netting 9.25 ETH.
Security firm ExVulSec traced the flaw to the double-counted collateral. The exploit transaction was 0xe3cba90e865c6cba950ebce36a52607f51f1fd33cd9fb920c78803f19b57791a and the drained vault was 0x4315990d9eeaffdfafd49958b4851f203fa1126f.
Aftermath
The loss was small in dollar terms, but the vault's pricing and registration logic were fully compromised in a single atomic call. The funds moved to the attacker's wallet and were not recovered.
Why it matters
RedSonic is another share-price inflation exploit, the same family as Sonne Finance: when a vault prices shares from a balance an attacker can move directly, and lets that balance be counted twice, a flash loan turns a few dollars of gas into a clean drain. Vaults must price shares from internally tracked accounting, never a raw token balance, and must never expose asset registration to the public.
Sources & on-chain evidence
- [01]blockonomi.comhttps://blockonomi.com/redsonic-vault-exploit-drains-9-25-eth-in-ethereum-flash-loan-attack
- [02]en.coin-turk.comhttps://en.coin-turk.com/redsonic-vault-exploited-for-9-25-eth-with-flash-loan-exvulsec-reveals-root-flaw/
- [03]cryptotimes.iohttps://www.cryptotimes.io/2026/09/07/crypto-hacks-cross-322m-in-septembers-first-week-as-liquid-network-alone-loses-320m/
- [04]coindesk.cchttps://coindesk.cc/redsonic-vault-exploit-drains-9-25-eth-in-ethereum-flash-loan-attack-110382.html
- 0xe3cba90e865c6cba950ebce36a52607f51f1fd33cd9fb920c78803f19b57791a