
Arrakis Finance’s page was exploited in an attack targeting a legacy G-UNI vault, in which a malicious actor used an exploit to target a vulnerability in the vault’s liquidity accounting. This information is per the blockchain security firm SlowMist. The incident concerned how the vault accounted for Uniswap V3 liquidity fees and balances when users minted and burned shares. SlowMist said the attacker exploited changes in the pool state within the same transaction. Arrakis later clarified that its current Pro vaults were not affected and that the incident involved an older G-UNI system that had already been deprecated.
The exploit caused a loss of 2.94 WETH from the affected vault. The security firm attributed the loss to the vulnerable mint–and-burn accounting mechanism.
SlowMist Identifies Vulnerability in Vault Accounting
SlowMist reported on X that the weakness was linked to the vault’s state-dependent Uniswap v3 mint and burn accounting. The attackers first minted shares based on one pool composition, then manipulated the pool and allowed fees to accrue. The attackers then burned the shares after the position state had changed.
According to SlowMist, the vault’s burn function collected pending fees and distributed the corresponding liquidity fees and idle balances on a pro rata basis. This created an opportunity for the attacker to exploit discrepancies between the pool state when the shares were minted and the state when they were burned. SlowMist described this issue as an atomic liquidity sandwich.
The security firm said the core problem was the absence of safety guardrails against minting and burning in the same transaction, as well as the lack of a state snapshot to save the relevant accounting state.
SlowMist also clarified that the issue was not a standard Oracle manipulation vulnerability but a simple error of share-over minting. Instead, the exploit involved how the vault calibrated and distributed assets after the underlying Uniswap V3 position was changed. The security firm identified the affected vault, attack contract, and other addresses involved in the incident in its alert while reporting a loss for the affected Arrakis vault.
🚨SlowMist TI Alert🚨
💸 @ArrakisFinance Loss: 2.94 WETH
🔍 Root Cause: The vault’s state-dependent Uniswap V3 mint/burn accounting was vulnerable to an atomic liquidity sandwich. The attacker minted shares against one pool composition, manipulated the price and accrued fees,…
— SlowMist (@SlowMist_Team) August 24, 2026
Arrakis Says Current Pro Vaults Were Not Affected
Arrakis Finance has responded to concerns about the incident by stating that no Arrakis Pro wallets were affected. The organization said its existing customers use Arrakis Pro, separating the affected systems from its existing products. According to Arrakis, the vulnerable wallet was a legacy G-UNI wallet from 2021. It was part of a deprecated public wallet system that existed before the company’s current products. Arrakis said it had previously announced the deprecation of the G-UNI system.
The company also explained that most funds had already been removed from the system, while some remaining dash was still present. The company further stated that the legacy G-UNI smart contract system is fully immutable. Its upgrade and management paths have been renounced, meaning the system will operate in its present form.
The incident emphasizes the risks that can arise from the state-dependent accounting in DeFi liquid vaults. Liquidity positions fed into balances can change between different stages of a transaction. Accounting mechanisms need to reflect those changes to prevent users from gaining an unfair share of the underlying assets.
SlowMist’s findings point to same-transaction minting-burn protection and state snapshots as potential guardrails against this type of accounting vulnerability. Meanwhile, Arrakis has emphasized that the affected system is a deprecated legacy wallet and that its existing Pro wallet was not affected
The incident leaves the affected Arrakis with the loss of 2.94 WETH, while the exploit exposed a weakness in the legacy G-UNI system. Arrakis has clarified that its current operations remain unfazed.
