← Back to live feed

Friday, Sep 11, 2026

1
Attacker Drains 15.45 ETH From ether.fi via AtomicQueue Exploit
topics 🪙 Crypto🔒 Cybersecurity tags CryptoCrypto HacksDeFi keywords SlowMistSlowM

Missing access controls in a smart contract enabled a malicious actor to steal cryptocurrency from ether.fi user accounts on Sept. 11. The thief exploited the `AtomicQueue.solve()` function by creating a malicious `AtomicRequest` and forcing a victim address to act as the solver, leveraging pre-existing ERC-20 allowances to drain approximately 15.45 ETH.

Security firm SlowMist identified the root cause as a lack of a `solver == msg.sender` check as well as missing signature, registration, or consent verification. SlowMist contacted the ether.fi team privately to responsibly disclose the vulnerability before issuing the public alert regarding the breach of the AtomicQueue contract.

See all 3 tweets →