Miscalculated Exchange Rate Lets Attackers Drain $2M From Bedrock's uniBTC Vault
On September 25th, a flaw in Bedrock's uniBTC vault contracts allowed attackers to mint the token at a distorted exchange rate, draining roughly $2 million before the protocol could react.
How the bug was found

Security researchers at Dedaub uncovered a critical vulnerability in the uniBTC vault contracts, exposing an estimated $75 million spread across at least eight chains. Dedaub notified Bedrock directly on Twitter/X and also contacted SEAL 911, but the warning came too late: attackers exploited the flaw roughly two hours after the alert went out, walking away with around $2 million.
Given that uniBTC's market cap on Ethereum alone stood at $75 million, the actual exposure was far larger than what was ultimately lost.
Root cause
According to Bedrock's post-mortem, the underlying issue was more nuanced than a simple arithmetic slip. The protocol's contracts failed to correctly handle native tokens on chains that are not natively BTC chains. Specifically, the SigmaSupplier contract never registered NATIVE_BTC, which meant total supply always read as zero. Because of that, the cap restriction meant to block unauthorized minting was effectively disabled, leaving the Vault contract's safeguards non-functional.
The practical effect: users could mint uniBTC using native tokens on non-native BTC chains, something the system was never designed to permit. This wasn't a rounding error so much as a structural mishandling of token types across chains, and it opened the door to exploitation on multiple networks at once.
The exploit
The vulnerable vault contract had been deployed on September 25th with a 1:1 ETH-to-uniBTC exchange rate. In one representative transaction, an attacker minted 30.8 uniBTC using 30.8 ETH, then sold 28.8 of that uniBTC for 27.8 WBTC — all within a single transaction.
Exploiter address: 0x2bFB373017349820dda2Da8230E6b66739BE9F96
Attack transaction: 0x725f0d65340c859e0f64e72ca8260220c526c3e0ccde530004160809f6177940
This was one of many similar transactions that together pulled roughly $2 million out of the protocol.
Response time
Bedrock took more than two hours to publicly confirm the exploit after Dedaub's initial alert, and close to four and a half hours to actually pause the affected contracts. Notably, the upgrade that introduced the vulnerable contract had not gone through a security audit.

As news spread, Pendle — which held a significant amount of uniBTC — paused related activity on its platform. Bedrock's team eventually paused the vulnerable contracts as well, though only after the damage had already occurred.
Scope of the damage
The exploit affected eight chains in total: Ethereum, BNB Chain, Arbitrum, Optimism, Mantle, Mode, BOB, and ZetaChain. A tally of 125 separate exploiter addresses participated across these networks. Bedrock was left facing a liquidity shortfall of $1.8 million as a result.
The episode underscores a familiar lesson in DeFi: skipping an audit on a contract upgrade — even one that seems routine — can carry a steep price when cross-chain token accounting is involved.
Get new scam files the moment we publish them — usually 2–3 emails a week.