Visor Finance's Reward-Minting Bug Turns an $8.2M Heist Into an 87% Price Crash
Visor Finance, a liquidity-management protocol built around Uniswap v3, let an unknown attacker mint an unlimited quantity of reward tokens after a flawed permission check slipped through its contracts.
On December 21, the attacker withdrew 8.8 million VISR from Visor, worth roughly $8.2 million at pre-attack prices. The payoff shrank fast: dumping that much VISR through Uniswap's VISR-ETH pool crashed the token's price by 87%, wiping out most of the exploit's real value before the attacker could fully cash out.

This was already Visor's third stumble of the year. Back in June, a security breach cost the protocol about $500,000 out of a roughly $3 million total value locked at the time, an episode the team downplayed in its own incident report. Then in November, Visor was hit again, an event its team labeled "economic arbitrage" rather than an exploit. Security researcher Mudit Gupta challenged that framing, asking whether a protocol's dependence on spot prices to issue shares shouldn't itself count as a smart contract bug.
How the December exploit worked
The attacker's address, 0x8efab89b497b887cdaa2fb08ff71e4b3827774b2, received funding from Tornado Cash in this transaction just minutes before carrying out the attack.
The root cause sat in a vulnerable require() check inside the deposit() function of the vVISR Rewards Contract. Using a contract under their control, the attacker exploited that check to mint shares without limit. As researcher @storming0x explained, anyone who passed their own contract in as the "from" parameter — provided that contract's Owner() function returned msg.sender — could call vvisr.mint() to create any quantity of shares, sent to any address they chose.
The attacker first transferred ownership of their contract to themselves, then ran the exploit transaction, minting 195,000 vVISR tokens from nothing. Those tokens were then burned for 8.8 million VISR, part of which was swapped for ETH through Uniswap v2 and laundered through Tornado Cash, beginning with this transaction and six further transfers totaling about 113 ETH (roughly $450,000) as of this writing.
The response

Visor's official post-mortem proposed a token migration based on a balance snapshot taken before the exploit, intended to make affected holders whole. The team also said it had engaged both Quantstamp and ConsenSys Diligence for audits running through December and January, which will cover the replacement staking contract.
With user funds set to be restored through the migration, the lasting damage looks confined mostly to Visor's reputation rather than depositors' balances — even if the team's handling of repeated incidents has drawn its own criticism. Reacting to Visor's pattern of soft-pedaling its exploits, security firm BlockSec remarked: "Since last time an attack was called arbitrage, can we call it an airdrop this time?"
Get new scam files the moment we publish them — usually 2–3 emails a week.