Thetanuts Finance Hit by $2.1M Exploit on Deprecated Vault; Whitehat Recovers Most Funds

— By Whatsertrade in Crypto markets

Thetanuts Finance Hit by $2.1M Exploit on Deprecated Vault; Whitehat Recovers Most Funds

An attacker drained about $2.1 million from a deprecated Thetanuts Finance vault on Ethereum on June 15, 2026, exploiting an integer-division flaw. A whitehat recovered roughly $2 million in option tokens.

An attacker drained approximately $2.1 million from a deprecated Thetanuts Finance vault on Ethereum on June 15, 2026, before a whitehat recovered most of the funds, according to on-chain security firms PeckShield and SlowMist.

What happened

The exploit targeted a redemption-math flaw in a legacy Thetanuts vault. SlowMist traced the root cause to an integer-division error in the contract's mint function: after the vault was drained, the deposit formula rounded down to zero, allowing the attacker to mint option tokens for free and, ultimately, create them without limit.

Most of the funds were recovered

PeckShield reported that around $2 million in option tokens were rescued by a whitehat. Before that recovery, the attacker managed to swap roughly $105,000 in USDC for about 60 ETH, the firm said.

Thetanuts response

Thetanuts Finance said the affected vault was deprecated years ago and has no relation to any of its current contracts or products, according to the team's statement on X. The protocol's live products were not affected.

Deprecated does not mean safe

The incident is a reminder that legacy smart contracts remain on-chain and exploitable long after a team stops using them, and that whitehat researchers continue to play a critical role in recovering stolen DeFi funds. For users, the practical defense is the same as always: verify a token and its contract before interacting with it.

DEXTools' Token Safety Checker flags honeypots, buy and sell taxes, mint functions, and whether a contract is verified, and our guide on how to spot a rug pull walks through the red flags to check before you trade.