DeFi

CICADA Finance pauses rtUSQ after smart contract exploit

CICADA Finance said it has paused its rtUSQ protocol after identifying a smart contract vulnerability that allowed an attacker to mint an abnormal amount of rtUSQ. In a security incident notice posted by the project, CICADA said the affected liquidity was protocol-owned and that no user funds were lost.

The project said the protocol has been suspended while it neutralizes the improperly minted rtUSQ and the ltCIC position the attacker obtained. CICADA added that rtUSQ instant redemption is paused and that users should not transact, convert, deposit, withdraw or provide liquidity for rtUSQ, wrtUSQ, ltCIC or related assets through its front-end, smart contracts or any DEX.

Boundary condition in the contract triggered the minting issue

According to the notice, the incident stemmed from a rare boundary condition in the rtUSQ contract. CICADA said the exploit resulted in an abnormal quantity of rtUSQ being minted, which the attacker then used to acquire ltCIC from the wrtUSQ/ltCIC liquidity pool.

The project said the position was contained and that the attacker cannot freely convert the improperly minted assets into stablecoins. It also said the realized loss was small and absorbed by protocol-owned liquidity.

CICADA said it will publish a full technical post-mortem and remediation plan later. For now, the protocol remains paused while the team works to remove the impact of the minted tokens and assess the contract issue.