ETHMACOAPY Protocol Lost 8.11 WETH in Defect
A rounding error in the protocol's fee calculation function led to unauthorized collateral withdrawal.
Updated on Oct. 6, 2026 in Financial Crime

Live Poll
Do you trust the security of decentralized finance protocols with your digital assets?
An ETHMACOAPY Set Protocol product lost 8.11 WETH following a flaw in its fee processing mechanism. The issue allowed users to redeem more collateral than they initially deposited.
Why it matters
The security incident highlights critical vulnerabilities in automated financial protocols where rounding errors in fee functions can be exploited to drain pool assets. Such flaws underscore the risks inherent in smart contract execution within decentralized finance environments.
The ETHMACOAPY product suffered a loss of 8.11 WETH across two transactions, with the second transaction resulting in a loss of 4.062 WETH. The investigation currently centers on a rounding defect found within the actualizeFee function.
The players
ETHMACOAPY
This is a decentralized finance product built on the Set Protocol framework.
The details
The defect occurred when collateral was transferred into the contract, triggering an incorrect recalculation that favored the user. Because the actualizeFee function rounded redemption collateral upward when no fees were applicable, the protocol mistakenly returned more collateral than was originally held.
Timeline
October 6, 2026: The loss was reported.
The second transaction occurred two blocks after the first.
Legal Context
This incident follows a pattern set by other vulnerabilities discovered in the Set Protocol smart contract architecture. These exploits highlight a broader trend in blockchain security where minor code implementation errors lead to significant unauthorized fund outflows.
The defect highlights the risks that participants in decentralized protocols face when interacting with automated fee functions. Users should verify that protocols have undergone rigorous audits of their underlying smart contracts to ensure collateral security.
The takeaway
Smart contract developers must implement precise rounding logic to prevent exploits that drain collateral during fee recalculations. Investors should prioritize platforms that demonstrate verified, error-checked code before committing assets to new protocol products.
Further reading
Learn more about the risks associated with Financial Crime in the digital asset sector.
Source note: This article includes information reported by TokenPost.
Live Poll
Do you trust the security of decentralized finance protocols with your digital assets?







