On October 9, 2026, blockchain security firm SlowMist flagged two separate decentralized finance (DeFi) incidents involving the protocols BitBay and EtherVista. Attackers exploited unrelated smart contract flaws to drain a combined total of approximately $32,600. The first incident occurred at 03:28 UTC, targeting BitBay’s DAI/USDC vault on the Polygon network. The second alert was issued at 05:20 UTC for EtherVista, a decentralized exchange protocol. In both cases, the code erroneously paid out more tokens than the attacker owned due to logic failures in withdrawal functions and safety checks.

The BitBay loss amounted to roughly 14,838.47 DAI, valued at $14,000 by SlowMist’s database. The vulnerability lay in the _withdraw() function, which transferred the entire token balance when liquidity stood at zero. An attacker forced this condition via the reposition() function before redeeming a minimal share unit. The EtherVista incident resulted in an estimated $18,600 loss in Wrapped Ether and VISTA tokens. This stemmed from an integer overflow in the K-invariant check within the swap() function. By registering a malicious router contract, the attacker executed crafted swaps that bypassed the constant product rule, allowing them to withdraw value exceeding their deposits.