Phalcon posted on the X platform that the stablecoin protocol TheStandard.io was attacked due to the lack of slippage protection when exchanging collateral, resulting in a loss of approximately US$290,000.
The attacker first created a CDP (SmartVaultV2), using 10 WBTC as collateral to mint 290,000 EURO. The attacker then forced the SmartVaultV2 contract to perform a swap in the WBTC/PAXG pool, which was manipulated through the only position the attacker had previously opened. It allows an attacker to siphon liquidity from the SmartVaultV2 contract and seize all WBTC collateral, causing the protocol to go bad and profit from minting EURO.