According to a blog post from the project, a potential exploit was discovered in a newly released AirSwap ($AST) smart contract. The vulnerability, which was discovered during an internal security review, would allow an attacker, under certain conditions, to perform a swap without requiring a signature from a counterparty. A list of 10 accounts that were at risk was released by the team. These accounts would have been at risk between midday September 11th and early morning of September 12th.
The impacted addresses are:
0x64ae361c1c55f61a02d2c67a4c78457d5169ac56
0xead57e1667f9b409a633750aae5b4c90739c1a1e
0x133acc82d6eaaec2a12e7547835219860551c570
0x2b13d1463b3821dd8a625e8935ab079251f1376d
0x669e01245cc4e8229d8c9cc753a4d14319877122
0x3e3742b6b7c0add19eb155c72eacbb6bfc8958dc
0xdd4769650e8e1ed7ddd4e45d8e291a5bfb65fe73
0xbbf0f047cab86b324c0081bcea683ffa24bab0e7
0xbd33caaedf06e436932522a9284d8312f325cae8
No action is required for addresses that are not on this list. For those that are listed the announcement directs users to https://authorizations.airswap.io/ where they can revoke authorizations for the contract.
For more details on the potential exploit and remediation steps see the Fluidity blog.