Eve can match Alice on one side and Bob on the other side.

highlighted = computed this step

Eve has two matching sides

With Alice, Eve has 3. With Bob, Eve has 6.

363\quad6
Eve holds both halvesThe DH MitM rows are recomputed before the table is rendered.Eve holds both halves - E=9quantityvaluee (Eve secret)10E=g^e mod p9Eve-Alice secret3Alice computes E^a3Eve-Bob secret6Bob computes E^b6real A-B shared never forms2

Alice and Bob do not match each other

Alice's value is 3 while Bob's value is 6.

363\ne6
Eve holds both halvesThe DH MitM rows are recomputed before the table is rendered.Eve holds both halves - E=9quantityvaluee (Eve secret)10E=g^e mod p9Eve-Alice secret3Alice computes E^a3Eve-Bob secret6Bob computes E^b6real A-B shared never forms2

The real shared value never forms

The honest Alice-Bob value would have been 2, but neither endpoint computed that value in this transcript.

honest shared=2\text{honest shared}=2
Eve holds both halvesThe DH MitM rows are recomputed before the table is rendered.Eve holds both halves - E=9quantityvaluee (Eve secret)10E=g^e mod p9Eve-Alice secret3Alice computes E^a3Eve-Bob secret6Bob computes E^b6real A-B shared never forms2

Summary

The attack does not break the arithmetic. It changes which public value each side uses.

two endpoints, two secrets\text{two endpoints, two secrets}
Eve holds both halvesThe DH MitM rows are recomputed before the table is rendered.Eve holds both halves - E=9quantityvaluee (Eve secret)10E=g^e mod p9Eve-Alice secret3Alice computes E^a3Eve-Bob secret6Bob computes E^b6real A-B shared never forms2