🚨@InverseFinance Related contracts of crvUSD/sDOLA have been compromised (DOLA is issued by
, with no exploitation of InverseFinance's own contracts). The stolen asset is crvUSD, with an initial estimated loss amounting to 2,347,964.436417844103988417 crvUSD. In a single transaction, the attacker first manipulated the oracle price, then exploited the vulnerability where the list of liquidatable users relies on real-time prices to conduct batch liquidation arbitrage, and additionally created a substantial new borrowing exposure.
Tx: https://t.co/nB82TlvsxR
Attacker Addresses: https://t.co/8uSYFa6OrS
The attacker first obtained USDC and WETH funds through flash loans, mortgaged WETH to borrow 25 million crvUSD, then successively called functions such as https://t.co/9DryVj4r7p, https://t.co/luvsvbmWsf, sDOLA.redeem and DolaSavings.stake. They triggered a LLAMMA price refresh with an in_amount of 0 to drive up the price_w, artificially creating a large number of liquidatable users with negative health scores. Next, the attacker deployed an auxiliary contract and injected initial funds into it; the auxiliary contract then executed batch liquidations on 27 users, exploited the spread arbitrage generated by stablecoin_received exceeding debt during liquidation, and funneled all liquidation proceeds back to the main attack contract.
Preliminary analysis shows that the core cause of the vulnerability lies in the flawed price dependency mechanisms of the crvUSD Controller and LLAMMA contracts. Functions including users_to_liquidate, liquidate and min_collateral all rely on the amm_oracle.price_w, a price that can be atomically manipulated within a single transaction, and do not adopt a cross-block stable price feed. A critical logical flaw is that liquidation eligibility is determined solely by calculating user health scores based on the manipulated price at a single point in time. Furthermore, the liquidate function does not conduct secondary verification of abnormal price fluctuations and user health scores during execution, which enabled the attacker to complete a closed loop of "price manipulation - liquidation arbitrage" within a single transaction.
125 OpenClaw startups now listed on TrustMRR.
$274,397 of verified revenue generated in the last 30 days.
If this represents ~1% of the market, @steipete's open source project helped developers make around $30M in February.