Data leak [loss] $3M+

Tweet thread by Vesper Finance

2021-11-02 [vendor] Vesper Finance
Primary Source ↗
Financial Loss $3.0M (3,000,000 USD)

Incident Details

By manipulating the price of a low-liquidity, beta-stage stablecoin, an attacker was able to borrow all tokens in a Rari Fuse pool using the initial token as (inflated) collateral. They then swapped the tokens for Ethereum, and made off with more than $3 million.

Total loss estimated at $3,000,000.

Technical Details

Initial Attack Vector
Oracle price manipulation
Vendor / Product
Vesper Finance

Timeline

  1. 2021-11-02 Breach occurred
  2. 2021-11-02 Publicly disclosed