Root-cause analysis not yet published. The incident description below contains all currently available signal — review the attack transaction directly for definitive forensics.
Reproducible Foundry test fork from SunWeb3Sec/DeFiHackLabs. Clone the repo, run forge test against the file path above, and replay the exploit against a mainnet fork at the historical block. Use for reproduction only — not for live targets.
Fantom-based decentralized derivatives protocol DEUS Finance was attacked, and the hackers made about $13.4 million in profit. The hack utilized a flash loan-assisted manipulation of price oracles read from the StableV1 AMM-USDC/DEI pair, and then used the manipulated collateral DEI price to borrow and drain the pool. Attack method (per SlowMist): Flash Loan Attack. Reported loss: $ 13,400,000.
- chain
- —
- protocol
- Deus Finance
- bug_class
- oracle
- date_occurred
- 2022-04-28
- loss_usd
- $13,400,000
- source_id
- sm:deus-finance::2022-04-28