ChainBleedv0.1 · open intel
← back to feed·ETHORACLE2022-03-20 · 4y ago
Incident · SLOWMIST

Umbrella Network

Contract Vulnerability
Estimated loss
$700.0K
VERDICT —UNRATED
Verdict pending. Auto-ingested incidents are reviewed before a public verdict is rendered.
▰ METHOD
ORACLE
ORACLEBYTECODE CATCHABLEAI SCANNABLE
Root cause

Root-cause analysis not yet published. The incident description below contains all currently available signal — review the attack transaction directly for definitive forensics.

▰ PROOF OF CONCEPT
DEFIHACKLABS
src/test/2022-03/Umbrella_exp.sol
view forked test on github ↗

Reproducible Foundry test fork from SunWeb3Sec/DeFiHackLabs. Clone the repo, run forge test against the file path above, and replay the exploit against a mainnet fork at the historical block. Use for reproduction only — not for live targets.

Forensic narrative

DeFi oracle Umbrella Network’s Ethereum and BNB Chain (formerly BSC) reward pools were hacked, resulting in the hackers earning around $700,000. The hacker was able to succeed because of an unchecked vulnerability in withdraw() , so anyone could withdraw any amount of funds without having any balance. Attack method (per SlowMist): Contract Vulnerability. Reported loss: $ 700,000.

Primary source
https://twitter.com/UmbNetwork/status/1505529412695076868
Sourced from
slowmist
Technical record
chain
ethereum
protocol
Umbrella Network
bug_class
oracle
date_occurred
2022-03-20
loss_usd
$700,000
source_id
sm:umbrella-network::2022-03-20
Related — same bug class· oracle
2026-05-03
1mo ago
BSC
TUB
BSC token contract exploit (vector undisclosed)
oracle
$27.7K
UNRATED
2026-05-01
1mo ago
ARB
Sharwa.Finance
Oracle Price Manipulation
oracle
$32.9K
UNRATED
2026-04-28
1mo ago
BSC
JUDAO
Price Manipulation
oracle
$228.0K
UNRATED
2026-04-27
1mo ago
BASE
Singularity Finance
Oracle Misconfiguration Exploit
oracle
$413.0K
UNRATED
2026-04-27
1mo ago
Singularity Finance
Contract Vulnerability
oracle
$413.0K
UNRATED
2026-04-27
1mo ago
Singularity Finance
Exploit
oracle
$413.0K
UNRATED
ChainBleed — live web3 threat intelligence