ChainBleedv0.1 · open intel
← back to feed·AVAXORACLE2021-09-21 · 4y ago
Incident · DEFILLAMA

Vee Finance

Flashloan Price Oracle Attack
Estimated loss
$34.00M
VERDICT —AUDIT-CATCHABLE
Same-block oracle-equals-venue is a known anti-pattern by 2021; any audit checking against the oracle-manipulation knowledge file flags the absence of TWAP or off-chain reference on the leveraged-trade entry.
▰ METHOD
Flashloan Price Oracle Attack
ORACLEBYTECODE CATCHABLEAI SCANNABLE
Root cause

Vee Finance's leveraged-trading vault on Avalanche routed swap execution through Pangolin (Uniswap-V2 fork) pairs and computed the trade's expected output / slippage check against the Pangolin pair's spot reserves. The attacker selected illiquid pairs (e.g. WBTC.e/USDT.e, WETH.e/USDT.e on Pangolin where Vee's slippage logic accepted any execution that satisfied a permissive reserve-based check), then for each position opened a leveraged long where the AMM swap step priced the asset based on manipulated reserves — by pre-trading into the same Pangolin pair within the same transaction, the attacker forced Vee's vault to swap user collateral at off-market rates and pocket the difference as the position closed. Across ~5 positions the attacker extracted ~8800 ETH + 213 BTC. Root cause is using the same DEX pair as both the execution venue *and* the price reference, without a TWAP or external oracle gate on slippage.

Forensic narrative

Classification: Ecosystem. Technique: Flashloan Price Oracle Attack. Target type: DeFi Protocol. Affected chains: Avalanche. Implementation language: Solidity.

Primary source
https://veefinance.medium.com/vee-finance-incident-report-2021-09-21-77ad5d2b9fe5
Sourced from
DefiLlama Hacks dataset · api.llama.fi/hacks
Technical record
chain
avalanche
protocol
Vee Finance
bug_class
oracle
date_occurred
2021-09-21
loss_usd
$34,000,000
classification
Ecosystem
technique
Flashloan Price Oracle Attack
target_type
DeFi Protocol
language
Solidity
source_id
dl:619
Related — same bug class· oracle
2026-05-03
1mo ago
BSC
TUB
BSC token contract exploit (vector undisclosed)
oracle
$27.7K
UNRATED
2026-05-01
1mo ago
ARB
Sharwa.Finance
Oracle Price Manipulation
oracle
$32.9K
UNRATED
2026-04-28
1mo ago
BSC
JUDAO
Price Manipulation
oracle
$228.0K
UNRATED
2026-04-27
1mo ago
BASE
Singularity Finance
Oracle Misconfiguration Exploit
oracle
$413.0K
UNRATED
2026-04-27
1mo ago
Singularity Finance
Contract Vulnerability
oracle
$413.0K
UNRATED
2026-04-27
1mo ago
Singularity Finance
Exploit
oracle
$413.0K
UNRATED
ChainBleed — live web3 threat intelligence