Pragma Flags 6 Starknet Feeds After $3.5M Exploit
The incident exposes a deeper lending risk: an oracle can price collateral accurately enough on paper while thin markets make liquidation losses unavoidable.
Every Zipp story tagged #OracleManipulation, newest first.
The incident exposes a deeper lending risk: an oracle can price collateral accurately enough on paper while thin markets make liquidation losses unavoidable.
The proposal could slow interest accrual across seven Base markets, but it does not guarantee reserve transfers, supplier repayments or restored borrowing.
The Mango Markets playbook strikes twice in four days, draining two lending markets through the same illiquid-token loophole that cost Avraham Eisenberg's victims $116M in 2022.
The network halt is the headline. The signal is the attack shape: a thin-liquidity governance token pumped 100x in 20 minutes, then used as collateral. Same mechanic as the 2022 Mango Markets exploit.
Security firms linked the suspected drain to illiquid MAMO collateral manipulation, with WELL down around 13% and MAMO off roughly 9%.
The protocol fix is live and verifiable, but ZEC still trades below the $500 area Ironwood was supposed to put back on the map, leaving the supply repair in technical hands and the price repair in…
The attacker netted under $1M, but the mechanism (an unguarded oracle write with no liquidation delay) is the real warning for every BTC-collateralized lending book.
The exploit hit Edel but the bug lives in credit markets built on tokenized equities, where 1:1 stock backing is meaningless if the wrapper, vault and exchange rate can be manipulated.
The attacker weaponized a registered forwarder and future-dated oracle reports to mint artificial trading profits, draining the OLP Vault before the team froze trading.
The attacker used Ostium's own Gelato-run price automation against it, forging future-dated oracle reads to extract an $18M USDC payout. It is the second major oracle hit in a week.
A zeroed oracle signature was the entire vulnerability: one byte in the wrong place let a single attacker borrow against collateral the system could not price, draining the Bonzo money market on…
A single verifier-side price bug let an attacker mint $9M of unbacked borrowing power on Hedera's largest lending market.
The attacker slipped a fake price past Supra oracle verification, borrowing $10M against 250 worthless SAUCE tokens. Nearly all of Hedera's DeFi value walked out the door in 24 hours.
The attacker used a signature-verification bug in Supra's oracle to spoof SAUCE prices, borrow against phantom collateral, and drain roughly $9.05M before the protocol was paused.
The flaw sat in the wrapper and the oracle, not in the equity itself. Edel's exploit is the first visible sign that wrapped tokenized stocks add a second pricing problem on top of the underlying…