logo

Cauldron Flashloan Attack

ID: 0abb3866-9e3c-53c2-ad84-ca8adc996cc8

STIX ID: report--0abb3866-9e3c-53c2-ad84-ca8adc996cc8

Feed Name: CertiK Blog

Threat Score
70/100

Date Published: 2022-09-07

Date Updated: 2026-06-11

...
...

TL;DR: On 2022-09-06 a flashloan-based exploit targeted the CauldronV2 smart contract on Avalanche, enabling an attacker to manipulate an exchangeRate oracle (derived from a JoeSwap pool) via injected liquidity and a public updateExchangeRate call, withdraw ~998k NXUSD, and realize ~370k USDC profit; the report includes the attack flow, vulnerable code paths, transaction links, attacker and contract addresses, and asset tracing results.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.