Inverse Finance Incident Analysis
ID: ac12bb27-fe14-5aa5-935c-95216ab4d5cc
STIX ID: report--ac12bb27-fe14-5aa5-935c-95216ab4d5cc
Feed Name: CertiK Blog
On 16 June 2022 an attacker executed a sophisticated flash-loan exploit against Inverse Finance by borrowing ~27,000 WBTC from Aave, depositing and swapping through Curve and Yearn to manipulate a YVCrv3CryptoFeed oracle, then borrowing and extracting DOLA and other assets. The attacker converted stolen assets to ETH (totaling ~1,068.215 ETH, ≈ $1.26M), routed large amounts through Tornado Cash, and left a remainder in the malicious contract; the report details the attack steps, the oracle vulnerability, and on-chain asset flows.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
