The August 23 attack bypassed the protocol’s core lending markets, which remained fully operational throughout the incident. Instead, the hackers exploited governance mechanisms by submitting malicious proposals to remove mandatory execution delays. By eliminating these windows—which typically allow liquidity providers to intervene—the attackers gained administrative control to drain approximately 2,843 ETH and 1.68 million USDC.
Technical analysis revealed that the perpetrators utilized two operator wallets funded via Tornado Cash to deploy a series of counterfeit contracts. These contracts impersonated legitimate vault controllers and price adapters, allowing the attackers to price a fraudulent repo token against the exact liquid balances of the target strategies. Once the proposals were passed, the assets were swept into the attackers' wallets.

Comments (0)
No comments yet. Be the first!