Security incident · 2020-11-14
ValueDefi
According to the public DefiLlama incident dataset, ValueDefi (Ethereum) suffered a security incident on 2020-11-14, with about $7.4M reported lost.
| Date | 2020-11-14 |
|---|---|
| Reported loss | $7.4M |
| Chain | Ethereum |
| Target type | DeFi Protocol |
| Technique class | Oracle Manipulation |
| Technique | Spot Price Manipulation |
| Bridge incident | No |
| Within 2020 | #14 by loss that year, 0.2% of all reported losses that year |
How this kind of attack works
The price feed the protocol relied on was pushed off for a short time, and the attacker borrowed or swapped at the distorted price.
Would a pre-payment check have helped
Oracle manipulation is a price-feed design problem.
Other incidents with the same technique
- CREAM Lending2021-10-27 · $130.0M
- Mango Markets V32022-10-11 · $115.0M
- Venus Protocol2021-05-18 · $100.0M
- Bunny2021-05-19 · $45.0M
- Vee Finance2021-09-21 · $34.0M
- xToken2021-05-12 · $24.0M

