Chi Protocol's USC stablecoin lost ~$8.5K to oracle manipulation and redeem-at-par logic error allowing attackers to burn depegged USC at peg value.
Security & Exploits ·
Chi Protocol's USC stablecoin experienced an approximately $8.5K loss on July 13, 2026, when an attacker exploited a flaw in the token's redemption mechanism. The ArbitrageV5.burn() function redeemed USC at a fixed $1 price without verifying the token was actually trading at peg, unlike the minting function which enforced such a check. An attacker flash-loaned 5 WETH from Balancer, purchased heavily discounted USC from a thin Uniswap V2 pool, and burned it at par value to redeem full-value collateral (weETH, stETH, and WETH), profiting approximately 4.66 WETH.
The vulnerability stemmed from an asymmetry in price validation: while the burn function calculated redemption as amount × $1 / reservePrice without checking USC's actual spot price, the mint function enforced strict peg requirements. This oracle manipulation was possible because the redemption logic treated depegged USC as if it maintained its $1 target value.
The exploit's future impact appears limited: protocol reserves are nearly exhausted, with total value locked around $883. The attacker address and victim contract are documented on-chain, though it remains unclear whether additional tranches of collateral or recovery mechanisms exist.