DeFiTuna lending pools drained of $580K in Solana exploit
Security & Exploits ·
An attacker siphoned $580,000 from DeFiTuna's lending pools on Solana, leaving a matching shortfall in USDC.
DeFiTuna, a lending protocol operating on Solana, disclosed that its lending pools were exploited for a total of $580,000, with the attack producing a USDC deficit equal to that amount. The disclosure came directly from the protocol, which confirmed the incident on X. Two distinct sources are tracking the cluster, both pointing to the same figure and the same mechanism: funds pulled from pooled lending capital, matched one-to-one by a hole in the protocol's USDC reserves.
Lending pools like the ones targeted at DeFiTuna function by aggregating depositor capital into shared smart contracts, which then issue loans against that pooled liquidity. When an attacker manages to drain assets from such a pool, the shortfall typically shows up as a deficit in whatever asset backed the loans or reserves, in this case USDC, meaning depositors or the protocol itself are left short by the exact amount extracted. Background on how pooled capital structures work across DeFi, including lending markets, is laid out in a general explainer on pools.
The exploit places DeFiTuna alongside a string of recent pool-related incidents across DeFi. Rhea Finance's losses from a separate liquidity pool exploit were revised upward to $18.4 million after a post-mortem found attackers had manipulated pools using fake tokens. Raydium separately disclosed plans to reimburse users after roughly $1.34 million was drained from five inactive liquidity pools tied to a retired AMM program that had been phased out since 2021. Elsewhere, stress in Solana lending markets intensified after a KelpDAO rsETH hack pushed Kamino's USDC markets to 100% utilization with zero liquidity available in key pools, illustrating how quickly pool-based systems can seize up under strain.
What remains unclear in the DeFiTuna case is how the attacker gained access to drain the lending pools, whether any funds have been recovered or frozen, and whether the protocol plans to compensate affected depositors. No technical post-mortem has been referenced yet, and it is not known whether DeFiTuna will pause deposits or lending activity while the incident is investigated. Further detail on the attack vector and any remediation steps has not been disclosed.