Denaria Finance vulnerability exploited via AMM price manipulation in realizePnL() function introduced post-audit, bypassing oracle protections.
Security & Exploits ·
Denaria Finance suffered an exploit resulting in approximately $165k in losses, according to a statement from the protocol. The team has paused access to user interfaces as a precaution and is working with the Linea team and auditors to investigate the incident.
The vulnerability appears to stem from post-audit code changes. A new realizePnL() function introduced after a previous security review allows users to extract profit-and-loss into withdrawable collateral without closing positions. Simultaneously, a fix addressing AMM price manipulation added a useSpotPrice parameter to control whether the protocol references oracle prices or AMM curve prices. However, while maintenance-related checks use the oracle price setting, the realizePnL() function ultimately calls code paths that default to the manipulable AMM price, creating an exploitation vector that circumvents the intended oracle protection.
A complete post-mortem remains pending. The team has invited the attacker to contact them to discuss a bounty and avoid legal action. Users with open positions or vault deposits at the time of the exploit are being evaluated for refunds, though the procedure has not yet been finalized.