DLMC protocol exploited for $222.5K on BNB Chain via oracle attack; attacker laundered 37 ETH through Tornado Cash.
Security & Exploits ·
The DLMC protocol was exploited for approximately $222.5K on BNB Chain through a price or oracle manipulation attack. The attacker subsequently moved 37 ETH to Ethereum using cross-chain bridges and privacy mechanisms to obscure the trail of stolen funds.
The exploit workflow involved converting the stolen assets and routing them via li.fi and Mayan Swift to move funds from BNB Chain to Ethereum. Once on Ethereum, the attacker fragmented the 37 ETH across multiple Tornado Cash deposit notes of 10 ETH and 1 ETH denominations, a technique commonly used to break the on-chain link between source and destination addresses.
The precise mechanism of the oracle attack—which price feed was manipulated, whether via flash loan or external data feed compromise—has not been detailed in available reports. The total value actually extracted, the identity of the attacker, and whether DLMC or affected users have initiated recovery or protocol patches remain unconfirmed.