dTRINITY.org exploited for $257K through flash-loan collateral inflation and repeated deposit/withdraw cycles.
Security & Exploits ·
dTRINITY.org sustained a $257K exploit through a flash-loan attack that manipulated collateral valuation. The attacker borrowed USDC from Morpho, deposited approximately $772 of it, and exploited an inflated index to have that deposit valued as roughly $4.8M in collateral, then borrowed $257K dUSD against the phantom position.
To extract additional value, the attacker executed 127 repeated deposit and withdrawal cycles through a helper contract, draining remaining USDC held in the aToken reserve. The mechanism relied on the protocol's failure to prevent either the index inflation or the cyclical withdrawal pattern that depleted the pool's liquidity.
The victim contract and affected pool have been identified on-chain, though details about the source of the index inflation vulnerability and whether recovery or remediation efforts have begun remain unclear.