Edel Finance lending protocol exploited via oracle manipulation of wGOOGLx exchange rate, resulting in $403k bad debt.
Security & Exploits ·
Edel Finance identified and contained an exploit affecting its lending protocol in which an attacker manipulated the exchange rate between wGOOGLx and GOOGLx tokens. The attacker inflated the collateral value of wGOOGLx by approximately 78x its actual worth, then used the artificially enhanced collateral to borrow from the protocol and generate roughly $403k in bad debt.
The Edel team paused all V1 contracts immediately upon detection. The team has stated that no depositor will incur losses, as it will absorb the bad debt and restore affected balances at a 1:1 ratio. The team has preserved protocol records to identify which balances were affected and is working to determine restoration timing.
Edel V2 is in deployment with a redesigned oracle architecture intended to prevent similar exchange-rate manipulation attacks. The team has also traced the attacker's transactions and is coordinating with exchanges and partners while offering a formal whitehat settlement to the responsible party. A full technical post-mortem detailing the exploit path and V2 improvements will follow.