Edelfi lending protocol exploited for $403K via oracle manipulation on wrapped stock token collateral.
Security & Exploits ·
Edelfi, an Ethereum lending protocol modeled on Aave, suffered an exploit on July 1 that drained approximately $403K from its pools. The attacker manipulated the price oracle used to value wrapped stock tokens—such as wGOOGLx—which serve as collateral on the platform. By executing a 41x loop of supply and borrowing activity, the attacker distorted the exchange rate within the wrapper vault, causing the oracle to report wGOOGLx at roughly $28K per token when the actual price hovered near $180.
The vulnerability stemmed from how Edelfi's oracle calculated collateral value—it relied directly on the ERC-4626 wrapper's share-to-asset conversion function, which divides total underlying balance by total supply and proved malleable under flash-loan conditions. Armed with artificially inflated collateral valuations, the attacker borrowed 204K USDC alongside tokenized stocks including wSPYx, wQQQx, wMSTRx, wNVDAx, and wTSLAx, netting roughly $403K in total and reducing the affected pool's total value locked from approximately $602K.
The exploit highlights a known risk in oracle designs that depend on pool or vault state rather than external price feeds. It remains unclear whether Edelfi has paused deposits, implemented additional validation checks, or coordinated with affected users on recovery steps.