Elevatefi staking vault exploited via oracle manipulation on UniswapV2 spot price; attacker used flash loan to artificially inflate EFI price, extracted 6,256.5 EFI (~$16K loss).
Security & Exploits ·
Elevatefi's EFI staking vault suffered an oracle manipulation exploit on May 19, 2026, resulting in a loss of approximately $16,000. The attacker extracted 6,256.5 EFI tokens—roughly double the amount initially committed to the vault.
The vulnerability stemmed from how the staking vault priced EFI, relying directly on the UniswapV2 spot price via raw reserve data. The attacker used a flash loan to fund a large purchase of EFI from the EFI/DAI pair, artificially inflating the spot price during the staking transaction. This allowed them to receive a disproportionately large packageUsd credit while paying in fewer EFI tokens than would normally be required.
After the price manipulation subsided, the attacker waited for reward epochs to accrue before calling the rebase() and claim() functions at normal market prices, allowing them to withdraw the inflated gains. The exploit exposes how direct reliance on spot prices without time-weighted averaging or other safeguards can enable attackers to extract vault value through short-lived price distortions.