LlamaLend sDOLA vault exploited via unsmoothed oracle reads, with a $190K donation inflating price per share by 13.79% and triggering hard liquidations of 27 borrowers.
Security & Exploits ·
On March 2, 2026, LlamaLend's sDOLA-long2 market was exploited via a two-pronged flash loan attack that hard-liquidated 27 borrowers holding approximately $10.9M in total debt. The attacker manipulated the sDOLA oracle price by donating $190K to the DolaSavings vault, inflating the price per share by 13.79%, which instantly rendered soft-liquidated positions unhealthy and eligible for forced liquidation.
The exploit combined four compounding vulnerabilities: a permissionless exchange function on the LLAMMA AMM that allowed forced soft-liquidation of all positions, extreme supply concentration with 87.9% of sDOLA deposited as collateral, a permissionless stake mechanism that let anyone inflate share prices without minting new shares, and an oracle that read vault price instantaneously without smoothing. The attacker's single exchange call simultaneously forced all positions into soft-liquidation while acquiring 9.83M of 11.77M sDOLA supply, then redeemed it to collapse total supply—enabling the subsequent donation to have outsized oracle impact.
LlamaLend has deprecated the affected market and increased borrow rates to deter further use. The protocol has identified that all LlamaLend oracles should implement price smoothing to prevent instantaneous jumps, with Swiss Stake developing a standardized oracle solution for v2 markets.