Rhea Finance exploited for $7.6M via fake token contracts and oracle manipulation.
Security & Exploits ·
Rhea Finance experienced an exploit resulting in $7.6M in drained assets, according to security researcher Vladimir S. The attacker's method involved deploying fake token contracts and seeding liquidity into newly created pools to establish a foothold in the protocol's ecosystem.
The exploit leveraged manipulation of both the oracle and validation layer to facilitate extraction of legitimate assets, including USDC, USDT, ZEC, and NEAR tokens. This two-pronged approach—fake tokens coupled with oracle and validation layer tampering—allowed the attacker to bypass safeguards and convert fraudulent positions into real value.
Details regarding the exact timeline of the exploit, whether funds have been recovered, and what operational changes Rhea Finance intends to implement remain undisclosed at this time.