An attacker manipulated token prices to distort exchange rates and drain about $9.5 million from decentralized stablecoin protocol Resupply. The exploit was first flagged on June 25 by security platform BlockSec Phalcon, which detected a suspicious transaction leading to a…An attacker manipulated token prices to distort exchange rates and drain about $9.5 million from decentralized stablecoin protocol Resupply. The exploit was first flagged on June 25 by security platform BlockSec Phalcon, which detected a suspicious transaction leading to a…

Resupply stablecoin protocol exploited for $9.5M via token price manipulation

2025/06/26 18:12

An attacker manipulated token prices to distort exchange rates and drain about $9.5 million from decentralized stablecoin protocol Resupply.

The exploit was first flagged on June 25 by security platform BlockSec Phalcon, which detected a suspicious transaction leading to a $9.5 million loss. Resupply protocol confirmed the incident on X shortly after, claiming that the affected smart contract had been paused and that the attack only affected its wstUSR market. The team also stated that a thorough post-mortem is in progress and that the core protocol is still operational.

While a detailed breakdown is still pending, preliminary analysis from security researchers points to a classic case of price manipulation within a low-liquidity market. The exploit targeted cvcrvUSD, a wrapped version of Curve DAO’s (CRV) crvUSD token staked through Convex Finance.

Analysts say the attacker manipulated the share price of cvcrvUSD by sending small donations, which artificially inflated its value. Because Resupply’s exchange rate formula relied on this inflated price, the system became vulnerable.

The attacker then used Resupply’s smart contract to borrow 10 million reUSD, the platform’s native stablecoin, with just one wei of cvcrvUSD as collateral. The borrowed reUSD was quickly swapped into other assets on external markets, resulting in a net loss of nearly $9.5 million.

Additional investigation revealed that the attacker exploited an empty ERC4626 wrapper that was serving as a price oracle in the CurveLend pair of the protocol. This allowed the price of cvcrvUSD to spike using just two crvUSD, bypassing the usual collateral requirements.

This incident adds to a growing trend of price manipulation attacks in 2025. Similar exploits have recently affected protocols such as Meta Pool and the GMX/MIM Spell ecosystem, which were both compromised due to oracle vulnerabilities and low-liquidity token manipulation.

Weak pricing mechanisms and flash loans remain common tools for attackers, who continue to target DeFi systems with thin trading volumes despite passing contract security audits. Resupply has not yet confirmed whether user funds will be reimbursed or if recovery efforts are underway.

Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen [email protected] ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Ayrıca Şunları da Beğenebilirsiniz

Little Pepe soars from presale to market spotlight

Little Pepe soars from presale to market spotlight

The post Little Pepe soars from presale to market spotlight appeared on BitcoinEthereumNews.com. Disclosure: This article does not represent investment advice. The content and materials featured on this page are for educational purposes only. Early investors often capture the biggest rewards in crypto, and Little Pepe, priced under $0.005, is emerging as a memecoin that could rival big players. Summary LILPEPE has sold over 15 billion tokens in its presale, raising $25.4 million. The project’s community has grown to more than 41,000 holders and 30,000 Telegram members. Analysts suggest the token could see gains of up to 55x in two years and 100x by 2030. Crypto enthusiasts are aware that early investors tend to benefit the most from the market. Ripple (XRP) and Solana (SOL) are popular tokens that have profited traders. Little Pepe (LILPEPE), valued at less than $0.005, might produce more profit. LILPEPE is swiftly gaining popularity despite its recent introduction. Little Pepe: The market-changing memecoin Little Pepe has surprised everyone with its quick surge in cryptocurrencies. LILPEPE is becoming a popular meme currency. Its presale price is below $0.003. Strong foundations, a distinct market presence, and a developing and enthusiastic community distinguish it from other meme tokens. Many meme currencies use hype to attract investors, but LILPEPE’s rarity, community support, and distinctive roadmap have effectively drawn them in. Currently in its 13th presale stage, more than 15 billion tokens have been sold, generating over $25.4 million and sparking considerable interest. As the token approaches official listing, enthusiasm is growing, and many people believe it could be one of the following major memecoin success stories. LILPEPE’s growing community drives growth The strong community surrounding LILPEPE is a primary reason for its success. LILPEPE has built a loyal following of over 41,000 holders and about 30,000 active members on Telegram. Its rise is being fueled by this. The support of its community…
Paylaş
BitcoinEthereumNews2025/09/19 15:12