Analysis of the UwU Lend Hack

2024-06-11 Slowmist

https://slowmist.medium.com/analysis-of-the-uwu-lend-hack-9502b2c06dbe

SlowMist analyzed the June 10, 2024 UwU Lend hack as a $19.3 million price oracle manipulation against the protocol's EVM lending pools. The attacker used Tornado Cash-funded flash loans and large CurveFinance swaps to suppress and then inflate sUSDE pricing, which let them borrow heavily, liquidate positions, and extract assets for profit. MistTrack linked the activity to attacker wallet 0x841ddf093f5188989fa1524e7b893de64b421f47, three attack transactions, and two holding addresses containing thousands of ETH. SlowMist attributed the root cause to the oracle's use of spot prices and median calculations that could be influenced inside a single transaction.

Related Reports

2024-06-10 • 60% Match
#UwULend
Shares tag: UwULend • Published within a week
« Back