BonqDAO Suffers a $120 Million Loss Through Price Oracle Manipulation

Summary

In February 2023, BonqDAO, a lending platform hosted on the Polygon network, was hacked. The attacker exploited protocol’s price oracle weakness to manipulate the price of the $WALBT token. This allowed the attacker to borrow 100 million $BEUR, a stablecoin pegged to the euro, and liquidate other users’ collateral. The total loss from the hack was estimated to be around $120 million.

Attackers

The attackers are unidentified.

Attacker Addresses:

Polygon

Ethereum

Malicious Contracts:

Losses

~$120 million

- $108 million worth of 98,658,538 BEUR
- $12 million worth of 113,813,998 WALBT

Timeline

Security Failure Causes

  • Lack of TWAP Oracles: BonqDAO allowed instantaneous price updates, which left the protocol susceptible to exploitation. In this instance, the attacker was able to manipulate the price oracle to change the value of the $WALBT token.
  • Lack of Oracle Diversity: Relying on a single source for price data left BonqDAO vulnerable to this kind of attack. Had the protocol used multiple price sources, the attacker’s manipulation would have been much less likely to succeed.