A recent attack in the DeFi space has revealed weaknesses in cryptocurrency storage systems, specifically the ERC-4626 vault. The hacker exploited a familiar tool called a flash loan to distort the exchange rate and deceive the pricing system, also known as an oracle.
On February 27, a hacker executed what is called a “donation attack” by borrowing about 4 million USD from Aave – a cryptocurrency lending platform. The target was the wUSDM token, part of the ERC-4626 vault system of Mountain Protocol. This is a profit-generating cryptocurrency linked to the stablecoin USDM – a cryptocurrency with stable value backed by short-term U.S. bonds. The hacker deliberately pushed the exchange rate of wUSDM from 1.06 to 1.7, making it appear more valuable than it actually was.
Next, the hacker used two accounts to ‘liquidate’ themselves – pretending to sell their own assets – on Venus Protocol, another lending platform. Although Venus quickly locked transactions to prevent this, the hacker still pocketed about 200,000 USD in profit. Meanwhile, Venus suffered more than 716,000 USD in losses, according to an analysis report from Chaos Labs, a risk management company.
Yoni Keselbrener, head of DeFi at Lightblocks Labs, shared with The Block: “Both teams responded promptly by locking the market, adjusting risk rules, and bringing the exchange rate back to normal.” Keselbrener is a contributor to eOracle, a system that provides real-world data for decentralized applications on Ethereum.
The ERC-4626 vault, launched in May 2022, is the standard for creating cryptocurrency storage solutions. However, a report from Chaos Labs pointed out that this standard “lacks protections when exchange rates fluctuate abnormally in lending platforms.”
In January 2024, Euler Finance published a study warning that most ERC-4626 vaults lack safety mechanisms to prevent rate manipulation. They suggest that multiple protective measures should be combined for greater effectiveness.
Chaos Labs also stated that the attack could have been avoided if measures such as: “The wUSDM contract should use a price-checking system from various sources. Or if Venus had been warned earlier, they could have limited the abnormal price increase.” To prevent recurrence, Aave plans to implement the CAPO mechanism – a tool to limit artificial price increases – for all profit-generating cryptocurrencies to prevent hackers from creating phantom profits.
Curve Finance's X account commented: “This vulnerability occurs not only with standard vaults but with all types of vaults. This is a common mistake seen in lending platforms.”
Keselbrener noted: “The CAPO mechanism is very effective, but requires additional complex programming and needs to be continuously monitored. We must ensure it does not hinder legitimate profits while still preventing hackers.” He added: “As DeFi becomes more complex, we cannot rely solely on simple price data. It is essential to understand the risks of each type of cryptocurrency. A price-checking system from multiple sources is not a drawback, but an important layer of protection. Dedicated oracle providers can design measures to detect and prevent such attacks.”
Disclaimer: This article is for informational purposes only and is not investment advice. Investors should conduct thorough research before making decisions. We are not responsible for your investment decisions.


