Rhea Finance has adjusted the impact level from the recent exploit, raising the estimated loss from $7.6 million to approximately $18.4 million after a detailed internal investigation.
The update published on April 17 also confirmed the root cause of the attack and outlined early recovery efforts. This marks a shift from the initial detection phase to post-incident analysis and remediation.
The slippage vulnerability has been identified as the root cause.
According to Rhea Finance, the exploit targeted its margin trading feature, exploiting a weakness in the slippage protection mechanism of trades to withdraw funds from the reserve.
Preliminary investigation results show that the system has aggregated expected output values across multiple swap steps. However, the system did not account for cases where tokens were reused in transactions.
This allows the attacker to build a chain of swap transactions to bypass the expected protective layer, redirecting borrowed assets into liquidity pools controlled by the attacker.
The exploit was carried out through a coordinated setup involving fake token contracts and manipulated liquidity pools. This move allowed the attacker to distort prices and trigger a chain of forced liquidations.
These liquidation events have ultimately depleted a significant portion of the protocol's reserves.
A portion of the funds has been recovered as investigations continue.
Rhea Finance stated that a portion of the exploited funds has been recovered or frozen. The attacker has returned approximately 3.3 million USD in USDC and 1.56 million NEAR to the protocol's lending contract.
In addition, approximately 4.34 million USD in USDT has been frozen, including funds blocked by Tether, as part of a coordinated effort to limit further movement of assets.
The team has also initiated formal tracing procedures with centralized exchanges to identify the attacker. At the same time, they are trying to establish direct contact to negotiate the repayment of the remaining funds.
Despite these developments, Rhea Finance warns that findings are still preliminary and may change as deeper on-chain analyses are conducted.
The protocol pauses as recovery and remediation plans gradually take shape.
After the exploit, Rhea Finance paused lending contracts to prevent further losses and preserve recoverable funds. The protocol is currently working with external security teams to finalize forensic analysis and implement fixes before any potential restart.
The team stated that they plan to use reserve funds and operational resources as part of a broader recovery and compensation framework for affected users, although details are still being finalized.
This incident follows initial reports on April 16 indicating an exploit worth 7.6 million USD related to Oracle manipulation through fake tokens.
The adjusted figures and confirmed attack vulnerabilities now indicate that this is a complex breach of much larger scale than initially understood.
https://coinphoton.com/rhea-finance-dinh-chinh-thiet-hai-len-18-4-trieu-usd-va-xac-nhan-lo-hong-truot-g.html
