A recent attack in the DeFi space has revealed vulnerabilities in cryptocurrency storage systems, specifically the ERC-4626 vault. The hacker exploited a familiar tool called a flash loan (a quick loan that is borrowed and repaid instantly) to distort the exchange rate and deceive the pricing system, also known as an oracle.
On February 27, a hacker executed what is called a “donation attack” by borrowing about $4 million from Aave – a cryptocurrency lending platform. The target was the wUSDM token, part of the Mountain Protocol's ERC-4626 vault system. This is a profit-bearing cryptocurrency linked to the USDM stablecoin – a cryptocurrency with stable value due to being backed by short-term US bonds. The hacker deliberately pushed the exchange rate of wUSDM from 1.06 to 1.7, making it appear more valuable than it actually was.
Next, the hacker used two accounts to self-“liquidate” – pretending to sell their own assets – on Venus Protocol, another lending platform. Although Venus quickly locked transactions to prevent this, the hacker still pocketed around $200,000 in profit. Meanwhile, Venus suffered losses of over $716,000, according to an analysis report from Chaos Labs, a risk management company.
Yoni Keselbrener, head of DeFi at Lightblocks Labs, shared with The Block: “Both teams responded in a timely manner by locking the market, adjusting risk rules, and bringing the exchange rate back to normal.” Keselbrener is a contributor to eOracle, a system that provides real-world data for decentralized applications on Ethereum.
The ERC-4626 vault, launched in May 2022, is the standard for creating cryptocurrency storage. However, a report from Chaos Labs indicates that this standard “lacks protective measures when the exchange rate changes abnormally on lending platforms.”
In January 2024, Euler Finance published a study warning that most ERC-4626 vaults do not have safety mechanisms to prevent exchange rate manipulation. They argued that multiple protective measures need to be combined for greater effectiveness.
Chaos Labs also noted that the attack could have been avoided if measures had been implemented such as: “The wUSDM contract should use a price-checking system from multiple different sources. Or if Venus had been warned early, they could have limited the unusual increase in exchange rates.” To prevent recurrence, Aave plans to implement the CAPO mechanism – a tool to limit artificial price increases – for all profit-bearing cryptocurrencies, preventing hackers from generating phantom profits.
Curve Finance's X account commented: “This vulnerability does not only occur with standard vaults but with all types of vaults. This is a common mistake seen in lending platforms.”
Keselbrener remarked: “The CAPO mechanism is very effective, but it requires additional complex programming and needs to be continuously monitored. We must ensure it does not hinder legitimate profits while still preventing hackers.” He added: “As DeFi becomes increasingly complex, we cannot rely solely on simple price data. It is necessary to understand the risks of each type of cryptocurrency. A price-checking system from multiple sources is not a disadvantage, but an important layer of protection. Specialized oracle providers can design measures to detect and prevent such attacks.”
Disclaimer: This article is for informational purposes only and should not be construed as investment advice. Investors should do their due diligence before making decisions. We are not responsible for your investment decisions.


