Odaily Planet Daily reports that the on-chain Ploutus protocol liquidity pool (0xD060…945D2) on Ethereum was attacked due to an oracle configuration error, resulting in a loss of approximately $390,000.
Analysis shows that the pool incorrectly pointed the USDC price to Chainlink’s BTC/USD feed, causing a significant deviation in the price. The attacker exploited this vulnerability by collateralizing only 8 USDC to borrow 187 ETH. On-chain data indicates that the attack transaction occurred in the next block after the configuration change was confirmed, suggesting the attacker monitored the updates in real-time and quickly exploited the parameter change.
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
Ploutus oracle misconfiguration exploited, liquidity pool loss of approximately $390,000
Odaily Planet Daily reports that the on-chain Ploutus protocol liquidity pool (0xD060…945D2) on Ethereum was attacked due to an oracle configuration error, resulting in a loss of approximately $390,000.
Analysis shows that the pool incorrectly pointed the USDC price to Chainlink’s BTC/USD feed, causing a significant deviation in the price. The attacker exploited this vulnerability by collateralizing only 8 USDC to borrow 187 ETH. On-chain data indicates that the attack transaction occurred in the next block after the configuration change was confirmed, suggesting the attacker monitored the updates in real-time and quickly exploited the parameter change.