Oracle Manipulation Drains $7.8M From Warp Finance's Lending Vaults
Warp Finance became the newest entry in a lengthening list of DeFi protocols undone by price-oracle manipulation.
A wallet funded with just one ETH routed through Tornado Cash deployed a contract that combined two forms of borrowed liquidity: a $180 million flash swap pulled from Uniswap and a $51 million flash loan drawn from dYdX. Because Warp Finance's lending market priced collateral using Uniswap LP token values directly, the attacker was able to distort those prices within a single transaction, borrow far beyond what their real collateral justified, and walk away having pulled roughly $7.8 million in DAI from the protocol's vaults.

Wallets and contracts identified in the incident:
- Attacker contract: 0xdf8bee861227ffc5eea819c332a1c170ae3dbacb
- Warp Oracle: 0x4A224CD0517f08B26608a2f73bF390b01a6618c8
- Warp Control: 0xBa539B9a5C2d412Cb10e5770435f362094f9541c
- wBTC-wETH LP Vault: 0x3c37f97F7d8f705cc230f97a0668f77a0e05D0aA
- WETH-DAI LP Vault (the vault that was drained): 0x13db1CB418573f4c3A2ea36486F0E421bC0D2427
- USDT-WETH LP Vault: 0xCDb97F4C32F065b8e93cF16BB1E5d198bcF8cA0d
- USDC-WETH LP Vault: 0xb64dfae5122D70Fa932f563c53921FE33967B3E0
- DAI Vault: 0x6046c3Ab74e6cE761d218B9117d5c63200f4b406
- USDT Vault: 0xDadd9bA311192d360Df13395E137f1E673C91deB
- USDC Vault: 0xae465FD39B519602eE28F062037F7B9c41FDc8cF
Summary of the exploit (per rekt OPSEC analysis):
Warp Finance's WarpVaultSC contract lost approximately $7.8 million in DAI and USDC. The exploit transaction landed at 10:24:41 PM UTC on December 17, 2020. The underlying cause was Warp Finance's dependence on an AMM-based price feed — specifically the UniswapV2 WETH-DAI pair's LP token — which the attacker could manipulate within the same transaction using flash-loaned capital. That manipulation let the attacker draw out roughly double the USDC and DAI their actual collateral should have permitted. Notably, the attacker did not walk away with immediate profit: the LP tokens posted as collateral remain locked inside Warp Finance because the resulting borrow position is underwater.
How the transaction unfolded:
- The attacker opened four simultaneous flash loans totaling 2.9 million DAI and 344.8K WETH, sourced from dYdX and UniswapV2: 90K WETH from the WETH-WBTC pool, 82K WETH from WETH-USDC, 96K WETH from WETH-USDT, 76K WETH from dYdX, and 2.9 million DAI from dYdX.
- The dYdX-sourced 2.9 million DAI and 76K WETH were deposited into the UniswapV2 WETH-DAI pair, minting 94.349K LP tokens.
- Those newly minted LP tokens were deposited into WarpVaultLP as collateral under the attacker's account, at a point when the UniswapV2 WETH-DAI LP token was priced at 58,815,427.
- The attacker then swapped 341K WETH for 47.6 million DAI on UniswapV2, artificially inflating DAI's price and, as a consequence, more than doubling the LP token's computed value to 135,470,392.
- With collateral now valued far higher than it should have been, the attacker borrowed 3.86 million DAI and 3.9 million USDC from Warp Finance — a combined sum of roughly $7.8 million.
- All four flash loans were then repaid to dYdX and UniswapV2, with transaction fees consuming most of what would otherwise have been the attacker's profit.

Despite the roughly $7.8 million shortfall this created for the protocol, the attacker gained no immediate payout: the borrow position sits underwater, and the 94.349K LP tokens backing it remain frozen inside Warp Finance. Analysts noted they continued watching the attacker's wallet for any further activity. (Pie chart analysis credited to @n2ckchong.)
Because most of the exploited funds are technically still recoverable — sitting locked behind an underwater position that a new vault controller could liquidate — the incident has effectively produced a large standing bounty rather than a clean theft. Some observers speculated that a future attacker using this same technique might choose to hold funds for ransom instead, demanding payment from a protocol under threat of further reputational damage rather than simply taking the money outright.
The episode also drew attention to Warp Finance's public acknowledgment of the "white hat" developers it thanked on Twitter after the incident, with several observers noting how familiar those names looked in the context of the DeFi security community — underscoring the recurring tension in the space between the pseudonymous, dual-purpose roles many technical contributors occupy.
Get new scam files the moment we publish them — usually 2–3 emails a week.