BlueBerry Hack
What happened
Blueberry's Ethereum lending market was exploited after a faulty oracle deployment valued low-decimal assets incorrectly and borrowing was enabled earlier than intended. About $1.4 million was affected; a whitehat front-ran and returned roughly 80%, and Blueberry committed its multisig funds to make lenders whole.
PriceOracleProxy delegated to a CoreOracle that returned prices at 18 decimals. Assets with fewer decimals were incorrectly valued when borrowed, and borrowing had been enabled before the configuration was intended to go live.
Case & protocol details
Attack Timeline
The attacker used a 1 WETH Balancer flash loan, deposited it into the lending market, and borrowed available liquidity in assets with fewer than 18 decimals, which the misconfigured oracle severely undervalued. The drained assets included OHM, USDC, and WBTC.
A whitehat front-ran and returned about 80% to the DAO multisig. The remaining amount was lost to the validator, while Blueberry stated it had sufficient multisig funds to reimburse lenders.
Security review history
- Pashov Audit Group Report
Funds Recovery
Recovered
$1.1M
Net Loss
$280,000
Evidence & learning
Proof of concept
1 availableSources and on-chain records
- report Report x.com
- report Post-mortem medium.com
- report Post-mortem medium.com
- report Post-mortem medium.com
- transaction Transaction etherscan.io
- analysis Twitter/X Alert twitter.com
- analysis Blueberry Attack Analysis coinlive.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.