BlueBerry Hack

TOTAL LOST $1.4M
Medium Flash Loan Attacks Ethereum

What happened

Blueberry's Ethereum lending market was exploited after a faulty oracle deployment valued low-decimal assets incorrectly and borrowing was enabled earlier than intended. About $1.4 million was affected; a whitehat front-ran and returned roughly 80%, and Blueberry committed its multisig funds to make lenders whole.

Technical Root Cause

PriceOracleProxy delegated to a CoreOracle that returned prices at 18 decimals. Assets with fewer decimals were incorrectly valued when borrowed, and borrowing had been enabled before the configuration was intended to go live.

Case & protocol details

Classification Oracle decimal-scaling misconfiguration / collateral-valuation error
Protocol Type Yield
Smart Contract Language Solidity
Official Website app.blueberry.garden
Protocol Twitter/X @blueberryFDN

Attack Timeline

The attacker used a 1 WETH Balancer flash loan, deposited it into the lending market, and borrowed available liquidity in assets with fewer than 18 decimals, which the misconfigured oracle severely undervalued. The drained assets included OHM, USDC, and WBTC.

A whitehat front-ran and returned about 80% to the DAO multisig. The remaining amount was lost to the validator, while Blueberry stated it had sufficient multisig funds to reimburse lenders.

Security review history

Funds Recovery

80.0%

Recovered

$1.1M

Net Loss

$280,000

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.