Cozy Finance Hack

REPORTED LOSS $170K
Low Oracle Issue

What happened

On September 2, 2026, DeFi protection protocol Cozy Finance was exploited on Optimism for 170,186 USDC.e (~$160K–$170K USD) across three v2 markets after an attacker submitted false oracle triggers that went completely undisputed during a 5-day challenge window.

On September 2, an attacker whose gas was pre-funded via Tornado Cash purchased protection coverage in three Cozy v2 markets (Aave v2, Curve, and Rabbithole Quests). In the same transaction sequence, the attacker submitted fraudulent "YES" assertions to the markets' underlying UMA Optimistic Oracle price feeds. Because no party submitted an on-chain dispute during the required 5-day challenge period, the false proposals automatically settled early on September 7.

The market payout logic triggered, allowing the attacker to burn ~1.6 million Cozy PTokens (CPT) and claim 170,186 USDC.e in collateral from the Main Set and Rabbithole Set. Within 90 minutes, the attacker bridged the USDC.e to Ethereum, converted the proceeds to ETH, and deposited them back into Tornado Cash.

Attacker Address: 0x003FE735…7c5ccB

Case & protocol details

Classification Other
Protocol Type Exploit/Oracle Issue
Official Website www.cozy.finance/
Protocol Twitter/X @cozyfinance

Evidence & learning

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.