Cozy Finance Hack
What happened
On September 2, 2026, DeFi protection protocol Cozy Finance was exploited on Optimism for 170,186 USDC.e (~$160K–$170K USD) across three v2 markets after an attacker submitted false oracle triggers that went completely undisputed during a 5-day challenge window.
On September 2, an attacker whose gas was pre-funded via Tornado Cash purchased protection coverage in three Cozy v2 markets (Aave v2, Curve, and Rabbithole Quests). In the same transaction sequence, the attacker submitted fraudulent "YES" assertions to the markets' underlying UMA Optimistic Oracle price feeds. Because no party submitted an on-chain dispute during the required 5-day challenge period, the false proposals automatically settled early on September 7.
The market payout logic triggered, allowing the attacker to burn ~1.6 million Cozy PTokens (CPT) and claim 170,186 USDC.e in collateral from the Main Set and Rabbithole Set. Within 90 minutes, the attacker bridged the USDC.e to Ethereum, converted the proceeds to ETH, and deposited them back into Tornado Cash.
Attacker Address: 0x003FE735…7c5ccB
Case & protocol details
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report x.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.