Cyrus Finance Hack
What happened
On 22 March 2026, Cyrus Finance reported that an attacker used a flash loan to manipulate the ETH/USDT price used by one of its BNB Chain pools. The protocol's initial notice estimated the loss at roughly $500,000; BlockSec's later analysis estimated about $512,000. This replaces a materially higher imported loss figure.
A liquidity-removal calculation trusted the current PancakeSwap V3 spot price. Because that price was flash-loan manipulable, it could be used to make a withdrawal appear valid at an economically false valuation. Critical pricing paths need manipulation-resistant observations such as a suitably designed TWAP plus bounds and circuit breakers.
Case & protocol details
Market Context at Time of Hack
Attack Timeline
Audit assessment
Review priorities based on the documented failure pattern in Cyrus Finance (March 2026).
Critical checks
- Verify every sensitive logic path is guarded by appropriate access controls and input validation - see the Flash Loan Attacks attack class for patterns
- Audit oracle price feeds for manipulation risks - ensure time-weighted average prices (TWAPs) or multi-source aggregators are used, not spot prices
Evidence & learning
Sources and on-chain records
- report Report x.com
- transaction Transaction bscscan.com
- analysis Cyrus Finance incident notice t.me
- analysis BlockSec weekly incident roundup, 23–29 March 2026 blocksec.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.