Defrost Hack

TOTAL LOST $12.0M
High Access Control Attacks avalanche

What happened

Defrost has been hacked with losses reaching $12M. The protocol’s V1 and V2 have been affected.

There are suspects the attack was an insider job.

On December 23th 2022, Defrost reported they had been exploited due to missing reentarncy lock in flashloan() and deposit() functions. As a result, the share price of LSWUSDC was manipilated and approximately $173K were gained by the attacker.

Later on, it was revealed that the protocol’s vaults have been exploited as well: a fake collateral token was added, and though calling the setOracleAddress() function, the price oracle was replaced with a malicious one leading to liquidations of user collaterals in Defrost’s vaults. The loss estimation is $12M.

The risk of user funds liquidations in case of replacing oracle to a malicious one was reported by Defiyield in its audit:

https://defiyield.app/audit-database/defiyield/defrost_finance

The attacker address:

https://snowtrace.io/address/0x7373dca2…4469f6

The exploit transaction:

https://snowtrace.io/tx/0xc6fb8217…f0212d

An example transaction of the oracle replacement:

https://snowtrace.io/tx/0x34eb46f4…61c3dd

UPD

On December 26th, the Defrost team reported the stolen funds had been returned, and they are going to check onchain what users have been affected in order to send them their funds back.

Case & protocol details

Classification Rugpull / Key Compromise / Stablecoin
Protocol Type CDP
Affected asset / contract MELT
Smart Contract Language Solidity
Protocol Twitter/X @Defrost_Finance

Funds Recovery

100.0%

Recovered

$12.0M

Net Loss

$0

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.