DEUS Finance Hack
What happened
On April 28, 2022, an attacker manipulated the DEI price used by DEUS Finance's Fantom lending system and extracted assets from the DeiLenderSolidex pool. Researchers reported approximately $13.4 million in attacker profit, while protocol-loss estimates varied.
Muon’s VWAP implementation relied only on the Solidly USDC/DEI pool and did not filter flash-swap activity. The lending contract also consumed a price from that same manipulable market, so its apparent on-chain and oracle checks were not independent.
Case & protocol details
Attack Timeline
The attacker used more than $143 million in temporary USDC liquidity to buy about 9.5 million DEI in the Solidly USDC/DEI pool. Flash swaps then distorted both the pool's price and the Muon oracle's volume-weighted price feed. Because the lender relied on these correlated values, the inflated DEI valuation was accepted as collateral.
Using the manipulated price, the attacker supplied a small DEI position and borrowed substantially more DEI from DeiLenderSolidex, then repaid the temporary liquidity and retained the difference. The exploit used flash liquidity for scale, but the root failure was treating a manipulable single-pool price path as a trustworthy oracle.
Evidence & learning
Proof of concept
1 availableSources and on-chain records
- report Report twitter.com
- transaction Transaction ftmscan.com
- transaction Transaction ftmscan.com
- analysis Twitter/X Alert twitter.com
- analysis Website reference twitter.com
- analysis Website reference twitter.com
- analysis Website reference twitter.com
- analysis How DEUS Finance Was Exploited for $13.4M on Fantom coindesk.com
- analysis 2022 Year in Review: Lending Protocols certik.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.