DEUS Finance Hack

TOTAL LOST $17.9M
High Flash Loan Attacks Fantom

What happened

On April 28, 2022, an attacker manipulated the DEI price used by DEUS Finance's Fantom lending system and extracted assets from the DeiLenderSolidex pool. Researchers reported approximately $13.4 million in attacker profit, while protocol-loss estimates varied.

Technical Root Cause

Muon’s VWAP implementation relied only on the Solidly USDC/DEI pool and did not filter flash-swap activity. The lending contract also consumed a price from that same manipulable market, so its apparent on-chain and oracle checks were not independent.

Case & protocol details

Classification Oracle Manipulation / Flash-Swap Price Manipulation
Protocol Type CDP
Affected asset / contract DEI
Smart Contract Language Solidity
Official Website deus.finance/
Protocol Twitter/X @DeusDao

Attack Timeline

The attacker used more than $143 million in temporary USDC liquidity to buy about 9.5 million DEI in the Solidly USDC/DEI pool. Flash swaps then distorted both the pool's price and the Muon oracle's volume-weighted price feed. Because the lender relied on these correlated values, the inflated DEI valuation was accepted as collateral.

Using the manipulated price, the attacker supplied a small DEI position and borrowed substantially more DEI from DeiLenderSolidex, then repaid the temporary liquidity and retained the difference. The exploit used flash liquidity for scale, but the root failure was treating a manipulable single-pool price path as a trustworthy oracle.

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.