DEUS Finance Hack

TOTAL LOST $3.0M
Medium Flash Loan Attacks fantom

What happened

On March 15, 2022, an attacker used flash liquidity to manipulate the Fantom USDC/DEI pool price used by DEUS Finance's lending logic, causing user positions to appear insolvent and extracting roughly $3 million.

Technical Root Cause

The lending and liquidation path accepted a manipulable AMM spot price for the USDC/DEI pair as an oracle input, allowing temporary flash-loan price distortion to change collateral and liquidation outcomes.

Case & protocol details

Classification Oracle Manipulation
Protocol Type CDP
Affected asset / contract DEI
Smart Contract Language Solidity
Official Website deus.finance/
Protocol Twitter/X @DeusDao

Attack Timeline

The affected DEI lending system treated a manipulable USDC/DEI AMM price as a collateral and liquidation input. The attacker borrowed liquidity in one transaction, distorted the pool price, liquidated positions that the protocol now treated as insolvent, unwound the position, and repaid the borrowed liquidity. Reporting at the time put the profit at about $3 million; DEUS paused the affected lending contract and said it would review the incident.

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.