dTRINITY Hack
What happened
On March 17, 2026, dTRINITY's Ethereum dLEND market incurred approximately $257,000 in dUSD bad debt through a liquidity-index inflation exploit. dTRINITY reports that the bad debt was fully covered.
An accounting edge case inherited from the Aave V3 fork let flash-loan fees disproportionately inflate liquidityIndex when the cbBTC reserve was effectively empty. The resulting precision and accounting distortion overstated collateral value.
Case & protocol details
Market Context at Time of Hack
Attack Timeline
The attacker targeted an almost-empty cbBTC reserve and repeatedly used flash-loan premium accrual to inflate its liquidity index. The distorted accounting overstated collateral value, allowing the attacker to borrow dUSD before recovering the deposited collateral.
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report x.com
- report Report wublock123.com
- report Report x.com
- analysis Website reference x.com
- analysis dTRINITY: Incident Disclosures docs.dtrinity.org
- analysis BlockSec: Weekly Web3 Security Incident Roundup, Mar 16–Mar 22, 2026 blocksec.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.