Edel Finance Hack
What happened
On July 1, 2026, an attacker manipulated the conversion rate between GOOGLx and its wrapped form, wGOOGLx, in Edel Finance’s lending protocol. The inflated wGOOGLx balance was accepted as collateral at roughly 78 times its normal value, allowing borrowing against assets the attacker had not economically deposited. Edel reported about $403,000 in bad debt and paused version one of the lending protocol.
The incident was an exchange-rate accounting failure, not a Chainlink price-feed failure.
Edel Finance treated a permissionlessly manipulable wGOOGLx conversion rate as reliable collateral value. Lending integrations must validate the economic backing and manipulation resistance of wrapper exchange rates, constrain same-transaction collateral-rate changes, and separate an underlying asset’s market price from the wrapper’s redeemable value.
How it happened
The attacker used the wGOOGLx wrapping path to make a small amount of tokenized Google-stock collateral appear much larger to Edel’s lending market. The protocol valued collateral using the manipulated wrapper conversion rate, so the attacker could borrow real assets against an artificially inflated wGOOGLx position. The principal exploit transaction left the lending pool with bad debt once the collateral conversion rate normalized.
Edel halted the affected version-one market, said it would absorb the loss so depositors were made whole, and announced a redesigned version two. The exploit illustrates why a correct external spot-price feed does not protect a lending market whose collateral share or wrapper exchange rate is manipulable.
Protocol details
Evidence
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.