ElevateFi Hack

Reported loss $16K
Polygon
Spot Price Manipulation

What happened

On May 19, 2026, an attacker exploited ElevateFi's Polygon staking vault after manipulating the DAI/EFI spot price. The reproduced on-chain transaction shows approximately 6,264.86 EFI paid from the vault, valued near $16,000.

Technical root cause

ElevateFi priced fixed-USD staking packages from raw DAI/EFI AMM reserves via getReserves(), without a time-weighted price, deviation bound, or independent oracle. The reward accounting remained denominated in the package's fixed USD value.

How it happened

  1. The attacker used temporary DAI liquidity to raise the DAI/EFI spot price, opened 100 fixed-USD staking packages while EFI was artificially expensive, then unwound the price.
  2. After one reward epoch, the fixed-USD rewards were settled at the lower normalized EFI price, drawing EFI from the staking vault.

Protocol details

Classification Oracle Manipulation
Protocol Type DeFi Protocol
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.