Float Protocol Hack
What happened
Float Protocol's pool was exploited via Oracle Manipulation which led to a loss of 1,440,724 $USD.
Float Protocol is a staking and earning platform running on the Ethereum chain. The protocol's Rari 90 pool was exploited via Oracle Manipulation, which allowed the attacker to gain 1,440,724 $USD worth of assets including $FRAX, $FEI, and $DAI. The attack started with 47 $ETH withdrawn from TornadoCash and then used to buy $FLOAT tokens from the UniV3 pool.
The action led to the $FLOAT price being higher than usual, and then Rari 90 pool that uses UniV3 pool as an oracle was exploited. The exploiter returned 250,000 $USDC to the protocol's multisig wallet. The rest of the stolen funds were transferred through TornadoCash.
Attacker address:
https://etherscan.io/address/0xa2ce300c…61a0e5
Malicious transactions:
https://etherscan.io/tx/0x71872e7b…f0fcfe
https://etherscan.io/tx/0x40db7bd8…827248
https://etherscan.io/tx/0xf09c4519…5ecacf
Malicious contract:
https://etherscan.io/address/0x6ceefd33…d9ade0
Return transaction:
https://etherscan.io/tx/0x560c9362…e7bb0e
Case & protocol details
Security review history
- Extropy Report
Funds Recovery
Recovered
$250K
Net Loss
$1,191,479
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report twitter.com
- report Report twitter.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.