Inverse Finance Frontier Hack

TOTAL LOST $15.6M
High Oracle Manipulation & Price Manipulation Ethereum

What happened

On April 2, 2022, an attacker used a price-oracle manipulation to borrow about $15.6 million from Inverse Finance's Anchor money market, now called Frontier. The attacker inflated the collateral value of INV, then borrowed DOLA, ETH, WBTC, and YFI from Anchor's pools. Inverse paused borrowing and began a DAO-led plan to repay affected users.

This is the April incident, distinct from Frontier's later June 2022 oracle incident.

Technical Root Cause

Anchor's INV collateral valuation depended on a Keep3r TWAP whose sampling method could be manipulated through trades in a low-liquidity SushiSwap market. The inflated oracle value let the attacker over-borrow against INV collateral.

Case & protocol details

Classification Oracle Manipulation
Protocol Type CDP
Affected asset / contract INV
Smart Contract Language Solidity
Protocol Twitter/X @InverseFinance

Attack Timeline

The attacker used approximately 901 ETH to make capital-intensive trades in thin SushiSwap INV markets. Anchor's Keep3r time-weighted price oracle sampled the manipulated market incorrectly, temporarily reporting an INV price near $20,926. The attacker acquired and staked INV while that distorted price was active, so Anchor accepted the position as much more valuable collateral than it was.

They then borrowed 1,588 ETH, 94 WBTC, roughly 4 million DOLA, and 39 YFI before the INV price corrected and the collateral was liquidated. The manipulation used the protocol's trusted price input; Inverse stated it was not a flash-loan exploit.

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.