Inverse Finance Hack
What happened
On June 16, 2022, an attacker used a 27,000-WBTC Aave flash loan to manipulate the Curve 3Crypto pool used to value yvCurve-3Crypto collateral in Inverse Finance's Frontier market. The inflated collateral value enabled an oversized DOLA borrow. Inverse later reported a net DOLA loss of $5.83 million, while security analyses traced about $1.26 million of attacker proceeds after the flash loan was repaid.
This was distinct from Inverse's April 2022 INV-oracle incident.
Frontier's YVCrv3CryptoFeed valued Yearn vault collateral from mutable balances in the Curve USDT-WBTC-WETH pool. A single-transaction reserve distortion therefore inflated the collateral price used in the borrowing check.
Case & protocol details
Attack Timeline
The attacker used part of the flash-borrowed WBTC to create Curve and Yearn collateral, then swapped the remaining WBTC for USDT in the Curve 3Crypto pool. That sharply changed the balances used by the yvCurve-3Crypto oracle. Frontier treated the collateral as worth far more than it was and permitted a 10.13 million DOLA borrow.
The attacker unwound the Curve position, repaid Aave, and retained WBTC and USDT proceeds.
Evidence & learning
Sources and on-chain records
- report Post-mortem rekt.news
- report Report certik.com
- report Report hacken.io
- report Report cryptopotato.com
- transaction Transaction etherscan.io
- analysis Inverse Finance: Reopen Frontier forum.inverse.finance
- analysis CertiK: Inverse Finance Incident Analysis certik.com
- analysis BlockSec: Inverse Finance Price Manipulation Attack blocksec.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.