Inverse Finance Hack

TOTAL LOST
Flash Loan Attacks Ethereum

What happened

On June 16, 2022, an attacker used a 27,000-WBTC Aave flash loan to manipulate the Curve 3Crypto pool used to value yvCurve-3Crypto collateral in Inverse Finance's Frontier market. The inflated collateral value enabled an oversized DOLA borrow. Inverse later reported a net DOLA loss of $5.83 million, while security analyses traced about $1.26 million of attacker proceeds after the flash loan was repaid.

This was distinct from Inverse's April 2022 INV-oracle incident.

Technical Root Cause

Frontier's YVCrv3CryptoFeed valued Yearn vault collateral from mutable balances in the Curve USDT-WBTC-WETH pool. A single-transaction reserve distortion therefore inflated the collateral price used in the borrowing check.

Case & protocol details

Classification Oracle manipulation
Protocol Type Exploit/Flash Loan Attack
Affected asset / contract INV
Official Website www.inverse.finance/
Protocol Twitter/X @InverseFinance

Attack Timeline

The attacker used part of the flash-borrowed WBTC to create Curve and Yearn collateral, then swapped the remaining WBTC for USDT in the Curve 3Crypto pool. That sharply changed the balances used by the yvCurve-3Crypto oracle. Frontier treated the collateral as worth far more than it was and permitted a 10.13 million DOLA borrow.

The attacker unwound the Curve position, repaid Aave, and retained WBTC and USDT proceeds.

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.