Lodestar V0 Hack

TOTAL LOST $6.9M
Medium Flash Loan Attacks arbitrum

What happened

Lodestar protocol was exploited via price feed oracle vulnerability. plvGLP price was manipulated which led to the protocol liquidity draining.

Lodestar Finance is a borrowing and lending protocol, based on the Compound fork, initially built and launched on the Arbitrum network. Lodestar aims to bring the critical DeFi primitive of decentralized money markets to Arbitrum communities. The protocol was exploited by manipulating the plvGLP oracle price using flashloans to create a large plvGLP collateral position.

The attacker increased the plvGLP/GLP rate and created the ability to change the price immediately, which was then compounded through the loops and led to significant borrowing ability. The main vulnerability that allowed such exploit flow was in GLPOracle price logic.

Attacker contract:

https://arbiscan.io/address/0x7596ACad…C53508

Attacker  address:

https://arbiscan.io/address/0xc29d9438…9e2b5c

Exploit TX:

https://arbiscan.io/tx/0xc523c630…004e8c

Case & protocol details

Classification Ecosystem / Oracle Manipulation / Borrowing and Lending
Protocol Type Lending
Affected asset / contract LODE
Smart Contract Language Solidity
Official Website www.lodestarfinance.io/
Protocol Twitter/X @LodestarFinance

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.