Lodestar V0 Hack
What happened
Lodestar protocol was exploited via price feed oracle vulnerability. plvGLP price was manipulated which led to the protocol liquidity draining.
Lodestar Finance is a borrowing and lending protocol, based on the Compound fork, initially built and launched on the Arbitrum network. Lodestar aims to bring the critical DeFi primitive of decentralized money markets to Arbitrum communities. The protocol was exploited by manipulating the plvGLP oracle price using flashloans to create a large plvGLP collateral position.
The attacker increased the plvGLP/GLP rate and created the ability to change the price immediately, which was then compounded through the loops and led to significant borrowing ability. The main vulnerability that allowed such exploit flow was in GLPOracle price logic.
Attacker contract:
https://arbiscan.io/address/0x7596ACad…C53508
Attacker address:
https://arbiscan.io/address/0xc29d9438…9e2b5c
Exploit TX:
https://arbiscan.io/tx/0xc523c630…004e8c
Case & protocol details
Evidence & learning
Proof of concept
1 availableSources and on-chain records
- report Report twitter.com
- analysis Twitter/X Alert twitter.com
- analysis Blog reference blog.lodestarfinance.io
- analysis Website reference twitter.com
- analysis Website reference twitter.com
- analysis Website reference twitter.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.