Rhea Finance Hack
What happened
On April 16, 2026, RHEA Finance on NEAR lost $18.4M when an attacker exploited a slippage protection flaw in the margin trading feature.
RHEA's margin trading had a critical flaw in its slippage protection. The system added up all expected minimum outputs across multiple swaps but didn't check when one swap's output became the next swap's input. This allowed attackers to chain swaps that looked valid but actually bypassed all protections.
The attacker spent three days preparing. They set up 423 intermediary accounts and funded them through NEAR Intents. On April 15, they created 8 fake token pools on Ref Finance, pairing worthless tokens with real assets like USDC and USDT at artificial prices. They built a custom swap router connecting these pools.
On April 16 from 08:22-09:42 UTC, they executed the main attack. They opened margin positions on RHEA using their rigged swap routes. Borrowed debt tokens got funneled into the fake pools while almost nothing came back to the protocol. Each position had massive debt but worthless collateral, triggering instant forced liquidations that drained RHEA's reserves. The attacker then pulled all liquidity from their fake pools and extracted the stolen value.
The attacker has since returned 3.359M USDC and 1.564M NEAR. Tether froze 4.34M USDT. The protocol froze the lending contract to preserve remaining funds.
Example Attack Transaction: 44tWhQmmkTJgchgFVkYpPrgyKvaH7wRLu1jZWXD3Du1x
Case & protocol details
Evidence & learning
Sources and on-chain records
- report Report x.com
- report Report x.com
- report The Block: Rhea post-mortem reporting theblock.co
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.