Rodeo Finance Hack

TOTAL LOST $1.7M
Medium Oracle Manipulation & Price Manipulation

What happened

Rodeo Finance, a Yield Protocol on Arbitrum, was exploited through an oracle issue causing a loss of 1,690,000 $USD.

Rodeo Finance was hit by an exploit resulting in a loss of approximately $880k stolen from the lending pool. Although the total impact was $1.7M, around $810k was recovered. The exploit occurred due to a sandwich attack on one of the oracles meant to be twap for Camelot's Uniswap v2 pools during its price update.

This led to an inflation in the price, which enabled the hacker to borrow from the lending pool and swap all to the said token. The hacker arbitraged the DEX pool back to its normal price. The remaining ~810k left in the Rodeo farm used for the attack was subsequently recovered.

Ethereum:

Attacker Address:

https://etherscan.io/address/0x2f3788f2…ace328

Staking Transaction:

https://etherscan.io/tx/0x114c6561…bc65db

TornadoCash Transfer Transaction:

https://etherscan.io/tx/0xadc1c04b…a2f603

Arbitrum:

Attacker Address:

https://arbiscan.io/address/0x2f3788f2…ace328

Malicious Transactions:

https://arbiscan.io/tx/0xdbcb3082…089ef1

https://arbiscan.io/tx/0xb1be5dee…9fb25a

https://arbiscan.io/tx/0x3942760f…c3de0b

Case & protocol details

Classification Yield Aggregator
Protocol Type Exploit/Oracle Issue
Affected asset / contract RDO
Official Website www.rodeofinance.xyz
Protocol Twitter/X @Rodeo_Finance

Security review history

Bug bounty Rodeo Finance Details

Funds Recovery

47.9%

Recovered

$810K

Net Loss

$880,490

Evidence & learning

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.