Sharwa.Finance Hack

TOTAL LOST $147K
Low Oracle Manipulation & Price Manipulation arbitrum

What happened

On October 20, 2025, Sharwa Finance, a lending protocol on Arbitrum, was exploited for approximately $147,000 through a price manipulation attack targeting USDC and WBTC liquidity pools. The Tornado Cash-funded attacker executed an atomic sandwich attack exploiting the protocol's reliance on Uniswap V3 quoter prices, with Sharwa committing to 100% refunds for affected users.

Sharwa Finance is a lending protocol allowing users to open long/short positions on BTC and ETH. The vulnerability stemmed from the protocol's blind trust in Uniswap V3 quoter prices without proper safeguards when closing positions. The attacker executed a two-transaction atomic sandwich attack: In transaction 1, they created a margin account with a BTC long position by depositing 2,000 USDC and borrowing approximately 40,000 USDC to purchase BTC.

In transaction 2, they performed the price manipulation sandwich by first swapping a large amount of BTC to USDC to crash the price, then immediately closing the long position which forced the protocol to sell BTC at the manipulated unfavorable price (creating bad debt), and finally swapping USDC back to BTC to complete the profitable sandwich. The attacker was funded through Tornado Cash and bridged funds from Ethereum mainnet to Arbitrum before executing the exploit.

Exploit Transaction 1:

0x9f8b4841…c23ead

Exploit Transaction 2:

0x35a523bd…addd36

Technical Root Cause

40,000 USDT were recovered with a help of Binance

Case & protocol details

Classification Protocol Logic / Borrowing and Lending
Protocol Type Derivatives
Smart Contract Language Solidity
Official Website sharwa.finance/
Protocol Twitter/X @SharwaFinance

Security review history

Funds Recovery

27.2%

Recovered

$40K

Net Loss

$107,016

Evidence & learning

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.