Shoebill Finance Hack

Reported loss $1.5M
Bob
Oracle Misconfiguration

What happened

On October 31, 2024, an attacker drained the BTC market of Shoebill Finance, a lending protocol, on the BOB chain. Shoebill said the flaw came from an unexpected interaction in its oracle configuration while it was adding solvBTC and solvBTC.BBN as new assets, which let the attacker borrow against very little collateral. The attacker took 19.512 wBTC and 1.597 tBTC, about 21.1 BTC or roughly $1.5 million.

The attacker bridged the funds from BOB to Ethereum through Meson, Orbiter and Across, swapped them to ETH, split them across wallets and moved them to Bitcoin addresses through eXch, Chainflip, Symbiosis and THORChain. Shoebill paused the market, fixed the oracle configuration, said its other markets were unaffected, brought in Cryptoforensic and AMLBot to trace the funds and reported the theft to law enforcement. In December 2024 it opened partial compensation: 2.1 BTC from its treasury, shared pro rata among 1,518 eligible users who had lost a combined 20.27 BTC.

How it happened

  1. Shoebill integrated solvBTC and solvBTC.BBN into its BTC market on BOB, and the oracle configuration for this setup contained an exploitable interaction that Shoebill has not detailed publicly.
  2. In a multi-stage exploit, the attacker used this condition to borrow from the BTC market contracts with only a small amount of collateral.
  3. The primary transaction 0xa6e181ea893bfbe2427fd9bca31e1f106d9913882b9f6b0776299e0f456b3c92 moved out 19.51 wBTC and 1.597 tBTC.
  4. The attacker bridged the funds to Ethereum, converted them to ETH and cashed out to Bitcoin addresses through cross-chain swap services.

Protocol details

Classification Oracle Manipulation
Protocol Type DeFi Protocol
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.