Shoebill Finance Hack
What happened
On October 31, 2024, an attacker drained the BTC market of Shoebill Finance, a lending protocol, on the BOB chain. Shoebill said the flaw came from an unexpected interaction in its oracle configuration while it was adding solvBTC and solvBTC.BBN as new assets, which let the attacker borrow against very little collateral. The attacker took 19.512 wBTC and 1.597 tBTC, about 21.1 BTC or roughly $1.5 million.
The attacker bridged the funds from BOB to Ethereum through Meson, Orbiter and Across, swapped them to ETH, split them across wallets and moved them to Bitcoin addresses through eXch, Chainflip, Symbiosis and THORChain. Shoebill paused the market, fixed the oracle configuration, said its other markets were unaffected, brought in Cryptoforensic and AMLBot to trace the funds and reported the theft to law enforcement. In December 2024 it opened partial compensation: 2.1 BTC from its treasury, shared pro rata among 1,518 eligible users who had lost a combined 20.27 BTC.
How it happened
- Shoebill integrated solvBTC and solvBTC.BBN into its BTC market on BOB, and the oracle configuration for this setup contained an exploitable interaction that Shoebill has not detailed publicly.
- In a multi-stage exploit, the attacker used this condition to borrow from the BTC market contracts with only a small amount of collateral.
- The primary transaction
0xa6e181ea893bfbe2427fd9bca31e1f106d9913882b9f6b0776299e0f456b3c92moved out 19.51 wBTC and 1.597 tBTC. - The attacker bridged the funds to Ethereum, converted them to ETH and cashed out to Bitcoin addresses through cross-chain swap services.
Protocol details
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.