Sturdy V1 Hack
What happened
Sturdy Finance, an Ethereum-based lending platform, fell victim to an oracle manipulation exploit, losing 775,332 $USD.
Sturdy Finance was exploited through an oracle price manipulation attack. In a read-only reentrancy attack, the perpetrator managed to exploit the SturdyOracle contract and manipulate its pricing. They executed a single withdrawal transaction from the 'Sturdy_eth interest bearing WETH' contract.
The total funds lost due to the exploit amounted to 880,850 $USD. However, the attacker's profit was 442 $ETH, equating to around 775,332 $USD, while the remaining funds served as the flashloan commission. The illicitly gained profits were later moved through TornadoCash in multiple transactions.
Attacker Address:
https://etherscan.io/address/0x1E8419E7…31a08B
Malicious Contract:
https://etherscan.io/address/0x0B09c862…dFbeab
Malicious Transaction:
https://etherscan.io/tx/0xeb87ebc0…fb9eb7
Example of Funds Transfer Transaction:
https://etherscan.io/tx/0x1702e647…2ee1a7
Case & protocol details
Evidence & learning
Attack pattern
Compare incidents →Proof of concept
1 availableSources and on-chain records
- report Post-Mortem sturdyfinance.medium.com
- report Report twitter.com
- analysis Twitter/X Alert twitter.com
- analysis Twitter/X Alert twitter.com
- analysis Website reference twitter.com
- analysis Website reference twitter.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.