Sturdy V1 Hack

TOTAL LOST $775K
Low Flash Loan Attacks ethereum

What happened

Sturdy Finance, an Ethereum-based lending platform, fell victim to an oracle manipulation exploit, losing 775,332 $USD.

Sturdy Finance was exploited through an oracle price manipulation attack. In a read-only reentrancy attack, the perpetrator managed to exploit the SturdyOracle contract and manipulate its pricing. They executed a single withdrawal transaction from the 'Sturdy_eth interest bearing WETH' contract.

The total funds lost due to the exploit amounted to 880,850 $USD. However, the attacker's profit was 442 $ETH, equating to around 775,332 $USD, while the remaining funds served as the flashloan commission. The illicitly gained profits were later moved through TornadoCash in multiple transactions.

Attacker Address:

https://etherscan.io/address/0x1E8419E7…31a08B

Malicious Contract:

https://etherscan.io/address/0x0B09c862…dFbeab

Malicious Transaction:

https://etherscan.io/tx/0xeb87ebc0…fb9eb7

Example of Funds Transfer Transaction:

https://etherscan.io/tx/0x1702e647…2ee1a7

Case & protocol details

Classification Ecosystem / Reentrancy / Borrowing and Lending
Protocol Type Lending
Affected asset / contract STRDY
Smart Contract Language Solidity
Official Website sturdy.finance/
Protocol Twitter/X @SturdyFinance

Security review history

Bug bounty Immunefi Details

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.