Synthetix Hack

Reported loss Not disclosed
Ethereum
Oracle Misconfiguration

What happened

On 24 June 2019 (3am on 25 June, Sydney time), Synthetix's oracle reported a wrong price for the Korean won. One of the commercial APIs behind the FX price feed began to intermittently return a KRW rate about 1000x too high. The oracle was built to discard outliers, but an earlier outage that nobody had caught meant only two APIs were serving KRW at the time. The oracle averaged those two prices and pushed the bad KRW rate on-chain to the exchange-rates contract.

A trading bot on Synthetix.Exchange spotted the error. It traded into and out of sKRW while the price was wrong, making several trades at about 1000x profit. Synthetix put the gain at over $1 billion within an hour, and news reports put it at more than 37 million sETH. After the community alerted the team, the CTO stopped the oracle from sending rates to the contracts, which halted all transfers and trading. The bot's owner agreed to reverse the trades in exchange for a bug bounty of undisclosed size, and trading resumed. Synthetix said it had added redundancy and better exception handling to its price feeds, and named Chainlink as a partner for a more decentralised oracle.

How it happened

  1. An earlier unrelated outage left only two APIs serving the KRW price. Synthetix's exception reporting did not catch this.
  2. One of the two APIs began to intermittently report KRW about 1000x above the real rate. With only two inputs, the outlier filter could not discard it, and the averaged bad price was written to the exchange-rates contract.
  3. A trading bot saw the mispricing and repeatedly converted into and out of sKRW, ending up with a very large balance, reported as more than 37 million sETH.
  4. Synthetix stopped oracle updates, which froze all transfers and trading. The bot owner then agreed to unwind the trades for a bug bounty.

Protocol details

Classification Oracle Manipulation
Protocol Type DeFi Protocol
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.