TenderFi Hack

TOTAL LOST $1.6M
Medium Oracle Manipulation & Price Manipulation

What happened

TenderFi was exploited by a WhiteHat hacker via the Oracle issue. The hacker was able to borrow 1,583,432 $USD worth of assets and returned almost the full amount.

TenderFi is a Lending and Borrowing protocol running on the layer-2 Arbitrum chain. The protocol was exploited via Oracle issue, which allowed the hacker to take 1,583,432 $USD worth of assets for 1 $GMX (~70 $USD). The project's Unitroller contract has oracle misconfiguration, which allowed malicious actions on DistributedBorrowerComp() function.

The WhiteHat hacker left an on-chain message, to contact him to return the funds. Within 24 hours after the incident, the TenderFi Team was able to recover the funds, while paying the Bug Bounty for 62.15 $ETH. The received funds were transferred to another EOA address.

The TenderFi Team claimed they will compensate the remaining funds, so the protocol's users will not be affected and there will be no bad debt.

Attacker address:

https://arbiscan.io/address/0x896df375…feb1ab

Malicious transaction example:

https://arbiscan.io/tx/0x0a637e32…ba4c4a

Recovering transaction example:

https://arbiscan.io/tx/0x0281ff6e…806bd1

Attacker's on-chain message:

https://arbiscan.io/tx/0x38ae6073…13ab9c

Recovering message from the TenderFi:

https://arbiscan.io/tx/0xdeb31360…6e0b72

Address holding the Bug Bounty:

https://arbiscan.io/address/0xd724a36b…203769

Case & protocol details

Classification Borrowing and Lending
Protocol Type Exploit/Oracle Issue
Affected asset / contract TND
Official Website www.tender.fi/
Protocol Twitter/X @tender_fi

Security review history

Bug bounty Immunefi Details

Funds Recovery

93.9%

Recovered

$1.5M

Net Loss

$96,589

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.