UwU Lend Hack
What happened
On June 13, 2024, UwU Lend lost about $3.7 million in a second exploit days after a larger June 10 attack. The attacker used collateral derived from the first exploit that the protocol still recognized as valid to borrow from and drain additional markets.
Incomplete incident remediation and invalid-collateral handling. Fixing the initial oracle path did not neutralize attacker-held collateral or revalue it as compromised before re-enabling borrowing.
Case & protocol details
Attack Timeline
UwU resumed operation after fixing the first sUSDe oracle issue, but the attacker still held a large balance derived from that attack. That balance remained acceptable collateral. The attacker used it to borrow assets from additional UwU pools, swapped the proceeds to ETH, and left the protocol with the loss.
Evidence & learning
Sources and on-chain records
- report Report x.com
- transaction Transaction etherscan.io
- transaction Transaction etherscan.io
- analysis Website reference x.com
- analysis Website reference theblock.co
- analysis UwU Lend Hacker Steals Another $3.7 Million unchainedcrypto.com
- analysis UwU Lend Drained in Second Exploit theblock.co
- analysis UwU Hacked: Cause by Price Oracle blog.verichains.io
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.