UwU Lend Hack

TOTAL LOST $3.7M
Medium Flash Loan Attacks Ethereum

What happened

On June 13, 2024, UwU Lend lost about $3.7 million in a second exploit days after a larger June 10 attack. The attacker used collateral derived from the first exploit that the protocol still recognized as valid to borrow from and drain additional markets.

Technical Root Cause

Incomplete incident remediation and invalid-collateral handling. Fixing the initial oracle path did not neutralize attacker-held collateral or revalue it as compromised before re-enabling borrowing.

Case & protocol details

Classification Collateral validation failure after an oracle-manipulation incident
Protocol Type Lending
Smart Contract Language Solidity
Official Website uwulend.fi/
Protocol Twitter/X @uwu_lend?lang=en

Attack Timeline

UwU resumed operation after fixing the first sUSDe oracle issue, but the attacker still held a large balance derived from that attack. That balance remained acceptable collateral. The attacker used it to borrow assets from additional UwU pools, swapped the proceeds to ETH, and left the protocol with the loss.

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.