UwU Lend Hack

TOTAL LOST $20.0M
High Flash Loan Attacks Ethereum

What happened

On June 10, 2024, UwU Lend lost about $20 million after an attacker manipulated the protocol's sUSDe pricing inputs with flash-loaned liquidity. The Ethereum lending market used a custom median oracle whose Curve spot-price inputs could be moved within one transaction.

Technical Root Cause

UwU's custom sUSDe oracle included five instantaneous Curve AMM spot prices among its 11 median inputs. Those prices were manipulable within one transaction, so an attacker could move enough inputs to distort the median despite the remaining EMA and TWAP sources. This false price then corrupted lending health-factor and liquidation calculations.

Case & protocol details

Classification Ecosystem / Oracle Manipulation
Protocol Type Lending
Smart Contract Language Solidity
Official Website www.uwulend.fi/
Protocol Twitter/X @UwU_Lend

Attack Timeline

Flash loans moved Curve pool spot prices that fed UwU's 11-source median oracle. The attacker used the false valuation to cycle collateral and debt across self-controlled positions, then liquidated an unhealthy position at a favorable price and withdrew or borrowed assets before repaying the flash loans. The oracle returned to normal after the transaction, but the protocol had already released collateral.

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.