UwU Lend Hack
What happened
On June 10, 2024, UwU Lend lost about $20 million after an attacker manipulated the protocol's sUSDe pricing inputs with flash-loaned liquidity. The Ethereum lending market used a custom median oracle whose Curve spot-price inputs could be moved within one transaction.
UwU's custom sUSDe oracle included five instantaneous Curve AMM spot prices among its 11 median inputs. Those prices were manipulable within one transaction, so an attacker could move enough inputs to distort the median despite the remaining EMA and TWAP sources. This false price then corrupted lending health-factor and liquidation calculations.
Case & protocol details
Attack Timeline
Flash loans moved Curve pool spot prices that fed UwU's 11-source median oracle. The attacker used the false valuation to cycle collateral and debt across self-controlled positions, then liquidated an unhealthy position at a favorable price and withdrew or borrowed assets before repaying the flash loans. The oracle returned to normal after the transaction, but the protocol had already released collateral.
Evidence & learning
Sources and on-chain records
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.