Zerogoki Hack

TOTAL LOST $670K
Low Oracle Manipulation & Price Manipulation ethereum

What happened

Zerogoki was attacked by way of compromising the price oracle. The attacker provided a price oracle signed by legitimate private keys, which contained a crafted number of tokens to be swapped. However, the reason why the attacker could construct a valid signature is unknown.

The attacker's address:

https://etherscan.io/address/0xaef46df5…30680d

The transaction behind the attack:

https://etherscan.io/tx/0x81e5f715…21acf8

In the attack transaction, the attacker constructed a message that contained valid signatures and passed a crafted ns parameter (which contains a large number of zUSD). As a result, the attacker used 300 REI to swap 700k zUSD.

Three addresses that are collated with the signatures are:

0x0d93A21b…76261C

0x3054e197…67aa4a

0x4448993f…77dfd2

Case & protocol details

Classification Other / Oracle Manipulation
Protocol Type Exploit/Other
Affected asset / contract REI
Smart Contract Language Solidity
Official Website zerogoki.org/
Protocol Twitter/X @0Zerogoki

Evidence & learning

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.