defirisk.co
rubric v1.7.0

Deus DAO (DEI lending contract): Flash loan oracle manipulation via Solidly AMM pool → user position liquidation

Deus DAO's freshly launched DEI lending contract lost ~$3M when an attacker flash-loaned from the same pool used as its price oracle, manipulated collateral valuations, and liquidated real users' positions for profit.

Occurred 2022-03-15 Loss $3M Status closed

Summary #

Deus DAO (DEI lending contract) suffered a Algorithmic Stablecoin / Lending on 2022-03-15, resulting in a loss of approximately $3M.

What happened #

Deus DAO's freshly launched DEI lending contract lost ~$3M when an attacker flash-loaned from the same pool used as its price oracle, manipulated collateral valuations, and liquidated real users' positions for profit.

Linked factors #

  • RD-F-004 — causal : Audit count likely 0; floor display [via dashboard_risk_factors/Vulnerability in audited or unaudited code: Unaudited newly deployed contract]
  • RD-F-006 — causal : Audit-deploy gap — alternate field name [via dashboard_risk_factors/Code newly deployed/upgraded?: Yes — newly launched DEI lending contract]
  • RD-F-007 — related : Bug bounty absent — baseline integrity gap [via dashboard_risk_factors/Bug bounty: None identified]
  • RD-F-099 — illustrative : Oracle price deviation > X% from secondary source — RT signal would have fired [via realtime_signals/Oracle anomaly (Y/N): Y — oracle price manipulated during the flash loan; detectable as a price spike/crash]
  • RD-F-100 — illustrative : Flash loan > $10M origination — RT signal [via realtime_signals/Unusual borrowing (Y/N): Y — 24.7M DEI flash loaned from oracle pool]