Deus DAO (DEI lending contract): Flash loan oracle manipulation via Solidly AMM pool → user position liquidation
Deus DAO's freshly launched DEI lending contract lost ~$3M when an attacker flash-loaned from the same pool used as its price oracle, manipulated collateral valuations, and liquidated real users' positions for profit.
Summary #
Deus DAO (DEI lending contract) suffered a Algorithmic Stablecoin / Lending on 2022-03-15, resulting in a loss of approximately $3M.
What happened #
Deus DAO's freshly launched DEI lending contract lost ~$3M when an attacker flash-loaned from the same pool used as its price oracle, manipulated collateral valuations, and liquidated real users' positions for profit.
Linked factors #
- RD-F-004 — causal : Audit count likely 0; floor display [via dashboard_risk_factors/Vulnerability in audited or unaudited code: Unaudited newly deployed contract]
- RD-F-006 — causal : Audit-deploy gap — alternate field name [via dashboard_risk_factors/Code newly deployed/upgraded?: Yes — newly launched DEI lending contract]
- RD-F-007 — related : Bug bounty absent — baseline integrity gap [via dashboard_risk_factors/Bug bounty: None identified]
- RD-F-099 — illustrative : Oracle price deviation > X% from secondary source — RT signal would have fired [via realtime_signals/Oracle anomaly (Y/N): Y — oracle price manipulated during the flash loan; detectable as a price spike/crash]
- RD-F-100 — illustrative : Flash loan > $10M origination — RT signal [via realtime_signals/Unusual borrowing (Y/N): Y — 24.7M DEI flash loaned from oracle pool]