Conic Finance DeFi protocol loses $3,2 million in an attack
The attacker conducted a flash loan attack by exploiting vulnerabilities in the protocol.
21.07.2023 - 15:30
2088
2 min
0
DeFi protocol Conic Finance suffered an exploit today by a hacker who managed to make off with 1700 ether (over $3.2 million), according to security analysts at BlockSec. Conic is a DeFi protocol designed to allocate funds across the Curve decentralized exchange using the liquidity pools it operates.
The unidentified attacker exploited a reentrancy vulnerability, which subsequently allowed the manipulation of a faulty price oracle that Conic relied on. This enabled them to drain funds, said Matthew Jiang, the director of security services at BlockSec, in an interview with The Block.
Such an attack leverages the ability to repeatedly call a function within a single transaction before the initial function call completes. This mechanism lets the attacker withdraw more funds than they’re entitled to.
In the incident around 6:35 am ET today, the hacker executed a flash loan, borrowing 20,000 staked ether, as evidenced by on-chain data. These funds were routed to Conic so its price oracle, which is sourced from a third-party “read-only” smart contract, could be tampered with — facilitating the reentrancy attack — BlockSec explained. “The flash-loaned stETH was utilized to amplify the profit,” Jiang said.
Keeping its community informed, Conic announced in a Twitter post that the team was “investigating an exploit involving the ETH Omnipool” and promised to share further updates.
After what appears to be a second attack, Curve Finance urged users to remove all funds from Conic Finance Friday afternoon. Conic later shut down all deposits across omnipools.
"Users are still able to withdraw," Conic Finance wrote on Twitter. "We are assessing the situation and will provide updates as soon as we have them."
This material is taken from the website https://www.theblock.co.
Useful material?
Incidents
Developers warned of potential risks to bridges across the ecosystem and asked exchanges for assistance.
Jun 22, 2026
Incidents
The defendant helped move funds stolen through investment scams and earned at least $4 million for his role in the operation.
Jun 10, 2026
Incidents
The company is linking the incident to a compromised private key on a service wallet, rather than a smart contract exploit
May 22, 2026
Incidents
Following the incident, the project temporarily halted trading operations and node activity.
May 15, 2026
Incidents
The user spent weeks unsuccessfully trying to guess the password until Claude helped find an old wallet backup file
May 14, 2026
Crypto regulations
Authorities are introducing mandatory registration for companies handling cross-border crypto transactions
May 8, 2026
Telegram
Twitter