CryptoReal
CASE FILE — Feb 3, 2023

Oracle Manipulation on Polygon Nets BonqDAO Attacker Under $2M From a $120M Paper Loss

BonqDAO suffered a headline loss of $120 million, but the attacker walked away with a fraction of that — under $2 million in realized value.

The Polygon-based lending and stablecoin protocol was hit on a Wednesday by a two-part exploit that added another entry to the long list of oracle-manipulation incidents in DeFi.

News of the attack surfaced on Twitter through @spreekaway, who tracked the stolen funds being sold off in real time as the transactions happened. BonqDAO and AllianceBlock — whose ALBT token was central to the exploit — both confirmed the breach within hours of the initial reports.

Even though the entire attack was traceable on-chain in real time, BonqDAO's Telegram moderators initially tried to minimize the situation while the team assessed the damage, posting that "FUD and spam will not be tolerated."

The irony wasn't lost on observers: instant, unverified price feeds for collateral valuation are arguably the thing that shouldn't have been tolerated.

Credit for the analysis goes to Peckshield and Beosin.

Attacker's address: 0xcacf2d28b2a5309e099f0c6e8c60ec3ddf656642

Example attack transaction: 0x31957ecc43774d19f54d9968e95c69c882468b46860f921668f2c55fadd51b19

Attacked smart contract: 0x8f55d884cad66b79e1a131f6bcb0e66f4fd84d5b

Sums referenced in this case file

Samczsun distilled the mechanism into a single line: the attacker essentially declared that 1 ALBT was now worth 5 billion MATIC, and the protocol simply accepted it.

The root cause was BonqDAO's use of the Tellor oracle for pricing its wrapped WALBT collateral. The attacker staked just 10 TRB tokens — worth roughly $175 — which was enough to gain the ability to manually push a price update to the feed. Because BonqDAO's contracts trusted that submitted value instantly, the attacker was able to borrow against the artificially inflated collateral within the very same transaction used to set the price.

The exploit unfolded in two moves. First, the reported ALBT price was pushed upward, letting the attacker mint 100 million BEUR — Bonq's euro-pegged stablecoin — against just 0.1 WALBT in posted collateral. Then, in a separate follow-up transaction, the WALBT price was slammed down to a near-zero value, which put every other user's WALBT-backed position into liquidation range. The attacker then liquidated that collateral cheaply, collecting roughly 113 million WALBT in the process.

Beosin published a detailed transaction-by-transaction breakdown: the attacker first called the depositStake function on the TellorFlex contract, staking exactly 10 TRB (10¹⁸ in raw decimals) — matching the contract's required takeAmount precisely. That stake unlocked the ability to call submitValue, through which the attacker submitted a new WALBT price of 50,000,000,000,000,000,000,000,000,000,000. With that price now recorded, the attacker called Bonq's createTrove function to open a trove contract (address 0x4248FD) used for recording debt, borrowing, and liquidation. Staking just 0.1 WALBT against this inflated price allowed a borrow of 100 million BEUR — far beyond what should have been possible under a safe collateralization ratio, since the trove's valuation logic pulled directly from the now-manipulated TellorFlex price. In the second transaction, the attacker pushed the WALBT price back down to a negligible level, which put other users' WALBT stakes into liquidation territory; the attacker then liquidated those positions at minimal cost, netting close to 114 million WALBT in total.

Using token prices at the moment of the attack, total losses have been widely cited at up to $120 million. In practice, thin liquidity meant the attacker could only convert the haul into roughly $1.7 million worth of ETH and DAI by the time of reporting. BonqDAO's own TVL reflected the damage starkly, falling from around $13 million the day before to just over $100,000 at time of writing.

The stolen BEUR was sold off on Polygon for just over $500,000. Proceeds were routed to the attacker's Ethereum address, where the ALBT holdings were gradually converted into ETH. At last check, that address held 711 ETH (roughly $1.2 million), 535,000 DAI, and 89 million ALBT — the latter theoretically worth around $3 million, contingent on the attacker finding a buyer.

BlockSec published a full flow-of-funds diagram tracing the movement. The attacker's Ethereum address had been funded via Tornado Cash shortly before the attack began, and the stolen proceeds have since been sent back into the mixer.

An earlier audit from Omniscia had already flagged "multiple vulnerabilities as well as core design flaws" in BonqDAO's codebase. According to Omniscia's post-mortem, BonqDAO ultimately chose not to deploy the implementation that had been audited, opting instead to move toward Chainlink oracles going forward. In the interim, the protocol shipped numerous updates — including the ConvertedPriceFeed, ChainlinkPriceFeed, and TellorPriceFeed contracts implicated in this exploit — none of which had ever actually been covered by Omniscia's original audit scope, making them effectively unaudited code in production.

While the underlying vulnerability sat with BonqDAO, AllianceBlock absorbed substantial collateral damage from the fallout. The forced liquidation and dumping of ALBT drove its price down by as much as 75% in the aftermath. AllianceBlock has since said it will reissue the ALBT token and airdrop replacements to holders based on a snapshot taken before the incident.

Bonq's own euro stablecoin, BEUR, slipped to roughly 25% below its intended peg, while BNQ, the protocol's governance token, dropped more than 30% in value.

AllianceBlock may not have been responsible for the technical flaw that caused the loss, but the episode raises fair questions about the due diligence applied before integrating a partner protocol — a discipline that sits outside DeFi's usual focus but matters just as much. If the project's stated goal is to "seamlessly bring DeFi and TradFi together," this incident suggests it could stand to borrow more of TradFi's risk-vetting habits. For Bonq itself, the damage to trust may already be done.

AllianceBlockBonqDAO
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.