CryptoReal
CASE FILE — Aug 18, 2023

Optimism Lender Exactly Protocol Drained of $7.2M via a Debt Manager Flaw

Exactly Protocol, a lending platform built on Optimism, became the latest in a string of layer-2 exploits this summer after attackers drained roughly $7.2 million in users' collateral on Friday, August 18, 2023.

Peckshield was the first to flag suspicious activity. The Exactly team confirmed shortly after that it was investigating, and roughly two hours later issued a follow-up statement announcing the protocol had been paused as a precaution:

We're actively investigating a security issue within our protocol. To ensure user safety, the protocol is temporarily paused (you can still withdraw assets). Our team is on top of this and will share more details asap.

Beyond the direct losses, the exploit triggered a broader outflow from the protocol. DeFiLlama data showed total value locked falling from $37 million before the incident to $26 million immediately after, and continuing to decline afterward — likely as remaining users withdrew what they could — dropping to under $11 million by the time of reporting. The protocol's EXA token also fell close to 35% following the hack.

How the exploit worked

Per an analysis credited to BlockSec, the root cause was an insufficient validation check within the DebtManager contract (proxy at 0x675d410dcf6f343219AAe8d1DDE0BFAB46f52106, implementation at 0x16748Cb753A68329cA2117a7647aA590317EbF41) that failed to properly confirm whether a supplied market address was legitimate.

Sums referenced in this case file

This gap let the attacker submit a spoofed market address while substituting a victim's address as _msgSender, effectively allowing the attacker to siphon off that victim's collateral.

Three addresses have been linked to the exploiter: 0x3747dbbcb5c07786a4c59883e473a2e38f571af9, 0xe4f34a72d7c18b6f666d6ca53fbc3790bc9da042, and 0x417179df13ba3ed138b0a58eaa0c3813430a20e0. The attack contract itself is deployed at 0x6dd61c69415c8ecab3fefd80d079435ead1a5b4d, with an example malicious transaction recorded at 0x3d6367de5c191204b44b8a5cf975f257472087a9aadc59b5d744ffdef33a520e.

Investigators traced the attacker's initial funding to Tornado Cash on Ethereum (via transaction 0x97618de89d43593dda51585a07972a1267d11433e387f89bfc2831ce120c2f86), with funds subsequently bridged over to Optimism to carry out the exploit.

Where the funds went

Of the total haul — 4,324 ETH, worth approximately $7.2 million — 1,500 ETH (around $2.5 million) has since been bridged back to Ethereum, where it currently remains. BlockSec published a chart tracing this fund flow in detail.

Audits didn't catch it

Exactly Protocol had reportedly undergone audits from four separate security firms, though none of those reviews took place after the DebtManager contract's code was published to GitHub — meaning the vulnerable version had gone unreviewed.

This episode reinforces a familiar lesson: security audits reduce risk but don't eliminate it, and should be treated as one component of a broader, ongoing security practice rather than a guarantee of safety. Meanwhile, tension persists in the industry between security researchers who report vulnerabilities and projects reluctant to pay adequate bug bounties — a dynamic that keeps generating headlines for incident trackers like rekt.news's running leaderboard of major exploits.

Exactly ProtocolOptimism
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.