CryptoReal
CASE FILE — Dec 13, 2024

Manual Price Updates Cost Alpaca Finance Lenders Millions After Thena's Binance Debut

Relying on hand-updated price feeds in DeFi lending is a precarious strategy, and Alpaca Finance's approach to pricing has now produced millions of dollars in disputed losses. The protocol's so-called oracle reportedly amounted to manual CoinGecko checks performed roughly every 30 minutes, a cadence that proved unable to keep up with a fast-moving market.

Users had already flagged concerns about this setup, but rather than address them, Alpaca's team reportedly banned people who questioned the practice.

The breaking point came when Thena's THE token listed on Binance and its price moved sharply, climbing from $0.26 to more than $4. Alpaca's outdated pricing mechanism couldn't keep pace, and the market unraveled quickly.

Alpaca Guard eventually paused the affected market, but by then traders who spotted the lag had already extracted value from the protocol's under-collateralized positions during the gap between the Binance listing and the oracle catching up.

Instead of accepting responsibility for the outdated infrastructure, Alpaca put forward a compensation plan of $50,000 — funds recovered from its liquidation bot's activity during the event. For a protocol that has at times held hundreds of millions of dollars in user deposits, depending on manually updated prices looks less like an oversight and more like a fundamental operational failure.

(Credit for reporting and commentary: 0xlaw, Alpaca Finance, cryptohamm, Binance.)

Oracles are a familiar scapegoat in DeFi — usually blamed when price manipulation or flash-loan exploits go wrong. This incident raises a different question: what happens when there effectively isn't a real oracle to blame?

The term "oracle" is doing a lot of work here. In Alpaca's case, it apparently meant checking whatever CoinGecko displayed and updating the system manually whenever staff got around to it. Their pricing methodology reportedly involved checking CoinGecko roughly every 30 minutes and entering values by hand.

Alpaca has argued that no oracle design could have instantly captured a fivefold price jump triggered by a fresh Binance listing — a fair point on its own. But it sits awkwardly alongside the protocol's claim of 23 completed security audits, including one specifically covering its oracle module.

Sums referenced in this case file

When users pressed the team on Twitter about the manual process, the response only reinforced the concern. One reply asked "Which faster oracle would you have used?" — seemingly overlooking that TWAPs, Chainlink, and other on-chain price feed mechanisms have existed for years.

That response stood in contrast to Alpaca's own documentation, which describes a more sophisticated setup built on Chainlink integration with multiple cross-checked price feeds. Users and security-minded commenters who tried to raise the alarm beforehand say they were banned from Alpaca's Discord server rather than heard out.

Once THE listed on Binance and its price surged, Alpaca's manually maintained feed remained frozen at stale values for up to 30 minutes at a time. During that window, one user withdrew 304,814 THE tokens — worth roughly $752,000 post-listing — having deposited only about $144,000 worth of collateral beforehand.

As of publication, roughly 1.48 million THE tokens remain locked in the protocol, valued at approximately $2.67 million, though that figure has fluctuated significantly since the incident.

Alpaca's official estimate puts the damage at $116,000. User-reported figures paint a different picture, with claims of more than $2.8 million lost overall, including one wallet down roughly $1 million on its own. That same wallet still holds 444,000 THE tokens stuck in Alpaca, worth about $783,000 at press time — a fraction of the position's peak value.

When questioned further, the Alpaca team reportedly grew less transparent, continuing to remove critical voices rather than engage with them.

Given the protocol's history of managing hundreds of millions in TVL, a stronger remediation effort might have been expected. Instead, the proposed $50,000 distribution — the amount recovered via the liquidation bot — was presented with two possible allocation methods: fully covering smaller lenders first, or distributing proportionally across all affected lenders. Either way, affected users stood to recover only a small fraction of what they lost.

Alpaca's public defense centered on the argument that "fast oracle feeds can't exist to report prices of token listings that don't yet exist," framing the Thena market as its only "Isolated" listing within a designated "high-risk category." That explanation addresses the difficulty of pricing a brand-new listing instantly, but sidesteps the more basic issue: if an asset can't be priced reliably, it arguably shouldn't be offered for lending in the first place.

Pressed further on why the system relied on manual updates at all, the team asked "Which lending market uses this standard?" — a response that did little to address the underlying design flaw.

Taken together, the episode highlights a recurring problem in DeFi: protocols that market themselves as "battle-tested" while running critical infrastructure — in this case, price feeds for a market that once handled significant user funds — on a manual, browser-refresh-driven process. Alpaca is not the only protocol operating this way, and the incident points to a broader pattern of underbuilt infrastructure across the sector. Until oracle design is treated as a first-order security requirement rather than an afterthought, similar failures are likely to recur.

Alpaca FinanceOracle
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.