CryptoReal
CASE FILE — Oct 15, 2021

A Pricing Delay in Indexed Finance's Pools Costs Users $16 Million

Indexed Finance has become the latest protocol added to the exploit tally, with an attacker walking away with roughly $16 million. Shortly after the incident, core contributor Dr Laurence Day attempted to reach the attacker directly through an on-chain message: "Indexed Finance here. Time to talk?"

01The protocol and the mechanism

Indexed Finance runs six index pools, each holding a basket of assets, with each pool's token intended to track a weighted average of its underlying holdings. At 18:37 UTC on October 14, an attacker targeted the DEFI5 and CC10 pools. The Future of Finance Fund (FFF) took significant collateral damage too, since DEFI5 and CC10 together made up 37.05% of its underlying holdings. A fuller technical breakdown is available in the official post-mortem and in Mudit Gupta's Twitter thread; Dillon Kellar, the original author of the codebase, also shared his own reaction in a tweet thread.

Indexed's pool contracts are a fork of the Balancer Pool contract, which rebalances holdings internally along a constant product curve. A function called extrapolatePoolValueFromToken derives total pool value using the first fully-initialized token with a target weight above zero, following the formula:

total_value = token_balance * total_weight / token_weight

To limit slippage, the protocol caps how quickly weight changes take effect — a design choice that creates a temporary mismatch between real and reported value, which the attacker exploited.

02How the exploit unfolded

Sums referenced in this case file

The attacker's wallet, 0xba5ed1488be60ba2facc6b66c6d6f0befba22ebe, had been funded via Tornado Cash just hours before the attack began. Both the DEFI5 and CC10 pools were hit using the same method; the transaction against the DEFI5 pool illustrates the pattern.

Using flash loans of the pool's other assets, the attacker bought out UNI holdings within the pool, which lowered the pool's extrapolated value because the system hadn't yet caught up to UNI's reduced weight. Because the protocol restricts any single swap from moving more than half of a token's existing pool balance, or purchasing more than a third of a token's pool balance, this had to be executed in stages rather than one transaction.

Having driven the reported pool value down this way, the attacker called updateMinimumBalance, which used the manipulated valuation to price the pool at just 29,851 SUSHI (roughly $300,000) — despite the pool actually holding over $100 million in other assets. With SUSHI now drastically over-weighted relative to the pool's stated value, the attacker deposited a comparatively small amount of it and received a hugely inflated quantity of DEFI5 tokens in return. Those tokens were then redeemed for a proportional share of the pool's real assets, completing the extraction. In total, around $16 million across various assets was taken; as of the time of the original report, the funds remained sitting in the same attacker address.

03The developer's response

In a follow-up to the technical post-mortem, Dr Laurence Day shared additional context suggesting the team believes it may know the attacker's identity, having interacted with them before the exploit occurred.

According to Day, a Discord user going by "UmbralUpsilon" (later "BogHolder#1688") reached out on September 15, asking detailed questions about how certain oracle parameters worked. Since Indexed's code is fully open-source, the team answered, and when asked why, the user said they were building an arbitrage bot for the pools — a plausible request, since exit fees charged on arbitrage-driven burns are one of Indexed's core revenue mechanisms. The team therefore saw no reason for concern and explained reindexing logic, reweighting timing, and how assets are added to or removed from candidate lists.

Separately, researcher @pcaversaccio flagged that the same actor had requested Kovan testnet ETH via Gitter using a now-defunct Twitter account, @ZetaZeroes, apparently created specifically for the attack. The team responded to that account on Gitter with a message addressed directly to the exploiter, acknowledging their technical skill — noting the vulnerability had gone unnoticed in production for ten months — and offering a 10% whitehat bounty in exchange for returning the funds and avoiding law enforcement involvement. Day's statement emphasized that the people harmed were largely users trying to diversify risk in a volatile market, calling that context particularly bitter, and left the door open for the attacker to reach out.

04Aftermath

Beyond the financial loss, Dr Laurence Day — who has been publicly identified throughout this episode despite bearing no responsibility for the exploit — has also received death threats as a result of the incident, raising an uncomfortable question about whether anonymity remains the safer path for developers in this space.

Indexed Finance
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.