Inverse Finance Drained of $15.6M as Attacker Manipulates SushiSwap TWAP Oracle
Inverse Finance, an Ethereum-based lending protocol, was hit for roughly $15 million after an anonymous attacker engineered a price distortion in INV, the platform's governance token, and used it to unlock a wildly oversized loan.
Analysis credited to Igor Igamberdiev and PeckShield traced how the exploit was carried out.

In total, roughly $15.6 million was drained, made up of 1,588 ETH, 94 WBTC, 4 million DOLA, and 39.3 YFI.
The attacker's opening move was withdrawing 901 ETH from Tornado Cash. From there, 1.5 ETH was spread across 241 freshly-created wallets using Disperse, and five smart contracts were deployed — only one of which was actually used in the attack.
Next, 500 ETH was swapped for roughly 1,700 INV through the thinly-traded INV-WETH pool on SushiSwap, pushing the token's price up by a factor of roughly 50 given the pool's shallow liquidity. While that trade was landing, the attacker flooded the mempool with competing transactions designed to guarantee that the exploit transaction would be the first included in the following block, locking in the inflated SushiSwap price.
The vulnerability sat in how Inverse Finance's price oracle worked: routed through Keeper Network, it pulled a SushiSwap time-weighted average price (TWAP) that, thanks to the manipulated pool, now reported a wildly overstated value for INV.
With that distorted price in place, the attacker deposited the roughly 1,700 INV — worth about $644,000 at fair market value — as collateral, and walked away with a $15.6 million loan that was never repaid.
PeckShield published a visual breakdown of how the transactions unfolded.
Inverse Finance subsequently issued an official statement on the incident, and observers across the space were quick to point out how technically demanding the attack had been — a departure from the simple "leaked private key" incidents that make up much of the hack landscape.
MEV researcher @bertcmiller called it "one of the most MEV aware hacks I've seen," noting that the attacker "held an oracle's price at an insane level across multiple blocks, prevented arb bots from bringing prices back in line, and protected against generalised frontrunners."

Chainlinkgod — a frequent commentator whenever an oracle exploit surfaces — added that "relying upon a TWAP oracle generated from a single thinly traded DEX trading pair with a short time sample compounds market manipulation risks."
Following the incident, Inverse Finance said during a Twitter Spaces session that it plans to work with Chainlink to launch a dedicated INV price feed once liquidity thresholds are met, replacing the TWAP-based oracle entirely.
While the underlying weaknesses look obvious in hindsight, the level of coordination involved makes clear this was not the work of an amateur.
Get new scam files the moment we publish them — usually 2–3 emails a week.