Inverse Finance Hit Again: $1.2M Stolen, $5.8M Lost in Second DOLA Oracle Exploit
Inverse Finance was exploited a second time, with an anonymous attacker walking away with roughly $1.2 million while the protocol's total losses from the incident reached $5.8 million. It marks the protocol's second appearance on the rekt leaderboard, following the $15 million price-manipulation attack it suffered just two months earlier.
This time, the target was Inverse Finance's DOLA lending market, again via oracle manipulation. Per the Risk DAO bad-debt dashboard, the protocol now carries $10.63 million in bad debt.

PeckShield tweeted about the exploit as it unfolded, but deleted the post after being criticized for publicizing the vulnerability while funds were still exposed. Inverse Finance later confirmed the incident, stating that "no user funds were taken or were at risk."
PeckShield is credited with the technical breakdown of the attack.
The exploit centered on manipulating the price of yvcrv3Crypto, which the protocol accepted as collateral. Inverse's oracle, per PeckShield, "misuses the balances of assets in the pool to directly calculate the LP token price" — meaning that shifting the pool's underlying asset balances directly shifted the reported collateral value.
Using a flash loan of WBTC to push large swaps through the underlying Curve pool, the attacker distorted those balances just long enough to borrow an inflated amount of DOLA before unwinding the trades. The sequence:
- Flash-loan 27,000 WBTC via Aave
- Deposit 225 WBTC into crv3crypto, minting 5,375 crv3crypto
- Deposit the 5,375 crv3crypto into yCurve-3Crypto, minting 4,906 yvCurve-3Crypto
- Post the 4,906 yvCurve-3Crypto as collateral on Inverse Finance
- Swap 26,775 WBTC for 75,403,376 USDT, skewing the collateral price
- Borrow 10,133,949 DOLA — far above what the position should have supported
- Reverse the earlier swap, turning the 75,403,376 USDT back into 26,626 WBTC
- Swap the 10,133,949 DOLA for 9,881,355 3Crv
- Redeem the 9,881,355 3Crv for 10,099,976 USDT
- Swap 10,000,000 USDT for 451 WBTC
- Repay the flash loan
The remaining funds were converted to ETH and moved out of the exploit contract: 1,000 ETH went into Tornado Cash, while 68 ETH stayed in the attacker's wallet.

The exploiter's address — funded via Tornado Cash two minutes before the attack — was 0x7b792e49f640676b3706d666075e903b3a4deec6. The exploit contract sat at 0xf508c58ce37ce40a40997c715075172691f92e2d, with the exploit transaction recorded on-chain. Two later withdrawals from the contract are also documented: 100,000 USDT and 53 WBTC, worth about $1.1 million.
Afterward, PeckShield muddied the waters further by suggesting that the exploit transaction had actually been front-run by a bot that beat the original attacker to it. That theory found little support elsewhere — given how quickly the address was funded and the proceeds subsequently laundered through Tornado Cash, an accidental or opportunistic front-run looks unlikely, though such a scenario isn't implausible for a future incident.
With bad debt now representing more than half of the protocol's roughly $20 million TVL, and two exploits within two months, Inverse Finance's ability to weather the broader market downturn is now an open question.
Get new scam files the moment we publish them — usually 2–3 emails a week.