Oracle Manipulation Drains Lodestar Finance's Arbitrum Lending Pools for $6.5M
Lodestar Finance, a Compound-derived lending protocol running on Arbitrum, became the latest DeFi platform hit by price manipulation, joining a growing list of similar incidents across the sector.
On Saturday, December 10, 2022, an attacker manipulated the price oracle tied to Lodestar's plvGLP collateral and used the distorted valuation to drain the protocol's lending pools, netting an estimated $6.5 million in profit.

Lodestar's official statement noted that "2.8 Million of the GLP is recoverable, which is worth about $2.4 million," and the team publicly appealed to the attacker to negotiate a white-hat bounty arrangement.
In the aftermath, Lodestar's LODE token fell roughly 70%, and the protocol's total value locked collapsed to just $11 — a figure that landed Lodestar at #77 on the rekt leaderboard.
Mechanism of the exploit
Among Lodestar's supported collateral types was plvGLP, a yield-bearing asset representing GLP deposited in Plutus DAO's vault. Using flash loans, the attacker manipulated the plvGLP price reported by Lodestar's GLPOracle contract, which in turn allowed them to borrow far more than they should have been able to against the assets they held.
Lodestar's own security documentation had stated that the protocol relied "on Chainlink Oracles for accurate pricing (with the exception of plvGLP)" — a carve-out that, in hindsight, flagged exactly where the vulnerability would surface.
Solidity Finance summarized the underlying flaw: the GLPOracle failed to account for the effect of a user calling donate() on the GlpDepositor contract, which artificially inflated the GlpDepositor's recorded assets and, by extension, the oracle's reported price for plvGLP.
Lodestar's preliminary post-mortem added further detail, noting that oracle pricing should never be allowed to shift instantaneously within a single block. CertiK also published a full technical breakdown of the attack sequence.
On-chain details
- Attacker address: 0xc29d94386ff784006ff8461c170d1953cc9e2b5c
- Example exploit transaction: 0xc523c6307b025ebd9aef155ba792d1ba18d5d83f97c7a846f267d3d9a3004e8c

The 343 ETH (about $430,000) used to fund the attack had been bridged from Polygon roughly three months prior to the exploit. After draining the pools, the attacker converted the proceeds to ETH, bridged them back to Ethereum mainnet, and distributed the funds across several addresses.
Context
Collateral price manipulation has been a recurring attack vector throughout DeFi's history, and this incident arrived shortly after October's attacks on Mango Markets and Moola Markets, which resulted in losses of $115 million and $8.4 million respectively. In both of those prior cases, funds were eventually returned in part or in full. As of two days after the Lodestar attack, however, no plan for reparations had been announced.
The incident is also a reminder that forking a battle-tested codebase does not automatically inherit its security guarantees. Lodestar's own documentation described the protocol as being "a Compound fork at the core," built on contracts it called some of the most battle-tested in DeFi, while noting it had added support for Arbitrum, DPX, MAGIC, and plvGLP, along with adjustments to its interest rate models. It was precisely one of those additions — plvGLP support — that introduced the flaw exploited here, underscoring that any modification to a proven codebase reopens the question of security regardless of the base protocol's track record.
Get new scam files the moment we publish them — usually 2–3 emails a week.