Sixteen Days After Launch, Loopscale Loses $5.8M to an Oracle Exploit
Just sixteen days after going live, the Solana lending platform Loopscale watched an attacker drain $5.8 million on April 26, exploiting a stale price feed that an earlier audit had already flagged as a risk.
The mechanics were unremarkable by DeFi hacking standards: manipulate the collateral price an oracle reports, use the distorted valuation to draw down loans that were never properly collateralized, pull the assets out, and move them off-chain. No sophisticated exploit chain was needed — just a broken assumption about where price data was allowed to come from.

Loopscale halted its markets and confirmed the exploit shortly after it happened. Co-founder Mary Gooneratne confirmed the shape of the attack directly: an attacker opened a series of undercollateralized loans, targeting the protocol's USDC and SOL vaults for approximately $5.8 million. Researcher Max N. pinned down the technical root cause quickly — the attacker deployed their own malicious price feed and called Loopscale's create_loan function directly, walking straight past the protocol's intended safeguards.
According to Gooneratne, the loss represented roughly 12% of Loopscale's total value locked. The company later described the flaw as isolated to how the newly launched SOL and USDC "Genesis" vaults priced RateX-based collateral. RateX founder Sean Hu was quick to separate his own protocol from the incident, stating that the investigation confirmed an oracle attack and that RateX's own protocol carried no security issues of its own — placing responsibility squarely on the implementation choices made by Loopscale.
Notably, the attacker apparently didn't need access to Loopscale's source code at all. As Twitter user Bill Papas laid out, it was possible to pull the Interface Description Language straight out of the deployed program binary, then study on-chain transaction patterns to reconstruct the relevant functionality locally — despite the code itself being closed-source. It's a reminder that keeping a codebase private doesn't equate to keeping it secure; it just delays when hidden flaws get found.
01Tracing the funds
The exploit itself played out on Solana, after which the proceeds were bridged to Ethereum via Wormhole.
Two addresses were involved on the Solana side: one used to carry out the exploit itself, and a second used to move the resulting funds toward Ethereum.
The withdrawal was split across four transactions: three draws of $1.5 million in USDC each, and a fourth recorded as $1.226.7 million USDC. The attacker then swapped the accumulated USDC for SOL and consolidated everything by moving roughly $5.792 million (39,474.5 SOL) from the exploiting address to the address handling the bridge transfer.
That SOL crossed to Ethereum through Wormhole in three separate legs: 5,000 SOL (about $735,000), 10,000 SOL (about $1.47 million), and 20,000 SOL (about $2.96 million).
02Negotiating a return
Within hours, Loopscale had paused its markets and disclosed the exploit publicly, and the team managed to restore loan repayments and loop-closing functionality soon after — though vault withdrawals stayed frozen while the investigation continued.
Loopscale then sent an on-chain message to the exploiter, proposing a standard whitehat arrangement: return 90% of the funds (35,527 SOL) and keep the remaining 10% (3,947 SOL) as a bounty, with a promise of no legal liability, and a 24-hour deadline attached.
The attacker rejected the standard split and countered, asking for 20% instead of 10%. As a show of good faith, they returned the smallest of the three bridged batches — the 5,000 SOL ($735,000) — while continuing to hold the larger remaining sums. They also stated that the 20,000 SOL still sitting inside Wormhole was no longer something they controlled, leaving Loopscale to sort that part out with the bridge directly.
The recovery continued in stages. By that Sunday, the first two bridged batches — a combined $2.2 million — had made their way back to Loopscale, while the $2.96 million portion remained stuck in the bridge. That final tranche, the 20,000 SOL worth about $2.96 million, was returned early the following Tuesday. By April 29, Loopscale confirmed all stolen funds had been recovered in full, and stated that users would not lose any deposits as a result of the incident, with further detail on vault withdrawals promised later.

What the team has not disclosed is whether the exploiter ultimately received any bounty for returning the funds; when asked directly, Loopscale did not share those details.
03The audit that saw it coming
Commentator Phat Bear summed up the underlying criticism: Loopscale had been transparent throughout the incident, but the exploit itself was still severe, and the Genesis vaults had opened with a $40 million cap without a thorough audit specific to them. That $40 million ceiling wasn't accidental — it was a deliberate limit the team set for vaults launched shortly after the protocol left beta.
The irony is that OShield's audit had already raised oracle validation as a concern, and the same audit reported that concern as resolved. Loopscale's own documentation stated that "all critical and high-risk issues identified have been fixed" — shortly before an attacker exploited precisely the class of vulnerability that audit had called out.
Recovering every dollar taken doesn't undo the exposure created by launching with real user funds on a Genesis vault whose oracle handling wasn't as airtight as the marketing suggested. Whether Loopscale's transparent handling of the aftermath is enough to offset that initial failure remains to be seen.
Get new scam files the moment we publish them — usually 2–3 emails a week.