Mirror Protocol's Hidden $90M Bug — and the $2M Oracle Exploit That Followed It
Mirror Protocol was hit by two separate exploits, and the larger of the pair went unnoticed for so long that it makes the Ronin Bridge hack — where missing funds took a week to trigger an alarm — look fast by comparison. It took Mirror Protocol a full seven months to detect its loss, and even then, no public disclosure followed. Then, 232 days after that first incident, the protocol was struck again: the day after news of the original exploit finally surfaced, attackers took an additional $2 million.
Exploit one: draining collateral through repeated unlocks

Credit for uncovering the details goes to FatManTerra and pedroexplore1.
The first exploit took place on October 8, 2021. It involved repeatedly unlocking collateral that users had posted against short positions on the platform. Mirror's lock contract lacked a duplicate-call check on withdrawals, letting the attacker call unlock_position_funds for their own position ID over and over — each call draining funds that other users had deposited.
Attack transaction: 08DD2B70F6C2335D966342C20C1E495FD7A8872310B80BAF3450B942F79EBC1F
A detailed technical walkthrough is available in BlockSec's writeup of the incident.
Despite the flaw remaining exploitable, there was no repeat attack — the lock contract's balance never grew large enough again to make a second attempt worthwhile without drawing attention. As FatManTerra put it, the entire episode "went completely unnoticed by TFL and the Mirror team & community."
The bug was quietly patched on May 14, with no accompanying disclosure of either the vulnerability or the $90 million it had drained seven months prior. Forum users grew suspicious after examining the code change themselves, sparking a discussion about why the fix had been slipped in without any announcement. FatMan ultimately published the full details on May 27 — and the very next day, the second exploit was discovered.
Exploit two: the LUNA/LUNC repricing switcheroo
Sources: Mirroruser, Blockpane, FatManTerra.
A forum user going by "Mirroruser" was first to flag the loss to the community.
This exploit stemmed from the same LUNC mispricing that had already produced an exploit on Anchor: on the legacy Terra chain, LUNC was being valued as if it were LUNA 2.0, at around 5 USTC (roughly $0.10) at the time. The cause was that Luna Classic validators were running an outdated oracle that had never been updated to reflect the chain split.
That mispricing let attackers buy LUNC cheaply, post it as collateral, and exploit its inflated valuation to drain Mirror's asset pools. The mBTC, mETH, mDOT and mGLXY pools were emptied, amounting to roughly $2 million taken.

Once the exploit became known over the weekend, the oracle was fixed — but the danger wasn't fully over. All of Mirror's synthetic stock assets (mAssets) remained untradeable until markets reopened after the long weekend, raising fears that the already-stolen funds could be used to scoop up those assets while they were still drastically undervalued. With only minutes to spare before markets opened the following Tuesday, the team managed to disable the stolen funds from being used as collateral, protecting what remained of the protocol.
Aftermath
That a $90 million exploit could sit undetected by users — and likely by the developers themselves — for seven months speaks to broader carelessness within the Terra ecosystem at the time. The scale of the losses stands in stark contrast to how simple the underlying bugs were: $90 million lost to a basic logic error in the lock contract, followed by an oracle oversight that was arguably foreseeable given how hastily the chain fork had been executed.
Even as these failures came to light, LUNA 2.0's price kept climbing, and Terra co-founder Do Kwon continued to project confidence despite the billions in losses suffered by users of the ecosystem — a dynamic that left developers who had sunk their time and retail investors who had sunk their savings bearing the cost of his rebuilding effort.
Get new scam files the moment we publish them — usually 2–3 emails a week.