Onyx Protocol Loses $3.8M in Second Exploit of Same Compound Bug
Onyx Protocol, a Compound v2 fork, was exploited a second time on September 26, 2024, this time for approximately $3.8 million. The attacker reused the same vulnerability class that had already cost the protocol funds late in the previous year, draining a mix of VUSD, XCN, DAI, WBTC, and USDT.
01How the alert broke

Cyvers flagged the incident first, reporting suspicious activity tied to Onyx DAO on Ethereum with an estimated loss around $3.8 million. Onyx's own confirmation came roughly four hours later, when the team acknowledged unusual platform activity and said it was reviewing third-party post-mortem data alongside its own investigation. By the time that statement went out, the funds had already moved.
02Mechanics of the attack
Security researchers, including Hacken, reconstructed the attack path as a repeat of the precision-manipulation technique seen in Onyx's earlier incident:
- The attacker took out a flash loan of 2,000 ETH from Balancer.
- They deposited 1,999.5 ETH into the oEther contract while routing 0.5 ETH through a custom malicious contract.
- That contract was used to mint and redeem oETH in extremely small increments — as little as 0.00000001 oETH per cycle.
- This mint/redeem sequence was repeated 56 times, progressively distorting the market's exchange rate.
The underlying flaw is a known issue across the Compound V2 fork family: exchange-rate calculations can be manipulated when a market has low liquidity. Onyx had already been warned about this class of bug.
Exploiter address: 0x680910cf5Fc9969A25Fd57e7896A14fF1E55F36B
Attack transaction: 0x46567c731c4f4f7e27c4ce591f0aebdeb2d9ae1038237a0134de7b13e63d8729
Attack contract: 0xAE7d68b140Ed075E382e0A01d6c67ac675AFa223
03A second flaw, layered on top
Peckshield identified an additional issue exploited in the same incident: the NFTLiquidation contract failed to properly validate user input, which let the attacker inflate the self-liquidation reward they could claim against Onyx's reserves.
04Funds extracted
Per Peckshield's breakdown, the stolen assets totaled:

- 4.1M VUSD
- 7.35M XCN
- 5K DAI
- 0.23 WBTC
- 50K USDT
Combined, this amounted to roughly $3.8 million.
05Background: audits, governance, and repeated warnings
Onyx's most recent public audit, conducted by CertiK, dates back to January 2022, with no publicized follow-up review since. Despite this, the protocol had recently added a VUSD market through a governance proposal — introducing a new, presumably low-liquidity market without a fresh security review.
Rekt's earlier coverage of Onyx's first exploit had already pointed out that the risk here isn't confined to the codebase itself — thin liquidity in newly launched markets creates exactly the conditions this exploit type depends on. Following a similar repeat hack at Hundred Finance, Hexagate had recommended a mitigation: mint and burn cTokens as needed to ensure total supply never drops to zero, closing off the low-liquidity window attackers rely on. That guidance apparently went unheeded at Onyx before this second incident.
Get new scam files the moment we publish them — usually 2–3 emails a week.