CryptoReal
CASE FILE — Jun 10, 2024

Oracle Manipulation Drains $19.4 Million From Sifu-Founded Lender UwuLend

Lending protocol UwuLend, founded by Sifu, the former CFO of Frog Nation, lost $19.4 million on June 10, 2024, after an attacker exploited a flaw in the way its markets priced collateral.

Cyvers was the first security firm to catch the incident, tracing it to three transactions carried out within a six-minute span. The attacker had routed funding through Tornado Cash beforehand, then converted the stolen WBTC and DAI into ETH once the exploit was complete.

UwuLend confirmed the breach roughly an hour later and paused the protocol while its team investigated. By that point the $19.4 million had already been split across two Ethereum wallets in a fast, tightly coordinated sequence. The loss was especially jarring because UwuLend had passed a security audit not long beforehand — and it has fueled ongoing suspicion of Sifu himself, given his history of controversy in prior projects.

01How the price feed was gamed

UwuLend's contracts are a fork of Aave V2, but with altered fallback-oracle logic that let the attacker borrow assets at one valuation and liquidate them at an inflated one, as illustrated in a side-by-side contract comparison. A root-cause writeup from Nick Franklin pinned the underlying issue on a pricing gap in that fallback oracle, which sourced its numbers from the state of several Curve pools.

Using a flash loan, the attacker pushed outsized trades through those pools to distort them, which in turn skewed the derived price feed. That distortion let the attacker borrow sUSDe valued at 0.99 while liquidating positions as though sUSDe were worth 1.03, pocketing the spread.

Attacker address: 0x841ddf093f5188989fa1524e7b893de64b421f47

Transactions carrying out the exploit:

0x242a0fb4fde9de0dc2fd42e8db743cbc197ffa2bf6a036ba0bba303df296408b

0xb3f067618ce54bc26a960b660cfc28f9ea0315e2e9a1a855ede1508eb4017376

Sums referenced in this case file

0xca1bbf3b320662c89232006f1ec6624b56242850f07e0f1dadbe4f69ba0d6ac3

Wallets currently holding the stolen assets:

0x48d7c1dd4214b41eda3301bca434348f8d1c5eb6

0x050c7e9c62bf991841827f37745ddadb563feb70

02Curve's founder among the hardest hit

Curve Finance founder Michael Egorov turned out to be one of the biggest individual losers, having deposited just over 23.5 million CRV (about $9.85 million) into UwuLend. The attacker moved those CRV tokens into Curve's Llama Lend market and borrowed roughly 8 million crvUSD (about $8.11 million) against them.

In one of the few positive outcomes of the incident, lenders in LlamaLend's CRV market repaid the debt themselves, forcing a full hard liquidation of the attacker's borrowed position — a sequence the Curve community cited as evidence the platform's risk parameters worked as intended under stress. The unfolding fallout was tracked in real time in Curve's Social Telegram channel.

03A bounty offer and an unexplained tip

Sifu subsequently sent an on-chain message to the attacker offering a 20% white-hat bounty in exchange for returning the funds by June 12 at 17:00 UTC, adding that after the deadline the reward structure would instead go to anyone who helped identify and pursue the attacker.

Separately, a different wallet sent the attacker an on-chain note laying out how to move the funds without drawing attention. Records show the same address had previously sent comparable guidance to whoever was behind the Gala Games, PlayDapp, and Exactly Protocol exploits.

04Audit history in question

UwuLend's codebase had previously been audited by PeckShield, whose report called the code "well designed and engineered" and found "no high-severity or critical issues." How a vulnerability in the fallback-oracle logic — the exact mechanism the attacker exploited — escaped that review remains an open question.

Whether UwuLend's reliance on DEX-derived prices for its fallback oracle was simply a design oversight, or something more deliberate given Sifu's involvement, has not been established. The identity of the party offering the attacker laundering advice, apparently linked to several unrelated exploits, is likewise still unknown.

Uwulend
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.