CryptoReal
CASE FILE — Sep 21, 2021

Oracle Manipulation on Avalanche Nets Attacker $34M From Vee Finance

Vee Finance lost $34 million to an exploit, placing the protocol seventh on the incident leaderboard. The attack marks the second major loss on the Avalanche network within the same month — following a roughly $3.2 million exploit at Zabu Finance on September 12 — underscoring that as AVAX has grown in popularity, so has the volume of attacks targeting projects built on it.

Details below are drawn from Vee Finance's first official post-mortem of the incident.

The attacker's addresses were identified on both chains: an Ethereum address (0xeeee458c3a5eaafcfd68681d405fb55ef80595ba) and the corresponding Avalanche C-Chain address (0xeeeE458C3a5eaAfcFd68681D405FB55Ef80595BA).

Funding for the attack originated through Tornado Cash, arriving in three separate 10 ETH deposits. Those funds were then bridged over to Avalanche, where the attacker swapped 26.999006274904347875 WETH.e for 1,369.708 AVAX using Pangolin.

With capital in place, the attacker deployed a first exploit contract, using it to swap AVAX into the specific tokens targeted by the attack and to establish a set of new trading pairs: QI/WETH.e, XAVA/WETH.e, LINK.e/WETH.e, QI/LINK.e, XAVA/LINK.e, XAVA/WBTC.e, and LINK.e/WBTC.e.

Sums referenced in this case file

Once that contract had been funded with 20 AVAX spread across five addresses, preparation for the exploit was complete. An initial attempt to execute the attack failed due to insufficient gas. The attacker then used a dynamically generated contract to carry out leveraged trading on the QI/WETH.e pair, but this attempt also failed. A new attack contract was subsequently deployed, repeating the same steps — this time successfully. Additional repeated trades converting USDT.e to ETH.e were routed through AugustusSwapper, and a third exploit contract was deployed as part of the operation.

The underlying vulnerability stemmed from how Vee Finance priced assets for leveraged trading: the protocol relied on a single price source — the token prices reflected in Pangolin's liquidity pools. By trading across the newly created pairs, the attacker was able to distort those reference prices. This manipulation, combined with a separate flaw where token decimals weren't correctly accounted for during price retrieval, let transactions slip past the protocol's slippage checks that should otherwise have blocked them. A deeper technical explanation appears in Vee Finance's second post-mortem, published the same day.

Over the course of the attack and afterward, the stolen assets were bridged back to Ethereum across more than 100 separate transactions. As of the report, the attacker's Ethereum wallet held 214 WBTC (roughly $9.3 million) and 8,804 WETH (roughly $26.9 million).

In its incident report, Vee Finance stated it was "actively working to further clarify the incident and will continue to try to contact the attacker to recover the assets," and offered the attacker a bug bounty in exchange for returning the funds. The team sent messages directly to the exploiter's addresses on both Ethereum and Avalanche, and shared the appeal publicly on Twitter, reading in part: "Hello, this is vee.finance team. We are willing to launch a bug bounty program for the bug you identified, please contact us via [email protected]."

The exploiter's addresses also became a magnet for unrelated on-chain messages from onlookers — including a warning reading "Your address has been caught by the team," a self-promotional message from a Twitter user asking to be followed, and a plea for funds reading "Big man, send me some for a poor man who can't afford to eat." As of publication, that request had gone unanswered.

Notably, Vee Finance had prior audits from both SlowMist and CertiK, but recommendations from the SlowMist review were reportedly not followed, and the CertiK audit likewise failed to prevent the incident. The protocol's continued presence in speculative "pump" communities was also flagged as a red flag for its overall health.

Vee Finance
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.