Onchain Security Roundup: Aug 31 - Sep 6

Nexus Mutual Team

·

Liquid Network Smart Contract Exploit

4,000 BTC (~$320 million); 3,400 BTC returned. Liquid is a Bitcoin sidechain, where BTC is bridged (pegged is the term Liquid Network uses for bridging) into the network and is represented as L-BTC, backed by the BTC held in reserve on the Bitcoin network.

On September 6th, an attacker exploited a vulnerability in Liquid’s verification process. To hide transaction amounts, Liquid's software runs expensive validity checks and caches the results to save time. The cache's labeling was flawed: a check verified on a legitimate transaction could be wrongly reused for a fraudulent one. After days of unnoticed preparation, the attacker used a verified validity check on a fraudulent transaction to mint roughly 4,000 unbacked L-BTC, then bridged it back to the Bitcoin network for BTC held in Liquid’s reserves, draining about $318 million (95% of the reserve) in under an hour. Notably, a fix already existed publicly but hadn't yet been shipped onchain.

The attacker, claiming to be a security researcher, returned 3,400 BTC after Blockstream patched the bug, keeping ~598 BTC (~$47 million) as a large whitehat bounty. Negotiations continue. Blockstream says updated software has been deployed and a coordinated restart is being prepared. A completed restart and full reserve reconciliation are not yet confirmed.

Injective Oracle Manipulation

$4.9 million. Injective is a Layer-1 blockchain built for trading. Injective lets anyone create new prediction-style markets ("binary options") without approval, including choosing the price feed that decides each market's outcome. 

On August 31st, the attacker created hundreds of markets with a price feed deliberately designed to fail and combined this with a bookkeeping flaw: the system confused two internal accounts because their identifying labels clashed. When each market closed without a price, the refund process paid out roughly twice what the attacker had deposited. About $105,000 deposited became ~$204,000 refunded, repeated over and over…

To stop the drain, the network's validators effectively froze the chain for nearly four hours while an emergency fix was installed; no ordinary user transactions were reversed. The stolen funds were moved to the Ethereum network, converted into ~1,980 ETH ($4.9 million), and remain parked in a wallet controlled by the attacker. Nothing has been recovered to date. Injective said that its core network, the INJ token, and staked assets were never at risk, with losses limited to a few trading applications. No official post-mortem has yet been published.

Aquifer Private Key Compromise

$2.47 million. Aquifer is an automated market maker (AMM) on Solana. Aquifer is a "proprietary automated market maker." Rather than pooling customer deposits, the firm quotes prices on ~190 token pairs using its own capital, updating those quotes from data feeds like a traditional market-making desk.

On August 31st, the Aquifer protocol was exploited for $2.47 million, effectively all of the money it held. The current evidence implies an operational security failure, where an attacker was able to compromise the digital keys controlling Aquifer's wallets; however, no technical explanation has been published yet. Within half an hour, the attacker emptied the protocol’s token inventory, converted it to USDC, and moved the proceeds to the Ethereum network. 

Aquifer publicly offered to let the attacker keep 20% as a white hat reward if at least 80% was returned by September 3rd. The offer was ignored. Between September 4th and 6th, the attacker converted the funds, ~1,000 ETH, into $2.47 million USDC and bridged it to other networks to obscure the trail. As of September 9th, nothing has been recovered and no reimbursement plan has been announced. 

Notional Finance V1 Smart Contract Exploit

$1.7 million. Notional v1 is a lending protocol on Ethereum. On September 4th, an attacker stole $1.7 million in stablecoins from Notional v1, which launched in 2021 and had been deprecated but never fully shut down. Its vault contract still held user deposits. 

The protocol’s escrow smart contract checks that every borrower has enough collateral before allowing users to withdraw. The attacker found an arithmetic flaw in that check. By deliberately creating a debt so astronomically large that it exceeded the biggest number the escrow contract could store, the recorded debt effectively "rolled over" to zero. The attacker was able to withdraw 69,257 DAI and 1,658,524 USDC, which was then swapped into ~689 ETH and routed through Tornado Cash. The exploit took under three minutes and cost the attacker only a small amount in fees and setup capital. 

Notional paused the legacy contract and said its current V3 deployment and Exponent assets were not at risk. No funds have been recovered to date.

Rocket Oracle Manipulation

$287,000. Rocket is a purpose-built layer-1 blockchain for derivatives trading that launched in beta earlier this year. Customers deposit USDC into the bridge contract on the Arbitrum network and then trade on Rocket's own high-speed exchange.

On September 5th, an attacker found a market on the exchange that nobody was trading. Because it was empty, the attacker could act as both buyer and seller and set whatever price they wanted. Using two accounts they controlled, they traded with themselves to manipulate prices and earn a profit in one account while dumping equal losses into a disposable account they then abandoned. The attacker then pocketed their profits.

In 40 minutes the attacker withdrew ~$329,600, of which $42,200 was their own recycled stake, a net theft of ~$287,400 that effectively emptied Rocket’s bridge contract. The funds were moved to other blockchains within 20 minutes. 

Rocket has frozen the platform, is working with law enforcement, and has promised a refund plan prioritizing smaller customers. Nothing has been recovered so far. 

Cozy Finance Oracle Manipulation

170,186 USDC.e. Cozy Finance is a parametric coverage protocol on Optimism. It lets people buy pooled protection that pays out if a covered event such as a hack occurs. On September 7th, Cozy Finance’s claims trigger was exploited for $170,186 after an attacker submitted a false oracle update that was approved. It was the protocol’s second loss in thirteen months.

The attacker abused the protocol’s optimistic oracle to trigger a fraudulent claim payout. Cozy decides whether a payout is owed by asking a yes/no question to UMA’s optimistic oracle, a system that treats any submitted answer as true unless someone challenges it within a set time window. On September 2nd, the attacker bought cheap protection on the Aave v2, Curve and Rabbithole Quests markets for ~$3,000, then formally answered “YES, these were hacked” to the UMA oracle, although nothing had happened.

As Cozy was largely abandoned and unmonitored, no one challenged the false answers during the five-day window. Once the window closed on September 7th, the markets resolved to Yes; the attacker legitimately claimed the full protection payout for 170,186 USDC.e, bridged to Ethereum, and then routed the proceeds through Tornado Cash within minutes.

The affected Sets are paused for new deposits and protection purchases, but suppliers can redeem their share of remaining assets. Cozy said they would soon provide a full account and an announcement on supplier losses.

Secured Finance Oracle Manipulation

$133,000 (estimated). Secured Finance is a fixed-rate lending protocol with onchain orderbooks on Ethereum, Arbitrum and Filecoin. Unlike a simple savings pool, it works like a bond exchange: every loan is recorded as a zero-coupon bond on an onchain order book, and the protocol’s books count each user’s lending position as collateral they can borrow or withdraw against. The value it assigns to that position, and therefore how much a user is allowed to take out, depends on the current market price of those bonds.

The flaw was in how the order book calculated that market price for its own accounting. Instead of using an independent, established price, the protocol derived it purely from the trades that occurred in the same block. It treated those trades as genuine without checking that they were struck between different parties. The attacker used a flash loan to manipulate the price by placing both sides of a trade with themselves to set the price to whatever they wanted, pushing it up to near the maximum. The order book then wrote this manipulated price into its books, so the protocol recorded the attacker’s lending position as collateral worth far more than it truly was. With the inflated bookkeeping entry, the attacker was able to withdraw far more than they had put in, draining the affected smart contracts. 

Roughly $133,000 was taken across several assets, the largest being ~0.9 Wrapped Bitcoin (~$72,000). Notably, the original attacker’s own attempt failed (it ran out of gas), and an automated “copycat” bot detected the opportunity and captured the biggest prize seconds later. Almost none of the money has been recovered: the value of the stolen Bitcoin was paid out to an Ethereum block builder as a transaction fee, and the drained vault remains essentially empty. 

Secured Finance's affected lending markets and TokenVaults remain paused on all three chains. Quantstamp is reviewing the proposed fix and helping trace funds. Loss reconciliation and individual user impacts remain under assessment. No reopening date or compensation plan has been announced.

Dream Health Chain Smart Contract Exploit

$71,800. Dream Health Chain is a project on BNB Chain that distributes onchain rewards through award contracts. On September 5th, an attacker discovered a logic flaw in the protocol’s award state machine. Once a reward had been paid, the contract was supposed to mark the reward claimed and never pay it again. Instead, anyone could flip a claimed reward back to unclaimed at essentially zero cost and repeatedly collect the same payout.

The attacker automated this loop, emptied about 95% of the rewards pot in a single transaction bundle in under one second, and immediately sold the stolen tokens into the project's trading pools, walking away with ~$71,800 in USDT. The token's market price fell roughly 80%, spreading additional losses across 35,000+ holders and liquidity providers.

Nothing has been recovered so far. As of this report, the funds sit untouched in the attacker's wallet, and the drained contract has had no activity. The project has been largely dormant since 2022, its code was never publicly verified, and it’s unknown if the code was ever audited.

Reddio RedSonic Smart Contract Exploit

9.25 ETH (~$22,800). RedSonic is Reddio's vault system on Ethereum, which issues the share tokens rsvETH and rsvstETH against deposited ETH and stETH. On September 5th, an attacker drained ~9.25 ETH (~$23,000) from the RedSonic Vault, an Ethereum deposit contract operated by Reddio. Users deposit ETH into the vault and receive a receipt token, rsvETH, which represents their share of the pooled funds and any yield earned.

The attacker exploited two smart contract vulnerabilities. First, a function that adds new asset types to the vault was left open to the public, so anyone could register a new deposit class. Second, the vault calculated the value of rsvETH by reading its raw token balances, so a deposit made through the newly registered class made existing rsvETH shares look more valuable, and the same collateral was counted twice.

The attacker borrowed 1,139 ETH through a flash loan, deposited those funds to take a 99% share of the vault, inflated the share price, redeemed everything at the inflated rate, repaid the loan, and kept the difference. The stolen 9.25 ETH, which represented all of the ETH in the vault, still sits untouched in the attacker's wallet. No recovery or team statement has been made public.

Reflexer GebProxyActions Smart Contract Exploit

5.9 ETH. Reflexer is the protocol behind the GEB system, where users hold collateral in SAFEs that are normally managed through personal proxy contracts. 

Some users had called the shared GebProxyActions contract directly instead of through their own DSProxy, which caused the SAFE manager to record the shared contract itself as the owner of their SAFEs. Because the public quitSystem() function did not restrict who could call it, an attacker invoked it for the affected SAFEs on September 2nd and directed 5.9436 ETH of released collateral to their address.

Contact us to structure cover for your portfolio

Subscribe to our newsletter

Be the first to know about our latest news, announcements and events!

This website is operated by Collective Risk Services CIC, with its registered office at 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ, on behalf of Terrapin International Foundation

© 2026 Nexus Mutual