지금 프로젝트를 보호하세요
최대 규모의 웹3 보안 제공업체로 프로젝트를 강화하세요.
CertiK 보안 전문가가 귀하의 요청을 검토 후 곧 연락드리겠습니다.

Lending Rate Manipulation: Investigating the FilDA Finance Attack

보고서 ·사고 분석 ·
Lending Rate Manipulation: Investigating the FilDA Finance Attack

Project name: FilDA

Project type: Lending

Date of exploit: April 22, 2023

Asset loss: $700K

Vulnerability: Exchange rate manipulation

Date of audit report publishing: June 1, 2021

Conclusion: Out of audit scope

Details of the Exploit

Background

FilDA provides a lending protocol where users can deposit token as collateral then borrow tokens.

Nature of the Vulnerability

The exchange rate is calculated by exchangeRate = (Cash + totalBorrows - totalReserves)/totalSupply. The attacker manipulated the exchange rate by donating a large amount of htHBTC tokens to the contract. Since Cash in the above formula is the amount of htHBTC that the Filda htHBTC contract has, the exploiter donates a large amount of htHBTC to inflate the exchangeRate. As a result, the attacker can borrow more than its collaterals from the pool.

CertiK Audit Overview

Screenshot 2024-01-08 at 5.28.30 AM

Conclusion

On April 22, 2023, FilDA Finance was attacked, leading to a loss of around $700K. The attacker manipulated the exchange rate in the lending pool and drained funds from it. CertiK has audited the FilDA’s Flashloan contracts. However, the vulnerability lies in the lending pool contract, which is a new product that is not within CertiK's audit scope.

References

FilDA exploit statement: https://fildafinance.medium.com/filda-exploit-statement-49ec69e34c53

관련 블로그

Makina Incident Analysis

Makina Incident Analysis

On 20 January 2026, DeFi protocol MakinaFi suffered an exploit resulting in the theft of 1,299 ETH, valued at approximately $4.13 million.

Oracle Wars: The Rise of Price Manipulation Attacks

Oracle Wars: The Rise of Price Manipulation Attacks

In this article, we look at how oracles work, why they matter, how they can be exploited, and more, with the goal of educating DeFi participants on how to better protect themselves from these types of threats.

Polter Finance Incident Analysis

Polter Finance Incident Analysis

On 16 November 2024, Polter Finance was exploited for ~$8.7 million, due to a price manipulation exploit. Polter Finance paused their platform shortly after to investigate.