지금 프로젝트를 보호하세요
최대 규모의 웹3 보안 제공업체로 프로젝트를 강화하세요.
CertiK 보안 전문가가 귀하의 요청을 검토 후 곧 연락드리겠습니다.

Oracle Dependency: Decrypting the Sturdy Finance Attack

보고서 ·사고 분석 ·
Oracle Dependency: Decrypting the Sturdy Finance Attack

Project name: Sturdy Finance

Project type: Lending

Date of exploit: Jan 12, 2023

Asset loss: 442 ETH

Vulnerability: Price manipulation (read-only reentrancy)

Date of audit conducted: Jan 25, 2022

Conclusion: Out of audit scope

Details of the Exploit

Project Background

Sturdy Finance, a DeFi lending protocol, enables users to deposit collateral and borrow tokens based on their collateral value, which is determined by external price Oracles to acquire price for the collateral. In the recent exploit, the Balancer protocol functioned as this external price Oracle.

Nature of the Vulnerability

  • The attacker's collateral value is incorrectly calculated by a manipulated asset price, so the attacker can borrow more than its collateral to drain the vault.
  • The collateral price is provided by a Balancer protocol, which has a read-only reentrancy issue in its implementation.
  • The attacker manipulated the collateral price from the Balancer protocol by triggering external calls to update its collateral in Sturdy's lending protocol in the process of withdrawing tokens from the Balancer protocol.

CertiK Audit Overview

Sturdy Finance table

Conclusion

On Jan 12, 2023, the lending platform Sturdy Finance was attacked, leading to a loss of 442 ETH. The attacker made use of a read-only reentrancy vector to manipulate the price used in a lending protocol to drain funds. The vulnerability lies in the dependency on the Balancer protocol, which was used to price Oracles in Sturdy's contracts and has been widely recognized by the community. The dependency on the Balancer protocol is not in CertiK's audit scope.

References

Rekt.new Analysis: https://rekt.news/sturdy-rekt/

Additional Resources: Reentrancy Vulnerability Scope Expanded

관련 블로그

The Enterprise DLT Oracle Challenge

The Enterprise DLT Oracle Challenge

In DeFi, oracle failures can cause financial losses within a system that broadly accepts risk. Enterprise DLT operates in a different world. The assets are physical. The counterparties are regulated. The consequences are legal.

Makina Incident Analysis

Makina Incident Analysis

On 20 January 2026, DeFi protocol MakinaFi suffered an exploit resulting in the theft of 1,299 ETH, valued at approximately $4.13 million.

Oracle Wars: The Rise of Price Manipulation Attacks

Oracle Wars: The Rise of Price Manipulation Attacks

In this article, we look at how oracles work, why they matter, how they can be exploited, and more, with the goal of educating DeFi participants on how to better protect themselves from these types of threats.