Home > Today’s Crypto News
bitcoin
bitcoin

$96418.721981 USD

-2.05%

ethereum
ethereum

$2687.739314 USD

-2.74%

xrp
xrp

$2.588011 USD

-3.00%

tether
tether

$0.999825 USD

-0.04%

bnb
bnb

$656.326573 USD

0.40%

solana
solana

$171.386564 USD

-2.54%

usd-coin
usd-coin

$1.000043 USD

0.01%

dogecoin
dogecoin

$0.244077 USD

-3.80%

cardano
cardano

$0.767310 USD

-3.77%

tron
tron

$0.237868 USD

-4.90%

chainlink
chainlink

$17.505561 USD

-4.59%

sui
sui

$3.344930 USD

-4.57%

avalanche
avalanche

$24.939290 USD

-1.00%

stellar
stellar

$0.327623 USD

-3.46%

litecoin
litecoin

$129.677981 USD

-3.20%

Oracle Manipulation

Oracle manipulation, or oracle price manipulation, is an exploit most common in the DeFi space where an oracle smart contract is manipulated by attackers, which leads to system failure, theft and other damages. DeFi networks are reported to have lost over $33 million due to price oracle manipulation in 2020 alone.

Oracles are third-party service providers that supply blockchains with external or real-world data such as price feeds, weather information, statistics, etc. Price feeds are by far the most exploited oracle data since they allow attackers to steal millions of funds from DeFi platforms. 

Generally, there are two ways an oracle can gather price information. One is to seamlessly siphon price data from centralized exchanges via APIs. On the other hand, oracles can also do the calculations themselves by consulting decentralized exchanges (DEXs). Both methods have their own sets of advantages and disadvantages, as well as ways of being manipulated.

In the Harvest Finance hack, the culprit was able to penetrate its pools through a flash loan using a form of oracle manipulation. Basically, the hacker reduced the value of USDC within the Curve pool via a trade. Then, the perpetrator got into the Harvest pool at the deflated price, brought USDC back to its initial price reversing his trade, then exited the pool at a much higher price.