• bitcoinBitcoin (BTC) $ 91,807.00
  • ethereumEthereum (ETH) $ 3,131.99
  • tetherTether (USDT) $ 0.998772
  • xrpXRP (XRP) $ 2.07
  • bnbBNB (BNB) $ 908.56
  • solanaSolana (SOL) $ 139.51
  • usd-coinUSDC (USDC) $ 0.999722
  • tronTRON (TRX) $ 0.298701
  • staked-etherLido Staked Ether (STETH) $ 3,132.92
  • dogecoinDogecoin (DOGE) $ 0.138701
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.04
  • cardanoCardano (ADA) $ 0.392433
  • wrapped-stethWrapped stETH (WSTETH) $ 3,835.90
  • bitcoin-cashBitcoin Cash (BCH) $ 613.30
  • moneroMonero (XMR) $ 643.46
  • whitebitWhiteBIT Coin (WBT) $ 55.25
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 3,406.81
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 91,659.00
  • wrapped-eethWrapped eETH (WEETH) $ 3,401.55
  • usdsUSDS (USDS) $ 0.999585
  • chainlinkChainlink (LINK) $ 13.21
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998640
  • leo-tokenLEO Token (LEO) $ 9.09
  • wethWETH (WETH) $ 3,132.97
  • stellarStellar (XLM) $ 0.222887
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 91,858.00
  • suiSui (SUI) $ 1.79
  • zcashZcash (ZEC) $ 397.49
  • ethena-usdeEthena USDe (USDE) $ 0.999301
  • avalanche-2Avalanche (AVAX) $ 13.75
  • litecoinLitecoin (LTC) $ 76.33
  • hyperliquidHyperliquid (HYPE) $ 24.32
  • canton-networkCanton (CC) $ 0.140908
  • shiba-inuShiba Inu (SHIB) $ 0.000009
  • hedera-hashgraphHedera (HBAR) $ 0.116102
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.168535
  • usdt0USDT0 (USDT0) $ 0.998653
  • susdssUSDS (SUSDS) $ 1.08
  • daiDai (DAI) $ 0.999807
  • the-open-networkToncoin (TON) $ 1.75
  • crypto-com-chainCronos (CRO) $ 0.100273
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.21
  • paypal-usdPayPal USD (PYUSD) $ 0.999923
  • polkadotPolkadot (DOT) $ 2.10
  • uniswapUniswap (UNI) $ 5.42
  • usd1-wlfiUSD1 (USD1) $ 0.999048
  • mantleMantle (MNT) $ 0.955367
  • rainRain (RAIN) $ 0.008766
  • memecoreMemeCore (M) $ 1.70
  • bittensorBittensor (TAO) $ 286.29
  • aaveAave (AAVE) $ 170.09
  • bitget-tokenBitget Token (BGB) $ 3.56
  • pepePepe (PEPE) $ 0.000006
  • tether-goldTether Gold (XAUT) $ 4,583.95
  • okbOKB (OKB) $ 111.28
  • nearNEAR Protocol (NEAR) $ 1.73
  • falcon-financeFalcon USD (USDF) $ 0.996157
  • jito-staked-solJito Staked SOL (JITOSOL) $ 175.00
  • ethereum-classicEthereum Classic (ETC) $ 12.46
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,130.79
  • pax-goldPAX Gold (PAXG) $ 4,599.83
  • ethenaEthena (ENA) $ 0.220075
  • internet-computerInternet Computer (ICP) $ 3.17
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • pi-networkPi Network (PI) $ 0.206256
  • aster-2Aster (ASTER) $ 0.698961
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.151526
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.79
  • htx-daoHTX DAO (HTX) $ 0.000002
  • binance-staked-solBinance Staked SOL (BNSOL) $ 152.48
  • worldcoin-wldWorldcoin (WLD) $ 0.564360
  • hashnote-usycCircle USYC (USYC) $ 1.11
  • global-dollarGlobal Dollar (USDG) $ 0.999618
  • kucoin-sharesKuCoin (KCS) $ 11.16
  • pump-funPump.fun (PUMP) $ 0.002497
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • ripple-usdRipple USD (RLUSD) $ 0.999919
  • aptosAptos (APT) $ 1.80
  • wbnbWrapped BNB (WBNB) $ 908.49
  • skySky (SKY) $ 0.057469
  • bfusdBFUSD (BFUSD) $ 0.998506
  • hash-2Provenance Blockchain (HASH) $ 0.024636
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,618.58
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999529
  • kaspaKaspa (KAS) $ 0.047531
  • ondo-financeOndo (ONDO) $ 0.392403
  • cosmosCosmos Hub (ATOM) $ 2.54
  • render-tokenRender (RENDER) $ 2.37
  • gatechain-tokenGate (GT) $ 10.29
  • arbitrumArbitrum (ARB) $ 0.204632
  • algorandAlgorand (ALGO) $ 0.130241
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,325.55
  • myx-financeMYX Finance (MYX) $ 5.95
  • midnight-3Midnight (NIGHT) $ 0.067059
  • filecoinFilecoin (FIL) $ 1.49
  • official-trumpOfficial Trump (TRUMP) $ 5.38
  • story-2Story (IP) $ 2.99
  • bridged-wrapped-lido-staked-ether-scrollBridged Wrapped Lido Staked Ether (Scroll) (WSTETH) $ 3,831.06
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 92,190.00
  • ignition-fbtcFunction FBTC (FBTC) $ 91,672.00
  • vechainVeChain (VET) $ 0.011490
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 91,564.00
  • nexoNEXO (NEXO) $ 0.961849
  • flare-networksFlare (FLR) $ 0.011274
  • bonkBonk (BONK) $ 0.000010
  • usddUSDD (USDD) $ 0.998159
  • xdce-crowd-saleXDC Network (XDC) $ 0.046461
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.02
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,393.12
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 3,321.04
  • usdtbUSDtb (USDTB) $ 0.999320
  • ousgOUSG (OUSG) $ 113.94
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.95
  • sei-networkSei (SEI) $ 0.121071
  • wrappedm-by-m0WrappedM by M^0 (WM) $ 0.999775
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.012021
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999605
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 91,602.00
  • blockstackStacks (STX) $ 0.387800
  • morphoMorpho (MORPHO) $ 1.30
  • clbtcclBTC (CLBTC) $ 91,345.00
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,349.26
  • beldexBeldex (BDX) $ 0.090995
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 162.25
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.10
  • jupiter-exchange-solanaJupiter (JUP) $ 0.209955
  • usdaiUSDai (USDAI) $ 1.00
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.285130
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • wrapped-flareWrapped Flare (WFLR) $ 0.011245
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.95
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 3,327.16
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,132.51
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.966754
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999949
  • optimismOptimism (OP) $ 0.317614
  • tezosTezos (XTZ) $ 0.566107
  • c8ntinuumc8ntinuum (CTM) $ 0.137541
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.22
  • curve-dao-tokenCurve DAO (CRV) $ 0.401071
  • dashDash (DASH) $ 44.80
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,133.06
  • spx6900SPX6900 (SPX) $ 0.600598
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 24.53
  • chilizChiliz (CHZ) $ 0.054865
  • tbtctBTC (TBTC) $ 91,897.00
  • usual-usdUsual USD (USD0) $ 0.986412
  • lighterLighter (LIT) $ 2.15
  • lido-daoLido DAO (LDO) $ 0.624021
  • injective-protocolInjective (INJ) $ 5.21
  • aerodrome-financeAerodrome Finance (AERO) $ 0.569499
  • gtethGTETH (GTETH) $ 3,130.98
  • flokiFLOKI (FLOKI) $ 0.000051
  • ghoGHO (GHO) $ 0.999031
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998902
  • true-usdTrueUSD (TUSD) $ 0.998220
  • ether-fiEther.fi (ETHFI) $ 0.738093
  • msolMarinade Staked SOL (MSOL) $ 188.58
  • celestiaCelestia (TIA) $ 0.547138
  • fasttokenFasttoken (FTN) $ 1.09
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 3,383.35
  • syrupMaple Finance (SYRUP) $ 0.395410
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.11
  • stader-ethxStader ETHx (ETHX) $ 3,378.25
  • the-graphThe Graph (GRT) $ 0.041474
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,507.15
  • newton-projectAB (AB) $ 0.004462
  • jasmycoinJasmyCoin (JASMY) $ 0.008608
  • riverRiver (RIVER) $ 21.69
  • wrapped-apecoinWrapped ApeCoin (WAPE) $ 0.206766
  • starknetStarknet (STRK) $ 0.082226
  • staked-aaveStaked Aave (STKAAVE) $ 168.82
  • usdbUSDB (USDB) $ 1.02
  • bittorrentBitTorrent (BTT) $ 0.00000042
  • doublezeroDoubleZero (2Z) $ 0.117850
  • sbtc-2sBTC (SBTC) $ 91,973.00
  • iotaIOTA (IOTA) $ 0.095992
  • justJUST (JST) $ 0.040734
  • sun-tokenSun Token (SUN) $ 0.020688
  • ethereum-name-serviceEthereum Name Service (ENS) $ 10.23
  • conflux-tokenConflux (CFX) $ 0.075629
  • wrapped-stx-velarWrapped STX (Velar) (WSTX) $ 0.383999
  • bitcoin-svBitcoin SV (BSV) $ 19.17
  • fartcoinFartcoin (FARTCOIN) $ 0.378909
  • pyth-networkPyth Network (PYTH) $ 0.065696
  • gnosisGnosis (GNO) $ 141.94
  • dogwifcoindogwifhat (WIF) $ 0.374211
  • chain-2Onyxcoin (XCN) $ 0.008789
  • trust-wallet-tokenTrust Wallet (TWT) $ 0.880209
  • pendlePendle (PENDLE) $ 2.17
  • apenftAINFT (NFT) $ 0.00000037
  • kaiaKaia (KAIA) $ 0.061255
  • crvusdcrvUSD (CRVUSD) $ 0.998571
  • cap-usdCap USD (CUSD) $ 1.00
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 91,747.00
  • euro-coinEURC (EURC) $ 1.17
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.138606
  • telcoinTelcoin (TEL) $ 0.003735
  • olympusOlympus (OHM) $ 21.49
  • kinesis-goldKinesis Gold (KAU) $ 147.69

Tokenized gold market on Morpho loses $230K after Oracle misconfiguration mishap

0 98

Tokenized gold market on Morpho loses $230K after Oracle misconfiguration mishap

The Paxos tokenized gold (PAXG) market on DeFi protocol Morpho Protocol suffered an exploit today, leading to a $230,000 loss. According to Chaos Labs founder Omer Goldberg, the incident was caused by a mistake during the setup of the Oracle pricing for $2.6 trillion.

In a post-mortem of the incident shared on X, Omer explained that an Oracle misconfiguration is likely because the PAXG/USDC market deployer did not fully understand the platform’s decimal system. Morpho Protocol allows users to create decentralized lending markets and set the parameters.

Omer explained:

“The Oracle SCALE_FACTOR was misconfigured, failing to account for the differences between decimals in USDC (6 decimals) and PAXG (18 decimals). This led to a 12-decimal inflation in price, overpricing gold by a factor of 10^12.”

The exploiter noticed the error on time, so they immediately sent $350 worth of PAXG to the market, using it to withdraw $230,000 in USDC.

While the incident appears to have been caused by an error on the part of the deployer, Omer observed that the protocol did not flag the issue, and the Morpho Protocol user interface showed the correct gold price.

In his opinion, this is likely because security monitoring focused on the reference prices instead of the Oracle price.

Morpho Protocol says the platform remains safe

Meanwhile, Omer noted that the incident highlights some of the risks of using decentralized platforms like the Morpho protocol, as there is a need for precision when setting up such lending markets, especially for parameters guiding oracles and risks.

He also called for real-time monitoring, saying:

“Real-time risk monitoring, in this case, a deviation between the Morpho market price and an external reference price, is essential to prevent incidents like this.”

However, the protocol developer Morpho Labs has responded by noting that the incident was not due to any security issue on its platform. Rather, it was because the risk curator made mistakes.

The team said:

“We believe it is important to differentiate between underlying smart contract vulnerabilities and mistakes at the risk curation layer – much like how misconfigured pairs on Uniswap are not considered exploits of the protocol itself.”

It further described the incident as an isolated issue that had no impact on the protocol, noting that even the risk curator has recovered some of the funds and is working to repay the lenders. The developer added that it will provide more tools to help curators limit such errors in the future.

Despite the clarifications, some users still believe that the Oracle provider used is responsible and have called Morpho Labs to rely exclusively on Chainlink for all its price feeds. However, the team said that its protocol is oracles agnostic, with each risk curator free to choose the oracles and private feed they want.

Meanwhile, Kamino Finance co-founder Marius noted that the risk curator in this case was not a full-time risk curator, which is likely what led to the mistake. He also confirmed that most of the funds have been recovered, and the issue is controlled.

Crypto investor says the incident is not an exploit

While discussions about the incident have focused on its impact, Felipe Montealegre, the co-founder of crypto investment firm Theia Capital, believes it is not a significant issue. According to him, losses by capital providers are an inherent part of the lending system, with even traditional financial institutions losing money on lending.

He said:

“Even Moody’s B rated corporate debt has a three-year default rate of 17%. You can’t have an interesting lending platform where capital providers aren’t occasionally losing money.”

However, he admitted that while risk curators can take risks and lose funds, the underlying DeFi protocols work correctly and as advertised. He noted that this is exactly what happened to Morpho Protocol, as the issue was caused by an error from the fund manager and had nothing to do with the protocol. Thus, he noted that this was not a DeFi exploit in the true sense of the word.

Source

Leave A Reply

Your email address will not be published.