• bitcoinBitcoin (BTC) $ 108,729.00
  • ethereumEthereum (ETH) $ 4,370.65
  • tetherTether (USDT) $ 1.00
  • xrpXRP (XRP) $ 2.80
  • bnbBNB (BNB) $ 858.62
  • solanaSolana (SOL) $ 200.32
  • usd-coinUSDC (USDC) $ 0.999807
  • staked-etherLido Staked Ether (STETH) $ 4,360.54
  • dogecoinDogecoin (DOGE) $ 0.215902
  • tronTRON (TRX) $ 0.338187
  • cardanoCardano (ADA) $ 0.821708
  • wrapped-stethWrapped stETH (WSTETH) $ 5,284.86
  • chainlinkChainlink (LINK) $ 23.37
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 4,711.43
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 108,912.00
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • hyperliquidHyperliquid (HYPE) $ 43.75
  • wrapped-eethWrapped eETH (WEETH) $ 4,687.91
  • suiSui (SUI) $ 3.30
  • stellarStellar (XLM) $ 0.354391
  • bitcoin-cashBitcoin Cash (BCH) $ 545.37
  • crypto-com-chainCronos (CRO) $ 0.315419
  • avalanche-2Avalanche (AVAX) $ 23.83
  • hedera-hashgraphHedera (HBAR) $ 0.224333
  • wethWETH (WETH) $ 4,374.05
  • leo-tokenLEO Token (LEO) $ 9.51
  • litecoinLitecoin (LTC) $ 110.26
  • the-open-networkToncoin (TON) $ 3.13
  • usdsUSDS (USDS) $ 0.999669
  • shiba-inuShiba Inu (SHIB) $ 0.000012
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 108,778.00
  • whitebitWhiteBIT Coin (WBT) $ 42.28
  • uniswapUniswap (UNI) $ 9.75
  • polkadotPolkadot (DOT) $ 3.78
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.19
  • bitget-tokenBitget Token (BGB) $ 4.53
  • aaveAave (AAVE) $ 315.67
  • moneroMonero (XMR) $ 259.57
  • daiDai (DAI) $ 0.999923
  • ethenaEthena (ENA) $ 0.662054
  • pepePepe (PEPE) $ 0.000010
  • mantleMantle (MNT) $ 1.21
  • okbOKB (OKB) $ 177.96
  • ethereum-classicEthereum Classic (ETC) $ 20.95
  • bittensorBittensor (TAO) $ 323.50
  • pi-networkPi Network (PI) $ 0.383544
  • nearNEAR Protocol (NEAR) $ 2.44
  • jito-staked-solJito Staked SOL (JITOSOL) $ 245.98
  • aptosAptos (APT) $ 4.30
  • ondo-financeOndo (ONDO) $ 0.912766
  • usdt0USDT0 (USDT0) $ 1.00
  • arbitrumArbitrum (ARB) $ 0.500609
  • binance-peg-wethBinance-Peg WETH (WETH) $ 4,373.59
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.251898
  • internet-computerInternet Computer (ICP) $ 4.88
  • usd1-wlfiUSD1 (USD1) $ 1.00
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • binance-staked-solBinance Staked SOL (BNSOL) $ 214.25
  • kaspaKaspa (KAS) $ 0.084729
  • story-2Story (IP) $ 7.03
  • vechainVeChain (VET) $ 0.024641
  • cosmosCosmos Hub (ATOM) $ 4.51
  • algorandAlgorand (ALGO) $ 0.233439
  • gatechain-tokenGate (GT) $ 17.01
  • rocket-pool-ethRocket Pool ETH (RETH) $ 4,977.65
  • susdssUSDS (SUSDS) $ 1.07
  • fasttokenFasttoken (FTN) $ 4.53
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 5.38
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.030087
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 4,585.36
  • render-tokenRender (RENDER) $ 3.49
  • worldcoin-wldWorldcoin (WLD) $ 0.911368
  • kucoin-sharesKuCoin (KCS) $ 14.01
  • sei-networkSei (SEI) $ 0.288195
  • bonkBonk (BONK) $ 0.000022
  • bfusdBFUSD (BFUSD) $ 0.999524
  • official-trumpOfficial Trump (TRUMP) $ 8.39
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 4,603.33
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.625610
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 43.85
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 4,723.42
  • filecoinFilecoin (FIL) $ 2.29
  • jupiter-exchange-solanaJupiter (JUP) $ 0.500774
  • flare-networksFlare (FLR) $ 0.021218
  • quant-networkQuant (QNT) $ 103.72
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 108,775.00
  • skySky (SKY) $ 0.063302
  • usdtbUSDtb (USDTB) $ 1.00
  • fourFour (FORM) $ 3.77
  • xdce-crowd-saleXDC Network (XDC) $ 0.079519
  • polygon-bridged-usdt-polygonPolygon Bridged USDT (Polygon) (USDT) $ 0.999817
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 4,619.74
  • falcon-financeFalcon USD (USDF) $ 1.00
  • mantle-staked-etherMantle Staked Ether (METH) $ 4,685.31
  • hash-2Provenance Blockchain (HASH) $ 0.026885
  • tether-goldTether Gold (XAUT) $ 3,445.67
  • injective-protocolInjective (INJ) $ 13.05
  • celestiaCelestia (TIA) $ 1.65
  • optimismOptimism (OP) $ 0.704973
  • nexoNEXO (NEXO) $ 1.25
  • pump-funPump.fun (PUMP) $ 0.003518
  • wbnbWrapped BNB (WBNB) $ 858.48
  • paypal-usdPayPal USD (PYUSD) $ 1.00
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 227.49
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998741
  • pyth-networkPyth Network (PYTH) $ 0.200379
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 109,271.00
  • blockstackStacks (STX) $ 0.624245
  • curve-dao-tokenCurve DAO (CRV) $ 0.780151
  • lido-daoLido DAO (LDO) $ 1.21
  • conflux-tokenConflux (CFX) $ 0.212629
  • spx6900SPX6900 (SPX) $ 1.14
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999839
  • memecoreMemeCore (M) $ 0.621616
  • sonic-3Sonic (S) $ 0.316386
  • aerodrome-financeAerodrome Finance (AERO) $ 1.12
  • immutable-xImmutable (IMX) $ 0.519447
  • super-oethSuper OETH (SUPEROETH) $ 4,375.56
  • pax-goldPAX Gold (PAXG) $ 3,462.93
  • syrupusdcSyrupUSDC (SYRUPUSDC) $ 1.12
  • the-graphThe Graph (GRT) $ 0.088731
  • raydiumRaydium (RAY) $ 3.46
  • msolMarinade Staked SOL (MSOL) $ 264.40
  • saros-financeSaros (SAROS) $ 0.350457
  • flokiFLOKI (FLOKI) $ 0.000094
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 108,876.00
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 4,356.41
  • kaiaKaia (KAIA) $ 0.148478
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.49
  • cgeth-hashkey-cloudcgETH Hashkey Cloud (CGETH.HASH) $ 4,250.12
  • clbtcclBTC (CLBTC) $ 109,858.00
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 4,374.36
  • dogwifcoindogwifhat (WIF) $ 0.810253
  • pendlePendle (PENDLE) $ 4.73
  • fartcoinFartcoin (FARTCOIN) $ 0.792961
  • vaultaVaulta (A) $ 0.494181
  • theta-tokenTheta Network (THETA) $ 0.782803
  • tezosTezos (XTZ) $ 0.738184
  • ethereum-name-serviceEthereum Name Service (ENS) $ 23.23
  • iotaIOTA (IOTA) $ 0.192244
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 1.15
  • galaGALA (GALA) $ 0.016251
  • ousgOUSG (OUSG) $ 112.39
  • loaded-lionsLoaded Lions (LION) $ 0.023674
  • jito-governance-tokenJito (JTO) $ 1.94
  • jasmycoinJasmyCoin (JASMY) $ 0.014733
  • ripple-usdRipple USD (RLUSD) $ 0.999801
  • build-onBUILDon (B) $ 0.690758
  • newton-projectAB (AB) $ 0.009146
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.09
  • usdx-money-usdxStables Labs USDX (USDX) $ 0.997827
  • the-sandboxThe Sandbox (SAND) $ 0.274116
  • stader-ethxStader ETHx (ETHX) $ 4,630.33
  • morphoMorpho (MORPHO) $ 1.99
  • mantle-restaked-ethMantle Restaked ETH (CMETH) $ 4,681.77
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 4,375.15
  • zcashZcash (ZEC) $ 40.05
  • bittorrentBitTorrent (BTT) $ 0.00000065
  • tbtctBTC (TBTC) $ 108,655.00
  • flowFlow (FLOW) $ 0.397693
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 4,801.84
  • usual-usdUsual USD (USD0) $ 0.997826
  • swethSwell Ethereum (SWETH) $ 4,732.74
  • beldexBeldex (BDX) $ 0.076923
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.216021
  • global-dollarGlobal Dollar (USDG) $ 0.999742
  • walrus-2Walrus (WAL) $ 0.386826
  • decentralandDecentraland (MANA) $ 0.284920
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 108,773.00
  • vision-3Vision (VSN) $ 0.164728
  • bitcoin-svBitcoin SV (BSV) $ 26.01
  • syrupMaple Finance (SYRUP) $ 0.463048
  • ether-fiEther.fi (ETHFI) $ 1.09
  • frax-etherFrax Ether (FRXETH) $ 4,339.94
  • true-usdTrueUSD (TUSD) $ 0.996588
  • starknetStarknet (STRK) $ 0.127891
  • neoNEO (NEO) $ 6.93
  • dydx-chaindYdX (DYDX) $ 0.618765
  • based-brettBrett (BRETT) $ 0.048196
  • polygon-pos-bridged-weth-polygon-posPolygon PoS Bridged WETH (Polygon POS) (WETH) $ 4,375.66
  • heliumHelium (HNT) $ 2.53
  • solv-protocol-solvbtc-bbnSolv Protocol Staked BTC (XSOLVBTC) $ 107,256.00
  • apecoinApeCoin (APE) $ 0.569266
  • apenftAPENFT (NFT) $ 0.00000045
  • usddUSDD (USDD) $ 1.00
  • reserve-rights-tokenReserve Rights (RSR) $ 0.007466
  • mantle-bridged-usdt-mantleMantle Bridged USDT (Mantle) (USDT) $ 0.997123
  • zksyncZKsync (ZK) $ 0.060657
  • bybit-staked-solBybit Staked SOL (BBSOL) $ 220.71
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999887
  • sun-tokenSun Token (SUN) $ 0.022784
  • coredaoorgCore (CORE) $ 0.431830
  • savings-daiSavings Dai (SDAI) $ 1.17
  • telcoinTelcoin (TEL) $ 0.004684
  • dexeDeXe (DEXE) $ 7.56
  • thorchainTHORChain (RUNE) $ 1.20
  • arweaveArweave (AR) $ 6.43
  • bridged-usdc-polygon-pos-bridgeBridged USDC (Polygon PoS Bridge) (USDC.E) $ 0.999796
  • instadappFluid (FLUID) $ 6.16

Tokenized gold market on Morpho loses $230K after Oracle misconfiguration mishap

0 53

Tokenized gold market on Morpho loses $230K after Oracle misconfiguration mishap

The Paxos tokenized gold (PAXG) market on DeFi protocol Morpho Protocol suffered an exploit today, leading to a $230,000 loss. According to Chaos Labs founder Omer Goldberg, the incident was caused by a mistake during the setup of the Oracle pricing for $2.6 trillion.

In a post-mortem of the incident shared on X, Omer explained that an Oracle misconfiguration is likely because the PAXG/USDC market deployer did not fully understand the platform’s decimal system. Morpho Protocol allows users to create decentralized lending markets and set the parameters.

Omer explained:

“The Oracle SCALE_FACTOR was misconfigured, failing to account for the differences between decimals in USDC (6 decimals) and PAXG (18 decimals). This led to a 12-decimal inflation in price, overpricing gold by a factor of 10^12.”

The exploiter noticed the error on time, so they immediately sent $350 worth of PAXG to the market, using it to withdraw $230,000 in USDC.

While the incident appears to have been caused by an error on the part of the deployer, Omer observed that the protocol did not flag the issue, and the Morpho Protocol user interface showed the correct gold price.

In his opinion, this is likely because security monitoring focused on the reference prices instead of the Oracle price.

Morpho Protocol says the platform remains safe

Meanwhile, Omer noted that the incident highlights some of the risks of using decentralized platforms like the Morpho protocol, as there is a need for precision when setting up such lending markets, especially for parameters guiding oracles and risks.

He also called for real-time monitoring, saying:

“Real-time risk monitoring, in this case, a deviation between the Morpho market price and an external reference price, is essential to prevent incidents like this.”

However, the protocol developer Morpho Labs has responded by noting that the incident was not due to any security issue on its platform. Rather, it was because the risk curator made mistakes.

The team said:

“We believe it is important to differentiate between underlying smart contract vulnerabilities and mistakes at the risk curation layer – much like how misconfigured pairs on Uniswap are not considered exploits of the protocol itself.”

It further described the incident as an isolated issue that had no impact on the protocol, noting that even the risk curator has recovered some of the funds and is working to repay the lenders. The developer added that it will provide more tools to help curators limit such errors in the future.

Despite the clarifications, some users still believe that the Oracle provider used is responsible and have called Morpho Labs to rely exclusively on Chainlink for all its price feeds. However, the team said that its protocol is oracles agnostic, with each risk curator free to choose the oracles and private feed they want.

Meanwhile, Kamino Finance co-founder Marius noted that the risk curator in this case was not a full-time risk curator, which is likely what led to the mistake. He also confirmed that most of the funds have been recovered, and the issue is controlled.

Crypto investor says the incident is not an exploit

While discussions about the incident have focused on its impact, Felipe Montealegre, the co-founder of crypto investment firm Theia Capital, believes it is not a significant issue. According to him, losses by capital providers are an inherent part of the lending system, with even traditional financial institutions losing money on lending.

He said:

“Even Moody’s B rated corporate debt has a three-year default rate of 17%. You can’t have an interesting lending platform where capital providers aren’t occasionally losing money.”

However, he admitted that while risk curators can take risks and lose funds, the underlying DeFi protocols work correctly and as advertised. He noted that this is exactly what happened to Morpho Protocol, as the issue was caused by an error from the fund manager and had nothing to do with the protocol. Thus, he noted that this was not a DeFi exploit in the true sense of the word.

Source

Leave A Reply

Your email address will not be published.