Lodestar Suffers $6M Flash Loan Attack
A lending protocol in the Arbitrum ecosystem, Lodestar Finance has fallen victim to a flash loan attack. On December 10, a malicious actor was able to cart off about $5.8M in loot from the platform. Lodestar has since posted a Twitter thread explaining how the culprit was able to do so. Hacker Tweaks Exchange Rate, Withdraws Liquidity Per the post, the attacker’s approach was to manipulate the swap rate of the network’s plvGLP contract. The culprit set the rate at 1.83 GLP per plvGLP. It was their first move, however, as the Lodestar team noted it could not have been worked on its own. A report from Solidity Finance explained why the hacker was able to manipulate the price of plvGLP. The GLPOracle did not properly take into account the impact of a user calling donate() on the GlpDepositor contract, which inflates the assets of the GlpDepositor contract, and therefore the oracle-delivered price of the plvGLP token.” Subsequently, using the inflated plvGLP as collateral...