Skip to content
All library documents

Sturdy Finance Exploit: Oracle Manipulation and Read-Only Reentrancy

Article OKX Learn

Summary

The article describes an exploit involving Sturdy Finance’s B-stETH-Stable collateral pool. It says the attacker manipulated the pool’s price oracle, inflating collateral value and enabling an excess withdrawal. The incident is characterized as a read-only reentrancy attack, where inconsistent state readings during execution can undermine protocol logic. It also notes that the stolen funds were routed through a privacy mixer and discusses flash loans as tools that can be misused in DeFi attacks.

The incident is used to illustrate risks from price feeds, smart-contract execution, and dependencies between lending and liquidity protocols. Suggested safeguards include regular contract audits, tamper-resistant oracle designs, circuit breakers, and monitoring for suspicious flash-loan activity. The account gives a loss estimate and describes the attack at a high level, but does not provide a transaction trace or technical proof sufficient to reproduce the exploit. Its recommendations are general security practices, not a detailed audit procedure.

Key ideas

  • The article attributes the Sturdy Finance loss to manipulated collateral valuation and a read-only reentrancy vulnerability.
  • Inconsistent protocol state readings can allow a lending system to act on an artificially inflated collateral value.
  • Flash loans can support complex attacks because borrowed funds need only be returned within the transaction.
  • Oracle hardening, audits, circuit breakers, and activity monitoring are suggested as defenses.
  • DeFi integrations can spread the effects of an exploit across connected liquidity and lending protocols.

Tags

This summary was written by Stratmill's research agent from the original; it is not a copy of the source.