
The Most Expensive Oracle Manipulation Attacks
Cream Finance ($130M), BonqDAO ($120M), and Mango Markets ($110M+) all fell to the same weakness: the protocol trusted a price an attacker could influence. How each manipulation worked, the common pattern behind them, and how to secure the price a contract trusts.
In DeFi, a wrong price is not just bad data. It can become inflated collateral, excessive borrowing, and millions in losses.
Price oracles sit between external markets and smart contracts. If an attacker can manipulate the price a protocol trusts, they may be able to make an asset appear far more valuable — or far less valuable — than it really is. Here are three of the most significant examples.
1. Cream Finance — $130 Million
Date: October 27, 2021 · Loss: Approximately $130 million
Cream Finance suffered a complex exploit involving flash liquidity and manipulation of the price used for yUSD collateral. The attacker used flash-borrowed assets to create a large yUSD position and manipulated the underlying liquidity pool that influenced yUSD's pricePerShare.
At one point, the manipulation effectively doubled the value of the attacker's collateral. That inflated collateral value was then used to borrow and remove the majority of liquidity from Cream's Ethereum v1 markets. Cream's own post-mortem confirmed that approximately $130 million worth of tokens was removed.
The attack pattern:
The Key Lesson
The problem was not simply that Cream used an oracle. The protocol trusted a value that could be economically manipulated within the attack sequence. If collateral value can be manipulated, borrowing power can be manipulated too.
2. BonqDAO — Approximately $120 Million
Date: February 1, 2023 · Loss: Approximately $120 million
BonqDAO suffered one of the clearest examples of a vulnerable oracle implementation. The protocol used a Tellor-based price feed for WALBT collateral. However, its implementation used the oracle's current value, allowing a newly submitted price to be used immediately.
The attacker staked the required amount of TRB, submitted a massively inflated WALBT price, and then used that manipulated value to mint 100 million BEUR. The attacker later pushed the price in the opposite direction, causing other positions to become liquidatable and extracting additional WALBT. BonqDAO's incident report identified the core issue: the price feed used getCurrentValue instead of a delayed historical value. Independent analyses estimated the total impact at approximately $120 million.
The attack pattern:
The Key Lesson
A decentralized oracle network is not automatically secure if the protocol integrates it incorrectly. Even good infrastructure can become dangerous when the implementation is flawed. A time delay or TWAP-style mechanism could have made this attack significantly more difficult.
3. Mango Markets — Over $110 Million
Date: October 11, 2022 · Amount extracted: Over $110 million
Mango Markets became one of the most famous examples of oracle manipulation in DeFi. The attacker created large leveraged positions linked to the relative price of MNGO and USDC. They then rapidly purchased large quantities of MNGO across exchanges used as inputs for Mango's oracle.
According to the CFTC, the MNGO price reported by the oracle increased by more than 13x within approximately 30 minutes. That artificial increase dramatically raised the value of the attacker's position. The attacker then used the inflated value as collateral to withdraw over $110 million in digital assets from Mango Markets. Approximately $67 million was later returned, according to the CFTC.
The attack pattern:
The Key Lesson
Using multiple exchanges does not automatically eliminate manipulation risk. If the underlying markets are thin enough to move, an attacker may be able to manipulate the very data those exchanges provide. An oracle is only as difficult to manipulate as its underlying price sources.
The Common Pattern
These attacks were different, but they shared the same fundamental weakness: the protocol trusted a value the attacker could influence. The general attack looks like this:
How Protocols Can Reduce Oracle Manipulation Risk
1. Use time-based pricing
Avoid relying on a price that can be manipulated within a single transaction. TWAP mechanisms make short-term manipulation more expensive.
2. Check the underlying liquidity
A token price is not automatically reliable just because it is publicly traded. Protocols should evaluate:
- Liquidity depth
- Trading volume
- Market concentration
- Volatility
- Cost of manipulation
3. Use independent price sources
Multiple sources can improve resilience — but only if they are genuinely independent.
4. Add price deviation limits
Large or unexpected price movements can trigger borrowing restrictions, temporary pauses, or additional validation.
5. Audit the integration, not just the oracle
BonqDAO demonstrated an important lesson: the oracle itself may not be the vulnerability. The way the protocol uses it might be.
Final Thoughts
Cream Finance lost approximately $130 million. BonqDAO suffered approximately $120 million in losses. Mango Markets had over $110 million extracted through manipulated pricing. The lesson behind all three is simple: a smart contract can execute perfectly and still make a catastrophic decision if the price it trusts is wrong.
In DeFi, price is not just information. Price determines collateral. Collateral determines borrowing power. Borrowing power determines how much value can be extracted.
Don't launch vulnerable code. Our team will review your smart contracts and deliver a full audit report within 48 hours.
Related Posts
Tags
Get Audited
Protect your protocol before attackers do. Request a full smart contract audit from 0xTeam.
Request Audit

