The post Scallop Protocol lost $142K in a flash loan merged with an oracle manipulation attac appeared on BitcoinEthereumNews.com. Scallop Protocol got hit by aThe post Scallop Protocol lost $142K in a flash loan merged with an oracle manipulation attac appeared on BitcoinEthereumNews.com. Scallop Protocol got hit by a

Scallop Protocol lost $142K in a flash loan merged with an oracle manipulation attac

For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Scallop Protocol got hit by a flash loan exploit on Sunday. The attacker reportedly drained around $142,000 (150,000 SUI) in what appears to be a highly targeted oracle manipulation attack. This one didn’t touch the protocol’s core contracts but exposed a deeper design flaw.

An attacker reportedly exploited a deprecated side contract tied to Scallop’s sSUI rewards pool. Their team urges that the core protocol remain intact and that all user deposits are safe. However, the loss is fully contained to that isolated part.

Old code or Oracle flaw?

Analysts suggest that the core issue was the manipulation of Scallop’s custom oracle price feeds. This allowed the attacker to artificially depress SUI/USDC rates and borrow assets at those distorted prices. It then repaid the flash loan within the same transaction. In the end, the suspect walked away with the difference.

This follows a familiar DeFi attack pattern; however, the execution in this event was unusually precise. The attacker didn’t target active code or standard SDK routes. They interacted with an older V2 contract from November 2023. This was a version that had been left but remained callable on-chain. Sui keeps all deployed contract versions immutable and accessible. That’s why this outdated package became a hidden attack surface.

Sui price hasn’t taken a hit after the exploit. It is up by almost 2% in the last 24 hours. Sui is trading at $0.94 at the press time. Its 24 hour trading volume hovers around $187 million.

An expert in a post mentioned that the flaw itself was subtle but severe. In the deprecated contract, a key variable “last_index” was never initialized when a new account was created. This allowed the attacker to claim rewards as if they had been staking since the beginning of the pool.

With the reward index having grown over time, the attacker passed through to credit themselves with the entire reward pool in a single transaction. He mentioned that the Spool index grew to 1.19B over 20 months. 

Attacker staked 136K sSUI and got credited with 162 trillion points. However, the rewards pool ran a 1:1 exchange rate (numerator and denominator both = 1), so 162T points converted directly to 162K SUI worth of rewards. The pool only had 150K SUI in it and all of them got drained.

On-chain data shows the stolen funds were quickly routed through a mixing service, similar to Tornado Cash on Sui. This makes the recovery even more difficult.

Scallop back online after hack

Scallop’s team responded by temporarily pausing operations. It then reported that they have unfrozen the core contracts and all operations have resumed. An X post highlighted that the issue was not related to the core protocol and was isolated to a deprecated rewards contract. In the end, tser deposits were not impacted and all funds remain safe. The withdrawals and deposits are now operating normally.

The attacker reportedly contacted the team and offered to return 80% of the funds in exchange for a white-hat bounty. The incident is now being investigated. The team will check how the flaw passed prior audits by firms such as OtterSec and MoveBit.

Cryptopolitan reported that many of April 2026’s major incidents have not come from core protocol logic. They emerged from old contracts, adapters, or infrastructure layers that remain accessible but overlooked. The cumulative losses exceeded $750 million by mid-April. April 2026 alone has accounted for over $600 million in stolen funds across 12 major incidents. 

Kelp DAO and Drift Protocol, all together has account for approx 95% of April’s losses. The attack on Kelp resulted in $177 million in bad debt on Aave. Meanwhile, Arbitrum’s Security Council successfully froze 30,766 ETH (approx worth $71 million) of the stolen funds.

Hyperliquid is still the biggest token in the DeFi category. HYPE price is up by 10% in the last 30 days. It is trading at $41.95 at the press time. Chainlink stands at the 2nd stop. LINK traded around $9.4.

There’s a middle ground between leaving money in the bank and rolling the dice in crypto. Start with this free video on decentralized finance.

Source: https://www.cryptopolitan.com/sui-based-scallop-hit-by-flash-loan-attack-142k-lost/

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Adoption Leads Traders to Snorter Token

Adoption Leads Traders to Snorter Token

The post Adoption Leads Traders to Snorter Token appeared on BitcoinEthereumNews.com. Largest Bank in Spain Launches Crypto Service: Adoption Leads Traders to Snorter Token Sign Up for Our Newsletter! For updates and exclusive offers enter your email. Leah is a British journalist with a BA in Journalism, Media, and Communications and nearly a decade of content writing experience. Over the last four years, her focus has primarily been on Web3 technologies, driven by her genuine enthusiasm for decentralization and the latest technological advancements. She has contributed to leading crypto and NFT publications – Cointelegraph, Coinbound, Crypto News, NFT Plazas, Bitcolumnist, Techreport, and NFT Lately – which has elevated her to a senior role in crypto journalism. Whether crafting breaking news or in-depth reviews, she strives to engage her readers with the latest insights and information. Her articles often span the hottest cryptos, exchanges, and evolving regulations. As part of her ploy to attract crypto newbies into Web3, she explains even the most complex topics in an easily understandable and engaging way. Further underscoring her dynamic journalism background, she has written for various sectors, including software testing (TEST Magazine), travel (Travel Off Path), and music (Mixmag). When she’s not deep into a crypto rabbit hole, she’s probably island-hopping (with the Galapagos and Hainan being her go-to’s). Or perhaps sketching chalk pencil drawings while listening to the Pixies, her all-time favorite band. This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Center or Cookie Policy. I Agree Source: https://bitcoinist.com/banco-santander-and-snorter-token-crypto-services/
Share
BitcoinEthereumNews2025/09/17 23:45
Exclusive interview with Smokey The Bera, co-founder of Berachain: How the innovative PoL public chain solves the liquidity problem and may be launched in a few months

Exclusive interview with Smokey The Bera, co-founder of Berachain: How the innovative PoL public chain solves the liquidity problem and may be launched in a few months

Recently, PANews interviewed Smokey The Bera, co-founder of Berachain, to unravel the background of the establishment of this anonymous project, Berachain's PoL mechanism, the latest developments, and answered widely concerned topics such as airdrop expectations and new opportunities in the DeFi field.
Share
PANews2024/07/03 13:00
Top U.S. economist says Gold reversal is imminent

Top U.S. economist says Gold reversal is imminent

The post Top U.S. economist says Gold reversal is imminent appeared on BitcoinEthereumNews.com. Considering its traditional position as a ‘safe haven’ asset and
Share
BitcoinEthereumNews2026/04/02 18:10