SlowMist Reveals Attackers Used Single Transaction to Liquidate Multiple BTCB Vaults
Attackers completed a combination operation in a single transaction by exploiting abnormally low oracle prices, liquidating multiple BTCB collateral vaults.
SlowMist pointed out that the vulnerability stemmed from the lack of price protection mechanisms and liquidation delays, allowing attackers to profit from oracle price deviations.
In market mechanisms, users of DeFi lending protocols became the main victims, with funds flowing from the attacked vaults to the attackers' addresses, putting pressure on liquidity providers and the protocol's TVL, while security audit firms and price oracle service providers benefited, exposing the systemic risks in decentralized finance during the price feeding process.
Source: Public Information
ABAB AI Insight
SlowMist has previously disclosed similar cases of oracle manipulation and liquidation attacks, such as in 2022 when multiple protocols suffered hundreds of millions in losses due to flash loans and price deviations, with attackers typically completing arbitrage through the atomicity of a single transaction.
In terms of capital pathways, attackers mobilize a small amount of capital to leverage the liquidity of lending pools, triggering chain liquidations through low-priced oracles, quickly transferring profits to new addresses. Their motivation lies in exploiting design flaws in protocol mechanisms to achieve risk-free or low-risk arbitrage, concentrating resources from normal users' collateral to a few attackers.
Comparing with historical DeFi hacking incidents like Mango Markets and Euler Finance, the current event shows that BTCB-related lending protocols are still in the early stages of inadequate security protections, lagging behind mature CeFi risk control systems.
Essentially, this represents a technological replacement and industrial chain reconstruction: decentralized oracles and automated liquidation logic are replacing traditional centralized risk control, with the mechanism amplifying the impact of price deviations through atomic execution of smart contracts, forcing protocol parties to invest more capital in building multi-source price protection and delay buffers, thus promoting the evolution of DeFi security infrastructure towards a more mature and capital-intensive direction.
ABAB News · Cognitive Laws
- The stronger the atomicity of a single transaction, the greater the amplification effect of protocol vulnerabilities.
- Lack of price protection = perfect hunting ground for liquidation delays; capital always chases the shortest path.
- In the early days of DeFi, security is the highest leverage; users pay for audits with TVL.