Oracle Manipulation & Price Attacks
Chainlink vs on-chain oracles, Uniswap V3 TWAPs, flash-loan price attacks, and the line of incidents from bZx to Mango Markets to Beanstalk.
40 min · expert · part of Smart Contract Security & Auditing
What you'll learn
- What Is an Oracle and Why Does It Break?
- Chainlink: The Dominant External Oracle
- On-Chain Oracles: Uniswap V2 vs V3 TWAPs
- The Flash-Loan Era: bZx, Harvest, Cream
- Mango Markets and Beanstalk: Two Sides of the Same Coin
- Modern Oracle Defenses
Key terms
- Oracle
- A system that brings external data (prices, events, off-chain state) to smart contracts. The single most common source of exploit losses in DeFi history because oracles introduce trust assumptions that are easy to break.
- Chainlink
- The dominant external price oracle network in DeFi. Decentralized node operators aggregate off-chain prices and commit median values on-chain. Strong against single-source manipulation but requires careful consumer-side staleness and sequencer-uptime checks.
- TWAP (Time-Weighted Average Price)
- An average price over a time window, designed to make single-block manipulation prohibitively expensive. Uniswap V3 TWAPs (via observe()) are the most common on-chain implementation; typical windows are 30 minutes or more.
- Flash-loan price manipulation
- Attack pattern where a flash loan provides whale-sized capital to move an on-chain price for one block, exploiting any protocol that reads that price as truth. Drained bZx (Feb 2020 ~$985K), Harvest (Oct 2020 ~$24M), Cream (Oct 2021 ~$130M), and many others.
- bZx incidents
- February 14-18, 2020 — two flash-loan oracle manipulation exploits totaling roughly $985K. The first large-scale public demonstration of flash-loan price attacks and the start of the modern oracle-design era.
- Harvest Finance hack
- October 26, 2020 — attacker used flash loans to manipulate the USDC/USDT ratio in Curve's y-pool, exploiting Harvest's use of the spot ratio for share pricing. Net loss: ~$24 million.
- Cream Finance hack (Oct 2021)
- October 27, 2021 — ~$130M exploit on Ethereum via flash-loan manipulation of yUSDVault share pricing, which Cream used as collateral valuation. One of the larger oracle-driven exploits in DeFi history.
- Mango Markets exploit
- October 11, 2022 — Avraham Eisenberg used ~$5M of his own collateral plus on-chain price pumping to inflate the MNGO oracle, borrowed ~$117M against the inflated position. Convicted of fraud in U.S. federal court in April 2024.
- Beanstalk governance attack
- April 17, 2022 — attacker took a ~$1 billion flash loan, used it to control governance for one block, executed a malicious upgrade draining the protocol, and repaid the loan in the same transaction. Net loss: ~$182 million. The canonical single-block governance attack.
- Sequencer uptime feed
- Chainlink-published feed on L2s (Arbitrum, Optimism, Base) indicating whether the sequencer is live. Consumers should refuse to operate using stale prices if the sequencer was recently offline.
Read the full lesson in the CryptoBipto app.
Open lessonEducational only — not financial advice.
