T
iTokenly

0VIX Protocol hack — April 2023

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedApril 28, 2023
Target typeLending protocol
Loss$4,330,000Published estimates range $2,000,000 to $4,330,000Price at time of incident
MethodOracle or price manipulationFlash-loan funded manipulation of the vGHST price oracle. 0VIX priced vGHST from the ratio of GHST held by the GotchiVault to the vault's outstanding shares, so the attacker donated 1.656M GHST directly with GHST.transfer(vault) instead of depositing through vault.enter(); no new shares were minted and the reported exchange rate rose from 1.03 to 1.78. That pushed a self-owned leveraged borrow position to 135% loan-to-value, and because liquidation incentives were a flat 10% (toxic threshold 90.9%), 24 consecutive self-liquidations made the position progressively more insolvent until all collateral was seized. Executed in one Polygon PoS transaction of 278 events at block 42054769.
ChainsPolygon
OutcomePartially recovered

What happened

On 28 April 2023 at 10:45 UTC an attacker drained the 0VIX lending protocol on Polygon PoS in a single transaction at block 42054769.

0VIX priced vGHST, a wrapper for staked Aavegotchi GHST, with an oracle that divided the GHST held by the GotchiVault by the vault's outstanding shares. After taking flash loans of 24.5M USDC, 6.15M USDT and 1.95M GHST from Aave and Balancer and building a large leveraged vGHST borrow position across two addresses, the attacker sent 1.656M GHST straight to the vault using GHST.transfer() rather than vault.enter(). Because no shares were minted, the reported exchange rate jumped from 1.03 to 1.78 and the borrow position's loan-to-value ratio rose to 135%. Liquidation incentives on 0VIX were a static 10%, so above a 90.9% LTV each liquidation left the position more insolvent rather than less. The attacker self-liquidated 24 times until all collateral was repossessed, leaving $6.46M of bad debt, then redeemed 23.765M USDC and 336k vGHST.

Published figures differ. Early reports based on on-chain data put the theft at roughly $2M. 0VIX's own post-mortem of 11 May 2023 calculated a net loss of $4.33M paid out of user funds, after accounting for $792k of swap slippage costs borne by the attacker and $735k of bad debt booked as protocol fees.

The proceeds left Polygon as 1,069 ETH bridged via Stargate and were deposited to Tornado Cash in three batches: 520 ETH immediately, 239 ETH the following day and the remaining 310 ETH on 9 May. 0VIX recovered an initial 206k vGHST following a GotchiVault DAO vote and later rebranded as Keom.

Law enforcement

0VIX Protocol Association said it was pursuing the investigation with law enforcement and security experts; no arrests reported.

Sources

  1. 0VIX / Keom (archived post-mortem)Primary · retrieved 2026-08-01
  2. CoinDeskSecondary · retrieved 2026-08-01
  3. DecryptSecondary · retrieved 2026-08-01
  4. QuillAuditsSecondary · retrieved 2026-08-01

Official post-mortem: https://web.archive.org/web/20231203033906/https://keomprotocol.medium.com/0vix-exploit-post-mortem-15c882dcf479

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "0VIX Protocol hack — April 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/0vix
https://itokenly.com/hacks/0vix

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.