Blueberry Protocol hack — February 2024
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | February 23, 2024 |
| Target type | Lending protocol |
| Loss | $1,300,000Price at time of incident |
| Recovered | $1,040,000 |
| Method | Contract logic errorFaulty oracle deployment rather than a flaw in the lending logic. The PriceOracleProxy routed to a CoreOracle that always returned prices scaled to 18 decimals, so assets with fewer decimals were drastically undervalued in borrow calculations. Borrowing had also been enabled unintentionally early. The attacker opened a Balancer flash loan of 1 WETH, deposited it into the lending market and borrowed against the mispriced collateral in the OHM, USDC and BTC markets. |
| Chains | Ethereum |
| Outcome | Users reimbursed |
What happened
Blueberry Protocol, an Ethereum leverage-lending protocol, was drained of 457.68 ETH, about $1.3 million, in the early hours of 23 February 2024. The cause was a misconfigured price oracle rather than a bug in the lending contracts: the protocol's PriceOracleProxy routed to a CoreOracle that always returned prices scaled to 18 decimals, so assets with fewer decimals were valued far below their real worth in borrow calculations. Borrowing had also been switched on unintentionally early, at 08:36 UTC on 22 February, roughly a day before the strategies it was meant to accompany.
At 02:22 UTC on 23 February an attacker opened a Balancer flash loan of 1 WETH, deposited it and borrowed against the mispriced collateral, targeting the OHM, USDC and BTC markets. The exploit was front-run by the MEV searcher operating c0ffeebabe.eth, which captured the drained funds. PeckShield first flagged the event publicly as an apparent front-run.
Of the 457.68 ETH removed, 366.65 ETH was returned to Blueberry's DAO multisig, roughly 80%, while about 91 ETH went to the block validator as a builder payment and was not recovered. OKLink's analysis notes the front-running address itself netted only around $409, with most of the extracted value going to the MEV builder. The team said it had engaged security professionals to approach the validator, and c0ffeebabe.eth received a 10% bounty on the returned amount.
Blueberry paused all contracts, said lenders in the affected pools would be made 100% whole, and stated the shortfall would be repaid from a Composable Corp multisig. Published dollar figures cluster around $1.3 million; the ETH amount is the firmer number.
Sources
- Blueberry & Bloom ProtocolsPrimary · retrieved 2026-08-01
- DailyCoinSecondary · retrieved 2026-08-01
- OKLinkSecondary · retrieved 2026-08-01
Official post-mortem: https://medium.com/@blueberryprotocol/2-22-24-exploit-post-mortem-6f6be7c1dcc3
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Blueberry Protocol hack — February 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/blueberry-protocolhttps://itokenly.com/hacks/blueberry-protocolPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.