BonqDAO hack — February 2023
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | February 1, 2023 |
| Target type | Lending protocol |
| Loss | $1,600,000Published estimates range $1,200,000 to $120,000,000Price at time of incident |
| Method | Oracle or price manipulationBonqDAO consumed the latest value submitted to the permissionless Tellor oracle with no delay or averaging. The attacker staked the minimum TRB required to report, submitted a hugely inflated price for wrapped AllianceBlock (wALBT) to mint BEUR against negligible collateral, then submitted a near-zero price to force liquidation of other users' troves. Immunefi found a fresh reporter contract was deployed for each submission to bypass Tellor's reporting timelock. |
| Chains | Polygon |
| Outcome | Users reimbursed |
What happened
On 1 February 2023, at around 18:30 CET, the Polygon-based borrowing protocol BonqDAO was drained through manipulation of the Tellor price oracle it used for wrapped AllianceBlock (wALBT) collateral. Tellor's reporting is permissionless: anyone staking the minimum amount of TRB can submit a price. Because BonqDAO used the most recent submitted value with no delay or averaging, a submitted price took effect immediately.
The attacker submitted a hugely inflated wALBT price, opened a trove backed by a fraction of a token and minted roughly 100 million BEUR, BonqDAO's euro stablecoin. Minutes later they submitted a near-zero price, which pushed existing troves under water and let them liquidate around 113 million wALBT. Immunefi's analysis found the attacker deployed a fresh contract for each price submission in order to bypass Tellor's reporting timelock.
The headline numbers are notional. The roughly $120 million figure given in Immunefi's analysis, and the $88 million reported by The Block, value the minted BEUR and seized wALBT at pre-attack prices, and neither could be realised because the tokens had almost no liquidity. The Block reported the attacker sold roughly $1.2 million before liquidity ran out. AllianceBlock's founder said the actual damage involving ALBT was closer to $1.6 million than the amounts previously reported. CoinDesk described it as an exploit of about $5 million. This entry uses AllianceBlock's own accounting as the best estimate and records the full published spread as the bounds.
AllianceBlock paused its bridge, withdrew liquidity from exchanges and pools and asked venues to halt ALBT trading. It said it was developing a solution involving minting a new ALBT token and airdropping it to addresses holding legacy ALBT balances. No arrests have been reported.
Sources
- AllianceBlockPrimary · retrieved 2026-08-01
- The BlockSecondary · retrieved 2026-08-01
- CoinDeskSecondary · retrieved 2026-08-01
- ImmunefiSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "BonqDAO hack — February 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/bonqdaohttps://itokenly.com/hacks/bonqdaoPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.