Cyrus Finance hack — March 2026
Incident facts
| Date of incident | (approximate) |
|---|---|
| Target type | Other |
| Loss | $520,000Published estimates range $512,000 to $525,000Price at time of incident |
| Method | Oracle or price manipulationThe CyrusTreasury contract sized liquidity withdrawals from its managed PancakeSwap V3 positions by reading sqrtPriceX96 directly from the pool's slot0, the instantaneous spot price in the current block, with no time-weighted average or external oracle. Using a flash loan of roughly 1,798 ETH the attacker swapped ETH into USDT to move the pool price, called the exit path so the position unwound almost entirely on the ETH side, then swapped back and repaid the loan within the same transaction. |
| Chains | BNB Chain |
| Outcome | Unresolved |
What happened
CyrusTreasury, the vault contract of the BNB Chain yield protocol Cyrus Finance, was exploited on or about 22 March 2026 in a single transaction. The contract managed PancakeSwap V3 liquidity positions. To decide how much liquidity to remove when a depositor exited, its withdrawUSDTFromAny path read sqrtPriceX96 straight from the pool's slot0, the live spot price in the current block, without a time-weighted average or an external price feed. The attacker took a flash loan of about 1,798 ETH, swapped it into USDT to push the pool price far out of line, then triggered the exit so the position was unwound almost entirely on the ETH side, swapped back to restore the price and repaid the loan. The vulnerable contract sat and the proceeds went. Two independent transaction-level analyses, by DarkNavy and by BlockSec, put the attacker's net gain at roughly 28.1 ETH plus about 454,000 USDT, or approximately $512,000 to $525,000. The two disagree on the calendar date: DarkNavy places the transaction on 22 March and publishes the transaction hash, while BlockSec dates the incident 23 March in its 23 to 29 March roundup. The date is recorded here as approximate for that reason. A much larger figure, around $5 million, circulates in third-party hack listings for this incident. No published analysis supports it, none of the listings show how it was derived, and it is an order of magnitude above what the transaction-level work shows, so it is not recorded here. No statement from the Cyrus Finance team has been published, no funds are known to have been returned, and the attacker has not been identified.
On-chain references
Published so the figures above can be checked against the chain rather than taken from us. Victim addresses are never listed.
Attacker addresses
- 0xb042ea7b35826e6e537a63bb9fc9fb06b50ae10b
- 0xf96eb14171b71ac16200013753dff3e91043b63b
Sources
- DarkNavySecondary · retrieved 2026-08-01
- BlockSecSecondary · retrieved 2026-08-01
- Smart Contract HackingAggregator · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Cyrus Finance hack — March 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/cyrus-financehttps://itokenly.com/hacks/cyrus-financePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.