DEUS Finance hack — April 2022
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | April 28, 2022 |
| Target type | Lending protocol |
| Loss | $13,400,000Published estimates range $13,400,000 to $15,700,000Price at time of incident |
| Method | Oracle or price manipulationDEUS's lending contracts priced its DEI stablecoin from the spot state of a USDC/DEI pool on Fantom rather than a manipulation-resistant feed. A flash loan of more than 143 million USDC was used to buy DEI and push the quoted price above the $1 peg; a small DEI deposit was then posted as collateral and about 17.2 million DEI borrowed against it, sold for USDC, and the flash loan repaid. |
| Chains | Fantom, Ethereum |
| Outcome | Unresolved |
What happened
At around 02:40 UTC on 28 April 2022 an attacker drained roughly $13.4 million from DEUS Finance's lending market on Fantom. It was the protocol's second exploit in six weeks; a similar attack on 15 March 2022 had cost about $3 million.
The attack turned on how DEUS priced its own stablecoin, DEI. The lending contracts read DEI's price from the spot state of a USDC/DEI pool rather than from a manipulation-resistant feed. The attacker took a flash loan of more than 143 million USDC, bought 9.5 million DEI with part of it — pushing the quoted price above the $1 peg — then posted a small amount of DEI as collateral (about 71,000 DEI, by CoinDesk's account) and borrowed roughly 17.2 million DEI against it. The borrowed DEI was sold for USDC, the flash loan repaid, and the surplus kept.
Loss estimates differ. PeckShield, which published the first analysis, put the take at $13.4 million; CertiK measured 5,446 ETH, about $15.7 million at the time. PeckShield also cautioned that the protocol's loss may have been larger than the attacker's profit. DEUS said in its initial statement that "all user funds are safe and that no users were liquidated" and that it had halted lending of the affected DEI markets, and The Record reported that DEI's peg was subsequently restored. A developer disputed the flash-loan framing, describing the incident instead as a zero-day involving the protocol's Solidly-based swaps and its Muon VWAP oracle: "the hack happening today absuing muon VWAP was clearly the first of its kind, a zero-day exploit on Solidly swaps."
The proceeds were bridged from Fantom to Ethereum and sent through Tornado Cash. No one has been charged and the funds were not recovered.
Sources
- CoinDeskSecondary · retrieved 2026-08-01
- The BlockSecondary · retrieved 2026-08-01
- The Record (Recorded Future News)Secondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "DEUS Finance hack — April 2022", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/deus-financehttps://itokenly.com/hacks/deus-financePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.