Inverse Finance (Frontier/Anchor) hack — April 2022
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | April 2, 2022 |
| Target type | Lending protocol |
| Loss | $15,600,000Published estimates range $14,500,000 to $15,600,000Price at time of incident |
| Method | Oracle or price manipulationAnchor, the money market Inverse Finance later renamed Frontier, priced its own governance token INV using a time-weighted average price oracle. A window-size flaw meant the cumulative price observation only refreshed once a full period had elapsed; because roughly fifteen seconds separated the attacker's setup transaction from the attack transaction, the elapsed-time check failed and the oracle passed the manipulated spot price through unsmoothed. The attacker moved the INV price on SushiSwap with their own capital, deposited the temporarily overvalued INV as collateral, and borrowed against it. No flash loan was used and no bug existed in Inverse's own lending contracts. |
| Chains | Ethereum |
| Outcome | Users reimbursed |
What happened
On 2 April 2022 an attacker drained Inverse Finance's Anchor money market, the lending product the DAO later renamed Frontier, by manipulating the price feed for Inverse's own governance token, INV.
The attacker withdrew 901 ETH from Tornado Cash and pushed a rapid series of trades through the INV pools on SushiSwap. Anchor priced INV with a time-weighted average oracle, but a window-size bug meant the cumulative price observation only refreshed once a full period had elapsed. Because roughly fifteen seconds passed between the attacker's setup transaction and the attack transaction, that check failed and the oracle carried the manipulated spot price straight through, briefly valuing INV at $20,926. The attacker deposited the inflated INV as collateral and borrowed 1,588 ETH, 94 WBTC, 3,999,669 DOLA and 39 YFI. Inverse stressed that this was not a flash loan attack and that its own contract and front-end code were not at fault.
The headline figure is contested. Inverse Finance put the loss at $15.6 million in its own accounting; CertiK's independent reconstruction valued the borrowed assets at roughly $14.5 million. Most proceeds were cycled back through Tornado Cash and the attacker was never identified.
Inverse paused borrowing on Anchor, moved to a Chainlink-based INV oracle, and committed to repaying affected wallets in full without minting DOLA against its peg or paying compensation in INV. Repayment ran through governance-controlled Debt Converter and Debt Repayer contracts issuing DOLA IOUs against damaged anTokens, and has been gradual rather than immediate. Frontier was later sunsetted in favour of the fixed-rate FiRM market.
Sources
- Inverse FinancePrimary · retrieved 2026-08-01
- Inverse FinancePrimary · retrieved 2026-08-01
- CoinDeskSecondary · retrieved 2026-08-01
- CertiKSecondary · retrieved 2026-08-01
- The Record (Recorded Future News)Secondary · retrieved 2026-08-01
Official post-mortem: https://docs.inverse.finance/inverse-finance/inverse-finance/legacy-products/frontier-anchor.md
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Inverse Finance (Frontier/Anchor) hack — April 2022", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/inverse-finance-frontierhttps://itokenly.com/hacks/inverse-finance-frontierPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.