Levana Protocol hack — December 2023
Incident facts
| Date of incident | (approximate) |
|---|---|
| Publicly disclosed | December 27, 2023 |
| Target type | Decentralised exchange |
| Loss | $1,146,000Price at time of incident |
| Method | Oracle or price manipulationPyth price feeds were accepted with up to 120 seconds of staleness. A bug in the Osmosis fee-market code meant that during congestion the gas price Levana's bots paid was too low for price updates to land, and the attackers deliberately congested the chain. Positions could then be opened against a known-stale price and closed after the update at a guaranteed profit, extracted from the liquidity pools. |
| Chains | Other |
| Outcome | Project relaunched |
What happened
Levana ran perpetual swaps on the Osmosis chain. Between 13 and 26 December 2023 attackers extracted about $1.146 million from its liquidity pools, roughly 10% of pool funds, by trading against prices the protocol could not update.
Levana's post-mortem describes three components acting together: its Pyth price feeds tolerated up to 120 seconds of staleness; a bug in the Osmosis fee-market code meant that during congestion the gas price Levana's bots offered was generally insufficient for trades and maintenance to go through; and the attackers themselves congested the chain. With prices effectively frozen, a position could be opened at a stale price and closed after the next update at a guaranteed profit, with the difference paid out of the liquidity pools. Levana stated that the Pyth oracle itself was not vulnerable and behaved as expected.
About 4% of pool value went over the first twelve days and a further 5% on 26 December alone. Levana's own accounting attributes extraction across markets as stATOM-USD $241k, ATOM-USD $229k, BTC-USD $190k, ETH-USD $128k, TIA-USD $108k and about $250k across USDC pairs. Range, analysing the attack separately, identified nine addresses connected to the attack with links to centralised exchange accounts and described the attackers selectively submitting Wormhole price payloads to time updates.
Levana halted new positions and modifications, deployed a fix separating order placement from execution so a position's price is set in a later block, and relaunched after testnet validation. It set up a compensation programme for affected liquidity providers funded by token airdrops and by protocol fees collected during the attack window. The funds were not recovered and no actor has been identified. The Block reported the loss as over $1.1 million, consistent with Levana's figure.
Sources
- Levana ProtocolPrimary · retrieved 2026-08-01
- RangeSecondary · retrieved 2026-08-01
- The BlockSecondary · retrieved 2026-08-01
Official post-mortem: https://blog.levana.finance/levana-exploit-postmortem-df89a72cc92b
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Levana Protocol hack — December 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/levana-protocolhttps://itokenly.com/hacks/levana-protocolPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.