T
iTokenly

Levana Protocol hack — December 2023

Verified — 3 sourcesLast checked August 1, 2026

Incident facts

Date of incident(approximate)
Publicly disclosedDecember 27, 2023
Target typeDecentralised exchange
Loss$1,146,000Price at time of incident
MethodOracle or price manipulationPyth price feeds were accepted with up to 120 seconds of staleness. A bug in the Osmosis fee-market code meant that during congestion the gas price Levana's bots paid was too low for price updates to land, and the attackers deliberately congested the chain. Positions could then be opened against a known-stale price and closed after the update at a guaranteed profit, extracted from the liquidity pools.
ChainsOther
OutcomeProject relaunched

What happened

Levana ran perpetual swaps on the Osmosis chain. Between 13 and 26 December 2023 attackers extracted about $1.146 million from its liquidity pools, roughly 10% of pool funds, by trading against prices the protocol could not update.

Levana's post-mortem describes three components acting together: its Pyth price feeds tolerated up to 120 seconds of staleness; a bug in the Osmosis fee-market code meant that during congestion the gas price Levana's bots offered was generally insufficient for trades and maintenance to go through; and the attackers themselves congested the chain. With prices effectively frozen, a position could be opened at a stale price and closed after the next update at a guaranteed profit, with the difference paid out of the liquidity pools. Levana stated that the Pyth oracle itself was not vulnerable and behaved as expected.

About 4% of pool value went over the first twelve days and a further 5% on 26 December alone. Levana's own accounting attributes extraction across markets as stATOM-USD $241k, ATOM-USD $229k, BTC-USD $190k, ETH-USD $128k, TIA-USD $108k and about $250k across USDC pairs. Range, analysing the attack separately, identified nine addresses connected to the attack with links to centralised exchange accounts and described the attackers selectively submitting Wormhole price payloads to time updates.

Levana halted new positions and modifications, deployed a fix separating order placement from execution so a position's price is set in a later block, and relaunched after testnet validation. It set up a compensation programme for affected liquidity providers funded by token airdrops and by protocol fees collected during the attack window. The funds were not recovered and no actor has been identified. The Block reported the loss as over $1.1 million, consistent with Levana's figure.

Sources

  1. Levana ProtocolPrimary · retrieved 2026-08-01
  2. RangeSecondary · retrieved 2026-08-01
  3. The BlockSecondary · retrieved 2026-08-01

Official post-mortem: https://blog.levana.finance/levana-exploit-postmortem-df89a72cc92b

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Levana Protocol hack — December 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/levana-protocol
https://itokenly.com/hacks/levana-protocol

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.