T
iTokenly

Lodestar Finance hack — December 2022

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedDecember 10, 2022
Target typeLending protocol
Loss$6,500,000Published estimates range $5,800,000 to $6,900,000Price at time of incident
MethodOracle or price manipulationLodestar's GLPOracle priced plvGLP from the assets-to-shares ratio of PlutusDAO's depositor contract. That ratio could be moved by anyone calling the contract's public donate() function, which adds GLP without minting shares. Backed by flash loans, the attacker built a large plvGLP position, called donate() to inflate the reported exchange rate, and borrowed out the protocol's remaining liquidity against the revalued collateral.
ChainsArbitrum, Ethereum
OutcomeUnresolved

What happened

Lodestar Finance, an Arbitrum lending protocol, was drained on 10 December 2022 after an attacker manipulated the price its oracle reported for plvGLP, a yield-bearing derivative of GMX's GLP token issued by PlutusDAO.

Lodestar's GLPOracle derived the plvGLP price from the ratio of assets to shares held in Plutus's depositor contract. That ratio could be moved by anyone calling the contract's public donate() function, which adds GLP without minting corresponding shares. CertiK's analysis describes the attacker using flash loans totalling about $70.5 million to build a large plvGLP position, then calling donate() to push the plvGLP exchange rate from about 1.07 to 1.82 GLP; Cointelegraph reported the manipulated rate as 1.83. With its collateral revalued upward, the position could borrow out essentially all remaining liquidity, leaving the protocol with bad debt.

Figures for what was actually taken differ. Lodestar said the attacker's profit was about $5.8 million and that roughly 2.8 million GLP, worth about $2.4 million, might be recoverable. CertiK put the attacker's profit at about $6.5 million and the protocol's own losses at over $6 million. Unchained recorded total value locked falling from $6.92 million to $11.07, a drop of about $6.9 million. Funds were bridged to Ethereum and split across three externally owned accounts, which Lodestar attempted to contact via DeBank.

Lodestar published a post-mortem, wound its interest rates to zero to freeze balances, and made a public white-hat offer: "If you are the hacker, reach out to us so we can find a white-hat agreement and move on." The attacker did not respond. PlutusDAO said its own contracts had worked as designed, that the exploit was "solely a result of Lodestar's oracle implementation, as proven by independent auditors", and apologised for having been "too eager to promote a protocol integrating plvGLP" without an audit; it said the surplus GLP left by the exploit would be used to reimburse affected Lodestar users, though completion of that reimbursement is not documented in any source located. No arrests have been reported.

Sources

  1. CertiKSecondary · retrieved 2026-08-01
  2. CointelegraphSecondary · retrieved 2026-08-01
  3. UnchainedSecondary · retrieved 2026-08-01
  4. PlutusDAOPrimary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Lodestar Finance hack — December 2022", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/lodestar-finance
https://itokenly.com/hacks/lodestar-finance

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.