Loopscale hack — April 2025
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | April 26, 2025 |
| Target type | Lending protocol |
| Loss | $5,800,000Price at time of incident |
| Recovered | $5,800,000 |
| Method | Oracle or price manipulationLoopscale accepted RateX principal tokens as collateral but validated the RateX program only partially. The attacker deployed a program that imitated a legitimate RateX market interface and returned inflated PT exchange rates. Loopscale's collateral pricing accepted those values, so a series of loans that were in fact heavily undercollateralised passed its checks, letting the attacker withdraw far more from the USDC and SOL Genesis Vaults than they posted. |
| Chains | Solana |
| Audited beforehand | OShield (completed February 2025); Sec3 audit in progress. The exploited RateX integration code path had not been through third-party review. |
| Outcome | Funds returned |
What happened
Loopscale, a Solana lending protocol, was exploited on 26 April 2025, sixteen days after launch. Roughly $5.8 million left its Genesis vaults - 5,726,724.97 USDC and 1,211.4 SOL - about 12% of deposits, affecting 3,126 USDC depositors and 2,047 SOL depositors.
The protocol accepted RateX principal tokens as collateral but, as its post-mortem states, validated the RateX program only partially. The attacker deployed a malicious program that spoofed the interface of a valid RateX market and returned artificially inflated exchange rates. Loopscale's pricing logic accepted those values, so a series of loans that were in fact heavily undercollateralised passed its checks and the attacker withdrew far more than they had posted.
Loopscale froze new lending, restored repayments and loop closures the same evening, and offered the attacker a whitehat deal: retain a bounty of 10% of the funds - 3,947 SOL, about $594,000, against a total of roughly 39,500 SOL-equivalent - and a release from all liability. The attacker signalled a willingness to return the funds on 27 April. Returns began at 6:54 PM on 27 April and settled on 29 April between 7:16 and 7:33 PM. The post-mortem records the full 5,726,724.97 USDC and 1,211.4 SOL recovered and does not record any bounty being retained. Loopscale reimbursed a $29,000 discrepancy caused by the attacker having swapped USDC at less favourable rates, so no depositor lost money. Vault withdrawals were re-enabled on 8 May at 2:00 PM after additional code reviews.
The patch was reviewed by Sec3 and two further third-party auditors, and Loopscale said its ongoing Sec3 engagement covers the full program library. Citing the sensitivity of the investigation, it declined to comment further. The attacker has not been identified.
Law enforcement
Loopscale said it engaged law enforcement and security professionals, and declined to comment further on the investigation. No public case or charges.
Sources
- LoopscalePrimary · retrieved 2026-08-01
- The BlockSecondary · retrieved 2026-08-01
- The BlockSecondary · retrieved 2026-08-01
Official post-mortem: https://blog.loopscale.com/posts/postmortem
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Loopscale hack — April 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/loopscalehttps://itokenly.com/hacks/loopscalePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.