Rho Markets hack — July 2024
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | July 19, 2024 |
| Target type | Lending protocol |
| Loss | $7,600,000Published estimates range $7,500,000 to $7,600,000Price at time of incident |
| Recovered | $7,600,000 |
| Method | Oracle or price manipulationOracle misconfiguration rather than active manipulation. At market initialisation the ETH price feed address was set to a WBTC/USD Chainlink feed, so the protocol valued ether at bitcoin's price, roughly 20 times too high. No contract code was vulnerable. An MEV bot detected the mispricing and repeatedly deposited overvalued collateral to borrow far more than it was worth; Dedaub documents one transaction depositing about 84 rETH and borrowing about 942 wstETH. |
| Chains | Other |
| Outcome | Funds returned |
What happened
Rho Markets, a lending protocol on the Scroll layer-2 network, had its USDC and USDT pools emptied of about $7.6 million on 19 July 2024. The cause was a configuration error rather than a contract bug. When the market was set up, the ETH price feed was pointed at a WBTC/USD Chainlink feed, so the protocol valued ether at bitcoin's price, roughly twenty times too high. Dedaub's analysis describes one transaction in which the exploiter deposited about 84 rETH as collateral and borrowed about 942 wstETH against it, then swapped it to ETH.
The extraction was carried out by an MEV bot that spotted the mispricing and repeated the trade. Dedaub puts the resulting bad debt at roughly $7.5 million, against the $7.6 million figure reported by Cyvers, the security firm that first flagged the incident. Scroll delayed chain finalisation while the incident was assessed, then confirmed it was confined to the Rho Markets application.
The operator of the bot contacted Rho on-chain, said the funds belonged to users and offered to return all of them on condition that Rho publicly describe the event as a misconfiguration on its own side rather than a hack or exploit. Rho did so, and about $7.6 million was transferred back roughly an hour later. Rho said no user funds were lost and reassigned the money to the affected borrow pools. Nobody was identified or charged.
Sources
- DedaubSecondary · retrieved 2026-08-01
- DecryptSecondary · retrieved 2026-08-01
- UnchainedSecondary · retrieved 2026-08-01
- CointelegraphSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Rho Markets hack — July 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/rho-marketshttps://itokenly.com/hacks/rho-marketsPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.