Tender.fi hack — March 2023
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | March 7, 2023 |
| Target type | Lending protocol |
| Loss | $1,590,000Published estimates range $1,590,000 to $1,600,000Price at time of incident |
| Recovered | $1,493,000 |
| Method | Contract logic errorTender.fi had switched its GMX price feed to a Chainlink feed, and the adapter consuming it scaled the price incorrectly, multiplying by both 1e20 and 1e10 so the value returned by GMXPriceOracle.getUnderlyingPrice carried 38 decimals instead of 18. A single GMX token deposited as collateral was therefore credited with effectively unlimited borrowing power. The Chainlink feed itself was not at fault and no price was manipulated. |
| Chains | Arbitrum |
| Audited beforehand | PeckShield |
| Outcome | Settled as bug bounty |
What happened
On 7 March 2023 someone borrowed roughly $1.59 million from Tender.fi, an Arbitrum lending market, against a single GMX token worth about $70. Nothing was manipulated. The protocol had recently switched its GMX price feed to a Chainlink feed, and the adapter written to consume it scaled the price wrongly, multiplying it by both 1e20 and 1e10 so the value returned carried 38 decimals instead of 18. Anyone depositing GMX was credited with an absurd amount of collateral.
Numen Cyber's analysis of the transactions, which places the exploit at 08:21:38 UTC, lists the assets drawn down: about 198 ETH, 541,700 USDC, 16 WBTC, 50,011 DAI, 36,700 USDT, 24,975 FRAX, 16,203 LINK and 8,798 UNI. Tender.fi's code had been audited by PeckShield, and the fault lay in Tender.fi's own integration rather than in Chainlink's data.
The borrower left an on-chain message telling the team their oracle looked misconfigured and inviting contact, and negotiations followed. The funds were returned the same day, apart from 62.15 ETH, worth roughly $97,000 at the time, which Tender.fi agreed to leave as a bounty — around six per cent of the sum taken.
Reported figures vary slightly between $1.59 million and $1.6 million depending on the valuation used. CoinDesk valued the retained bounty at $850,000, which does not survive arithmetic: 62.15 ETH was worth roughly $97,000 in March 2023, consistent with The Block's $96,500. The exploiter was never identified and made no claim to any affiliation beyond acting as a white hat. Because the funds came back, the net cost to Tender.fi was the bounty itself.
Sources
- CoinDeskSecondary · retrieved 2026-08-01
- The BlockSecondary · retrieved 2026-08-01
- Numen Cyber LabsSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Tender.fi hack — March 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/tender-financehttps://itokenly.com/hacks/tender-financePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.