Vee Finance hack — September 2021
Incident facts
| Date of incident | (approximate) |
|---|---|
| Publicly disclosed | September 21, 2021 |
| Target type | Lending protocol |
| Loss | $35,000,000Published estimates range $34,000,000 to $35,000,000Price at time of incident |
| Method | Oracle or price manipulationSingle Pangolin price oracle manipulated, plus a token-decimals error that defeated slippage checks |
| Chains | Avalanche |
| Audited beforehand | SlowMist |
| Outcome | Unresolved |
What happened
Vee Finance, a lending and leveraged-trading protocol on Avalanche, was drained six days after its 14 September 2021 launch. The team announced on 21 September that it had detected abnormal transfers, paused all services, and lost 8,804.7 ETH and 213.93 BTC. CoinDesk and Decrypt valued those at roughly $26 million and $9 million respectively, about $35 million in total, while Halborn's later analysis put the loss at approximately $34 million. Stablecoin positions were not affected.
The protocol priced assets for its leveraged trading from a single source, the Pangolin decentralised exchange. The attacker created new trading pairs on Pangolin and traded between them, distorting the prices Vee Finance relied on. A second defect compounded it: Vee Finance's calculation of how much of one token could be received for another did not account for the tokens' decimal places. The false prices combined with that arithmetic error let the attacker pass slippage checks that should have rejected the trades, so the protocol approved leveraged positions it should have blocked and the pooled ETH and BTC could be withdrawn. A pre-launch audit by SlowMist had raised concerns about the protocol's use of oracles.
Vee Finance said on-chain monitoring showed the attacker had not moved the assets on, and publicly offered to treat the incident as a bug bounty, writing that it was willing to launch a bounty program for the bug identified and asking the attacker to make contact. It also approached auditors and exchanges to help trace the funds. No return of funds, recovery or arrest has been reported, and no attacker has been identified.
Sources
- CoinDeskSecondary · retrieved 2026-08-01
- DecryptSecondary · retrieved 2026-08-01
- HalbornSecondary · retrieved 2026-08-01
- CryptoSlateSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Vee Finance hack — September 2021", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/vee-financehttps://itokenly.com/hacks/vee-financePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.