Vesper Finance hack — November 2021
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | November 2, 2021 |
| Target type | Lending protocol |
| Loss | $3,500,000Price at time of incident |
| Method | Oracle or price manipulationThe attacker cornered the Uniswap v3 VUSD/USDC 0.05% fee tier and opened a 0.1 USDC liquidity position priced at trillions of VUSD per USDC, so the Uniswap v3 oracle reported an astronomical VUSD price. The Fuse lending market read that feed, valued VUSD collateral as effectively infinite, and let the attacker borrow out every asset in the pool. |
| Chains | Ethereum |
| Outcome | Unresolved |
What happened
At approximately 14:00 UTC on 2 November 2021 an attacker emptied Vesper Lend beta, a lending market that Vesper Finance ran as pool #23 on Rari Capital's Fuse platform. Vesper's post-mortem says the attacker borrowed roughly $3.5 million in assorted assets against collateral the market had been tricked into valuing at infinity, and that 735 ETH of the proceeds sat in one address at the time of writing. Vesper never published a final accounting, so that figure remains the team's own approximation.
The mechanism was oracle manipulation, not a contract bug. According to Vesper, the attacker withdrew 100 ETH from Tornado Cash, swapped 58 ETH for USDC, and bought every VUSD available in the 0.05 percent fee tier of the Uniswap v3 VUSD market, pushing that tier out of range. They then opened a new liquidity position of 0.1 USDC marked at a price of trillions of VUSD per USDC. The Fuse market took its VUSD price from that Uniswap v3 tier, read the collateral as effectively unlimited, and allowed the attacker to borrow the pool dry. VUSD, a low-liquidity beta stablecoin, was the weak point.
Rari Capital publicly described it as an isolated incident of oracle manipulation on pool #23 and noted that Fuse's customisability leaves oracle choice to the pool deployer. Vesper paused borrowing of VUSD and vVSP, set VUSD's collateral factor to zero, and coordinated with Rari, Yearn and Uniswap. Its Grow and Earn pools were unaffected and the VUSD collateral system stayed solvent. Co-founder Jeff Garzik said the team hoped to make everyone whole but would not promise it pending a full accounting; vVSP holders could only withdraw as liquidity returned.
Sources
- Vesper FinancePrimary · retrieved 2026-08-01
- Vesper FinancePrimary · retrieved 2026-08-01
- Crypto Economy (carrying Rari Capital's statement)Secondary · retrieved 2026-08-01
- CoinCodeCapSecondary · retrieved 2026-08-01
Official post-mortem: https://medium.com/vesperfinance/on-the-vesper-lend-beta-rari-fuse-pool-23-exploit-9043ccd40ac9
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Vesper Finance hack — November 2021", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/vesper-financehttps://itokenly.com/hacks/vesper-financePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.