Raft Finance floats user bailout plan after odd exploit

An attacker stole 1,575 ETH from Raft, then burned 1,570 of it

article-image

Profit_Image/Shutterstock modified by Blockworks

share

Raft Finance experienced a severe security breach on Friday when a hacker managed to exploit a vulnerability in the protocol, resulting in the loss of approximately $3.3 million in ether.

The protocol originated as a fork of Liquity that replaced ether with staked ether as the collateral source backing its stablecoin, R. The exploit caused R to deviate from its intended $1 peg.

That prompted the team behind Raft to confirm the vulnerability and pause further minting to prevent additional losses​​​​.

According to a post-mortem blog post published Monday, the attacker was able to mint 6.7 million R, which was then swapped for 1,575 ether (ETH) causing R to de-peg.

Read more: Liquity aims to build on safety record with V2 using staked ether

In a surprising turn of events, the attacker then sent 1,570 ETH to a burn address, effectively removing it from circulation. This action left the hacker with only 7 ETH from the stolen funds.

Prior to the attack, the hacker’s address had received 18 ETH through a crypto mixer service, suggesting a level of premeditation and planning for the attack​​​​​​.

The circumstances of this attack are unusual, in that the large majority of the stolen funds were burned, leading to speculation about the attacker’s motives. The loss may have been accidental.

Loading Tweet..
Loading Tweet..

It’s not yet clear what comes next for the protocol and its users. Developers have promised an “in-depth recovery plan this week, outlining the steps to address the situation and provide redress for affected users,” the team said in its post-mortem statement.

“The Raft community will have the opportunity to provide feedback on the proposed recovery plan before it is concluded and the recovery plan is executed,” it said.

Raft issued a governance token (RAFT) in an airdrop on Oct. 11, intended to be staked to provide holders with voting rights over the protocol. The price of RAFT has plummeted about 60% since the exploit, per Coingecko.

Total value locked (TVL) in the protocol peaked in July at $64 million, and has been on a steady decline since, according to DefiLlama — just $1.48 million remains as of today.

Meanwhile, the formerly dollar-pegged stablecoin R is volatile with very limited liquidity on a handful of decentralized exchange markets. Although the developers have suspended the creation of new R tokens, users can still repay their R-related debts to retrieve collateral that is locked in the protocol.


Start your day with top crypto insights from David Canellis and Katherine Ross. Subscribe to the Empire newsletter.

Explore the growing intersection between crypto, macroeconomics, policy and finance with Ben Strack, Casey Wagner and Felix Jauvin. Subscribe to the Forward Guidance newsletter.

Get alpha directly in your inbox with the 0xResearch newsletter — market highlights, charts, degen trade ideas, governance updates, and more.

The Lightspeed newsletter is all things Solana, in your inbox, every day. Subscribe to daily Solana news from Jack Kubinec and Jeff Albus.

Tags

Upcoming Events

Javits Center North | 445 11th Ave

Tues - Thurs, March 18 - 20, 2025

Blockworks’ Digital Asset Summit (DAS) will feature conversations between the builders, allocators, and legislators who will shape the trajectory of the digital asset ecosystem in the US and abroad.

recent research

Unlocked by Template.jpg

Research

The BitcoinOS team is the first to have developed and posted a ZK-compressed proof on the Bitcoin network. Other proof verification efforts have been limited to the Signet or testnet deployments. Their work has resulted in the development of BitSNARK, a software library for ZK-compressed fraud proofs on the Bitcoin network. The project aims to provide a horizontal scaling solution, offering a one-stop shop for teams interested in developing a rollup on Bitcoin. This approach shares similarities with the horizontal tech stack scaling in other ecosystems like Cosmos and Optimism, particularly in its focus on simplified verification, bridging standards, and lightweight interoperability.

/

article-image

A16z’s State of Crypto report shows that DeFi has the largest number of daily active addresses, with stablecoins following closely behind

article-image

G2 is delivering real-world performance breakthroughs at 50-100 Mgas/s, Conduit says

article-image

World Liberty Financial’s token sale debuted just as an absurd AI-fueled memecoin captured crypto’s attention

article-image

Coinbase hired History Associates in 2023 to assist in retrieving records from the SEC and FDIC

article-image

Hours after pledging to support Black men’s rights to safely invest in crypto, VP Harris’s Monday night speech mentioned blockchain zero times