
Security researchers said the attacker manipulated pricing linked to an ERC4626 vault and wGOOGLx collateral valuation, using a flash-loan-assisted donation attack to borrow and drain funds from the Aave Pool and protocol reserves.
Edel Finance was exploited for about $350,000 in an attack that manipulated how collateral was priced. CertiK Alert said the vulnerable mechanism tied wGOOGLx collateral pricing to its GOOGLx balance, while SlowMist said the protocol’s price source read an ERC4626 vault through latestAnswer() and convertToAssets() even though totalAssets() depended on the underlying asset balance. According to SlowMist, that design enabled a flash-loan-assisted donation attack that distorted oracle values, inflated collateral value and allowed the attacker to borrow funds and drain the Aave Pool and protocol reserves. Earlier reports put losses at about $204,000.