K

KeyAudit

· ·defi-exploit·private-key-leak·infrastructure·social-engineering

Edel Finance Exploited via Token Wrapping Flaw, $403K Bad Debt

Edel Finance paused its lending protocol after an attacker exploited the wrapping mechanism of tokenized Google stock (GOOGLx) to inflate collateral value by about 78 times, resulting in approximately $403,000 bad debt. The exploit did not involve faulty price oracles; Chainlink correctly reported Alphabet's share price. Instead, the attacker manipulated the exchange rate between GOOGLx and its wrapped version wGOOGLx, borrowing real assets against overvalued collateral. Edel stated that depositors will be fully compensated, and the team is deploying a redesigned version-two system to prevent similar attacks. A white-hat settlement has been offered to the attacker while coordinating with exchanges. This incident highlights price manipulation as a persistent DeFi vulnerability, especially in tokenized equities which add extra layers between assets and their prices.

Key facts

  • Attacker inflated wGOOGLx collateral value ~78x via wrapping mechanism manipulation.
  • Chainlink oracles correctly reported Google share price; exploit was in token conversion.
  • Edel Finance paused v1 lending, plans to absorb $403K bad debt for depositors.
  • White-hat settlement offered; team coordinating with exchanges.
  • Price manipulation remains a top DeFi vulnerability, per OWASP and CertiK.

← Back to list