Liquidation Heist: Breaking down the reUSD oracle manipulation attack
Last night an unknown wallet executed an oracle price manipulation attack which exposed highly levered looping trades in the PT-reUSD-10DEC2026/USDC Morpho market to be liquidated, resulting in $35,188,279 of liquidations and a net profit of $920,781 for the attacker. In this post I break down exactly what happened and what we can learn from it.
The Morpho Market Setup
In the last months, loopers have been flocking to a new form of yield arbitrage between reinsurance capital from Re (.xyz) and onchain borrow rates. The market which was attacked was the PT-reUSD-10DEC2026/USDC, which at it’s recent peak had $70m of borrows.
The primary use case for this market was to loop reUSD Pendle PTs, which were consistently earning about 10-11% fixed yield against the 8.8% average borrow rate in this market. At a Liquidation Loan-To-Value (LLTV) of 91.5%, loopers could lever up to 10.5 times and as a result achieve an annual yield of 34.6%. Since reUSD is a senior tranche reinsurance token, that is immediately redeemable onchain against a cash buffer the size of 50% of its supply (source: re docs) - the risk of holding reUSD is in theory fairly low from both a strategy and duration point of view, making it a suitable candidate for looping trades. As a result, this Morpho market attracted tons of borrowers and lenders (including vaults from Wintermute, Steakhouse, RockawayX, Clearstar, Keyrock - none of which lost any funds in this event).
The crucial kink in the armor of this trade from a loopers point of view, was the oracle configuration. It is configured as: PT/USDC price = min(Pendle 15-minute PT-to-USDC TWAP, 6% linear-discount curve). So it is the lower of either of the two rates: A linear discount model or a 15min time weighted average price (TWAP) of the PT denominated in USDC.
Steakhouse eloquently expressed the case for this design (which I agree with) as “generally good practice for Pendle oracles to mitigate the possibility of bad debt in the event of an impairment in the underlying asset. “ In practice, what this means is that if there is an impairment of the underlying reUSD, the oracle will pick this up. The alternative which many markets deploy is to hardcode the price with a time-decay curve which can result in bad debt if the underlying is impaired as we have seen multiple times in the past. Fundamentally, the design is a risk transfer from borrowers to lenders. The position becomes safer for lenders to underwrite, but exposes borrowers at extreme levels of leverage to liquidation in the event of even a small impairment of reUSD or the PT.
The attack
On Aug-25-2026 04:28:47 AM UTC a wallet (0x854e3f3b521dbae34cb111ebef0dce41d8b5690d) freshly funded with 1m$ from Gate, mints 1m$ worth of reUSD, converts it to Pendle SY reUSD and proceeds to use the funds to aggressively purchase YT-reUSD-10DEC2026, which has the consequence of roughly doubling the YT price from 0.029 to 0.0575, consequently dropping the PT side to to 0.9425 at the bottom (the Pendle chart below doesn’t show the true bottom).
Because borrower LTV ratios are calculated based on the value of the PTs as collateral, and these dropped in value by ~3%, this was sufficient to cause a cascade of liquidations. Liquidators earn a 2.616% incentive to perform liquidations in this event, which resulted in $920,781 in collected oracle bonuses.
The main liquidator contract (0x51a453d677396F62fbb1dff9925a205fa96fAB5e) was funded by the same Gate wallet at the same time as the oracle manipulator address, so we can safely assume this was the same actor.
Borrowers lost a total of $1,203,803 from the oracle bonus and liquidation at an unfavorable market rate. Because of relatively high rate of effective leverage, the equity losses amounted to approximately 30-40% for the affected borrowers (see img below).
The legality of this market operation is dubious at best. Given the funds came from a CEX at a relatively large size, it should be possible to trace the manipulation back to a specific entity. The legal precedence here is unclear, but this smells like crime.
Oracle design
The fundamental question this event raises is one of oracle design. Is it wise, to configure markets with 15 min TWAPs on thin liquidity, and support 70m$ of borrow capacity? I would argue the design is better than hardcoding oracles as many PT looping markets do, which has blown up for lenders more than once. A major challenge for borrowers is understanding the risks present in oracle design - which I believe as an ecosystem we need to do a better job at communicating. It is a wide and unstandardized design space, that is highly technical, which has huge implications on the risk for both borrowers and lenders. The devil, is truly in the detail. In this case, the oracle meant a risk transfer from lenders to borrowers. At the same time, borrowers are able to capture 34.6% yields at 10x leverage, so you might rightfully say “no wonder this comes at some risk!” - If you are levered to your tits and earning 30%+ yield, then you simply cannot cry in the casino.
I do think there is a fair critique to the oracle set-up in terms of it’s configuration compared to it’s design objectives. If the goal is to guard against impairment of reUSD - the oracle configuration should perhaps have some check against underlying impairment, before printing a lower value. This could balance both the needs of borrowers and lenders, without enabling this type of heist. Relying on Pendle secondary prices at a 15m TWAP, can be relatively easily manipulated, even with $30m+ of liquidity, as we saw today. At the same time, we cannot truly say the current design had a “bug”, in a sense the bug for the borrower is a feature for the lender.
Every blow-up is a chance to make the system itself more resilient, having spent a fair bit of time underwriting vault risk I think it is clear we have come quite far over the past year in terms of risk management and oracle configurations, but there is more work to be done. Onwards.
Give
@robdogeth to stay up to date on crypto and vault risk.