/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Lending protocol Euler Finance lost $197M in a flash-loan attack, including $136M in stETH and $34M in USDC; Euler raised $32M in June 2022; EUL drops 45%+

Vishal Chawla / The Block :

The Block Vishal Chawla

Context & Ripple Effects

Euler Finance was one of DeFi's better-capitalized lending protocols — its $32M raise led by Haun Ventures in mid-2022 made it a flagship of the non-custodial lending category — which is what makes a single flash-loan attack draining $197M, mostly in stETH and USDC, such a sharp test of the sector. It also fits a grim lineage: Cream Finance lost an estimated $130M in a flash loan attack after two smaller hits the same year, and dForce's Lendf.Me was drained of ~$25M back in 2020.

What distinguishes the aftermath here is that the money came back: the attacker first sent ~$102M in ETH, then, per Euler, all recoverable funds were returned within weeks, with an apology visible on-chain. EUL still fell more than 45% before recovering 27% on the first return tranche — the market repriced the protocol faster than the negotiation resolved it.

First-order effects

  • Depositors in Euler's lending markets face immediate uncertainty over their positions while the protocol is paused, and EUL holders absorb a 45%+ drawdown that erased far more value than the $32M the treasury had raised.
  • The loss composition — $136M in stETH plus $34M in USDC — shows even blue-chip collateral pools are extractable at scale when the code layer fails.

Second-order effects

  • Every rival lending protocol now competes on audit depth and exploit response rather than yield, since depositors have watched Cream get hit three times and Euler once despite institutional backing.
  • The negotiated partial return sets up bounty dynamics as a de facto recovery channel, pressuring other exploited protocols to open talks with attackers instead of writing off losses.

Third-order effects

  • If negotiated returns keep replacing outright theft — Lendf.Me and Cream saw little come back; most of Euler's did — on-chain negotiation becomes a standard post-exploit playbook, softening headline losses but not the trust damage.
  • Recurring seven-figure losses across lending protocols regardless of funding quality point toward audits, formal verification, and possibly on-chain insurance becoming table stakes for any protocol holding depositor assets.

The trend: DeFi lending remains the sector's most-exploited attack surface, and the Euler episode marks a shift from irreversible losses toward negotiated, partially recovered exploits.

Discussion

  • @peckshield @peckshield on x
    Hi @eulerfinance: you may want to take a look: https://etherscan.io/...
  • @eulerfinance @eulerfinance on x
    We are aware and our team is currently working with security professionals and law enforcement. We will release further information as soon as we have it. https://twitter.com/...
  • @zachxbt @zachxbt on x
    @peckshield ... Almost certainly is blackhat as they were exploiting some random protocol on BSC a few weeks ago and then the funds deposited to Tornado https://etherscan.io/...
  • @pcaversaccio @pcaversaccio on x
    Euler finance was attacked via a flash loan: https://etherscan.io/.... We got around 8.9M DAI & 8.1k WETH loss. https://twitter.com/...
  • @peckshield @peckshield on x
    2/ The hack is made possible due to the flawed logic its donation and liquidation. Specifically, the donateToReserves needs to ensure the donator is still over-collateralized. And liquidation needs to ensure the *correct* conversion rate from borrow to collateral asset. https://t…