{"investigation":{"slug":"blueberry","entity_name":"BlueBerry Protocol","trust_score":32,"severity_base":null,"score_modifier":0,"confidence":0.78,"status":"published","content_type":"investigation","summary":"Blueberry Protocol is an Ethereum-based decentralized leveraged yield farming and prime brokerage protocol developed by Composable Corp. In February 2024, the protocol suffered a significant exploit caused by an oracle misconfiguration that allowed a flash loan attacker to drain approximately 457.7 ETH (~$1.35M) from three lending markets; most funds were rescued by white hat MEV operator c0ffeebabe.eth but ~91 ETH (~$265,000) was permanently lost to validator payments. Despite completing multiple Sherlock and Hacken audits and raising $2.5M in a June 2024 Series A, the protocol's security track record and history of audit findings raise material concerns for prospective users.","sections":[{"content":"On February 22, 2024 at approximately 08:36 UTC, borrowing functionality within Blueberry's new money market was activated prematurely — before the planned Monday launch of borrowing strategies. This window of exposure allowed an attacker to execute a flash loan attack on February 23, 2024 at approximately 02:22 UTC. The attacker initiated a flash loan of 1 WETH from Balancer and used the proceeds to drain liquidity from three lending markets: 8,616 OHM, 913,263 USDC, and 6.87 WBTC. In total, 457.684 ETH (approximately $1.35 million) was drained. The root cause was an oracle misconfiguration: the money market was using the PriceOracleProxy, which routes calls through the CoreOracle designed for Blueberry's strategy side. The CoreOracle always returns prices scaled to 18 decimals, causing assets with fewer than 18 decimals (such as WBTC and USDC) to be severely undervalued as collateral, enabling the attacker to borrow far more than should have been possible. MEV bot operator c0ffeebabe.eth — a pseudonymous white hat who had previously rescued $5.4M from the Curve Finance exploit in 2023 — detected the malicious transactions and front-ran the attacker, routing most of the drained funds to the Blueberry multisig. Of the 457.7 ETH drained, 366.6 ETH (~$1.08M) was recovered. Approximately 91 ETH (~$265,000) was permanently lost as a validator tip paid during the front-run process. Composable Corp paid c0ffeebabe.eth and collaborators a 10% bounty on recovered funds.","heading":"February 2024 Oracle Exploit","sources":[{"url":"https://medium.com/@blueberryprotocol/2-22-24-exploit-post-mortem-6f6be7c1dcc3","name":"medium.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/defi-protocol-blueberry-pauses-after-exploit","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://beincrypto.com/white-hat-saves-million-defi-exploit/","name":"beincrypto.com","type":"other","credibility":3},{"url":"https://www.web3isgoinggreat.com/single/blueberry-protocol-narrowly-avoids-1-3-million-hack","name":"web3isgoinggreat.com","type":"other","credibility":3},{"url":"https://cryptonews.com/news/blueberry-defi-protocol-suspends-lending-services-after-1-3m-exploit/","name":"cryptonews.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The post-mortem published by the Blueberry team confirmed that the exploit was not caused by a smart contract reentrancy bug in the classical sense, but by the deployment of an incorrect price oracle in the new money market module. The CoreOracle used for Blueberry's leveraged strategy side normalizes all asset prices to 18 decimal precision. When applied to assets such as WBTC (8 decimals) or USDC (6 decimals), the 18-decimal output caused those assets to appear dramatically undervalued when used as borrow collateral, enabling an attacker to borrow orders of magnitude more than the collateral warranted. The money market should have used a dedicated oracle that accounts for each asset's native decimal precision. This misconfiguration was introduced during the deployment of the new money market — a component separate from the protocol's previously audited strategy contracts — and was not caught before borrowing was enabled.","heading":"Oracle Misconfiguration Root Cause","sources":[{"url":"https://medium.com/@blueberryprotocol/2-22-24-exploit-post-mortem-6f6be7c1dcc3","name":"medium.com","type":"other","credibility":3},{"url":"https://www.web3isgoinggreat.com/single/blueberry-protocol-narrowly-avoids-1-3-million-hack","name":"web3isgoinggreat.com","type":"other","credibility":3},{"url":"https://bsc.news/post/defi-platform-blueberry-halts-operations-following-exploitation-attempt-what-happened","name":"bsc.news","type":"other","credibility":3}],"severity":"medium"},{"content":"c0ffeebabe.eth is a pseudonymous Ethereum MEV bot operator with an established history of front-running black hat exploits and returning funds to affected protocols. In August 2023, c0ffeebabe.eth recovered approximately $5.4 million from the Curve Finance exploit using similar MEV strategies. In the Blueberry incident, c0ffeebabe.eth detected the malicious flashloan transaction and submitted a competing transaction with a higher gas price, executing the same drain before the attacker's transaction could finalize. The rescued ETH was deposited directly into the Blueberry Foundation multisig wallet. Composable Corp subsequently paid a 10% bounty on the returned funds to c0ffeebabe.eth and their collaborators. The Blueberry Foundation publicly stated on X (formerly Twitter) that all affected lenders would be made 100% whole, with the residual 91 ETH validator loss to be covered by the team. The net permanent user loss was approximately $265,000.","heading":"c0ffeebabe.eth White Hat Intervention","sources":[{"url":"https://beincrypto.com/white-hat-saves-million-defi-exploit/","name":"beincrypto.com","type":"other","credibility":3},{"url":"https://medium.com/@blueberryprotocol/2-22-24-exploit-post-mortem-6f6be7c1dcc3","name":"medium.com","type":"other","credibility":3},{"url":"https://www.theblock.co/post/242136/mev-bot-runner-c0ffeebabe-eth-returns-5-4-million-amid-curve-exploit","name":"theblock.co","type":"other","credibility":3},{"url":"https://cryptonews.com/news/blueberry-defi-protocol-suspends-lending-services-after-1-3m-exploit/","name":"cryptonews.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Blueberry Protocol underwent multiple audits prior to the February 2024 exploit. Sherlock conducted at least four competitive audit contests between February and July 2023 (repositories: 2023-02-blueberry, 2023-04-blueberry, 2023-05-blueberry, 2023-07-blueberry). High-severity issues identified across these audits included: (1) ineffective transaction deadline checks allowing stale slippage parameters to be exploited; (2) no slippage protection on IchiVaultSpell withdrawals, creating conditions for sandwich attacks by MEV bots; (3) Balancer Pair Oracle LP price calculation underflow/overflow causing collateral valuation reverts; and (4) ConvexSpell liquidity removal without slippage protection. Hacken also performed a separate audit of the protocol, which identified oracle staleness as a concern — specifically that Chainlink price feed return values should be checked for staleness using the answeredInRound and updatedAt fields. Following the February 2024 exploit, the team paused the protocol and commissioned additional post-exploit audits from Spearbit, 0x52, and Cuthalion0x. These reviewers found that all high-severity issues in the core contracts were related to the oracle deployment error from the exploit — no additional high-severity vulnerabilities in user-fund-threatening areas were identified. The critical failure in February 2024 occurred in a money market module that was not part of the previously audited strategy contracts, highlighting a gap in audit scope coverage.","heading":"Audit History and Pre-Existing Vulnerabilities","sources":[{"url":"https://github.com/sherlock-audit/2023-02-blueberry-judging","name":"github.com","type":"other","credibility":3},{"url":"https://github.com/sherlock-audit/2023-07-blueberry-judging","name":"github.com","type":"other","credibility":3},{"url":"https://hacken.io/audits/blueberry-protocol/","name":"hacken.io","type":"other","credibility":3},{"url":"https://hackmd.io/@brainbot-services/recap_blueberry","name":"hackmd.io","type":"other","credibility":3},{"url":"https://medium.com/@blueberryprotocol/re-launch-security-update-49442502ec67","name":"medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the exploit, the Blueberry Foundation committed to making all affected lenders whole. Lenders in the three affected pools (BTC, OHM, and USDC markets) were repaid 100% of their losses from funds held in the team multisig. To further incentivize continued participation after relaunch, the community token allocation at the Token Generation Event (TGE) was increased from 5% to 10% of total BLB supply, with the additional 5% weighted toward users who had lent to Blueberry before the exploit and continued using the protocol post-relaunch. The TGE for the BLB governance token was structured as a lockdrop beginning January 29, 2024 (prior to the exploit) with an IDO from June 5–10, 2024, raising approximately $190,000 at $0.0194 per token. The overall community allocation across all distribution mechanisms was set at 55% of total supply.","heading":"User Compensation and Token Incentives","sources":[{"url":"https://medium.com/@blueberryprotocol/2-22-24-exploit-post-mortem-6f6be7c1dcc3","name":"medium.com","type":"other","credibility":3},{"url":"https://medium.com/@blueberryprotocol/blueberry-tokenomics-and-token-generation-event-lockdrop-airdrop-1ac267d30092","name":"medium.com","type":"other","credibility":3},{"url":"https://cryptorank.io/ico/blueberry-protocol","name":"cryptorank.io","type":"other","credibility":3},{"url":"https://www.binance.com/en/square/post/2024-02-24-blueberry-protocol-to-compensate-users-after-vulnerability-attack-4536854784242","name":"binance.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Blueberry Protocol was built by Composable Corp, a DeFi development company. Key personnel include CEO Jonathan Thomas and co-founder and CTO Bailey Spraggins. Investor Slater Heil, described in company materials as a commodities fund manager and DeFi fund operator, is identified as a founder on some databases (Crunchbase lists Arthur Wiseberg and Slater Heil as founders). Technical lead Alex Chon previously contributed to TrueFi and Platypus Finance. The company raised an initial $1.2M seed round followed by a $2.5M Series A in June 2024, led by White Star Capital with participation from Varys Capital, SNZ Capital, Alchemix DAO, Aquanow, GateCap Ventures, and others. The June 2024 Series A was closed approximately four months after the February exploit, suggesting investors assessed post-exploit remediation as acceptable. The company stated the Series A proceeds would be used for team expansion and increased security budget.","heading":"Team and Funding Background","sources":[{"url":"https://medium.com/@blueberryprotocol/team-behind-blueberry-raises-1-2m-to-enable-capital-efficient-borrowing-on-ethereum-f1aef0a25023","name":"medium.com","type":"other","credibility":3},{"url":"https://www.finsmes.com/2024/06/blueberry-protocol-raises-2-5m-series-a-funding.html","name":"finsmes.com","type":"other","credibility":3},{"url":"https://www.crunchbase.com/organization/blueberry-protocol","name":"crunchbase.com","type":"other","credibility":3},{"url":"https://www.linkedin.com/in/bailey-spraggins/","name":"linkedin.com","type":"other","credibility":3}],"severity":"medium"},{"content":"ZachXBT, the pseudonymous on-chain investigator with a documented track record of flagging DeFi exploits and scams, flagged Blueberry Protocol as a risk entity, which is the basis for the elevated concern score on this platform. The specific nature and timing of ZachXBT's flag has not been confirmed in publicly verifiable tier-1 or tier-2 sources retrieved for this investigation. The February 2024 exploit itself was widely reported across crypto media and represents an objectively verifiable security failure. No evidence of fraudulent intent, rug pull mechanics, or team misconduct was identified in available sources. The exploit appears to have resulted from operational negligence — specifically the premature activation of borrowing and the deployment of an incorrect oracle — rather than malicious team action. Community concern remains elevated due to the multiple pre-exploit audit findings that were not sufficient to prevent the oracle misconfiguration failure.","heading":"ZachXBT Flagging and Community Risk Signals","sources":[{"url":"https://www.web3isgoinggreat.com/single/blueberry-protocol-narrowly-avoids-1-3-million-hack","name":"web3isgoinggreat.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/defi-protocol-blueberry-pauses-after-exploit","name":"cointelegraph.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Blueberry Protocol (formerly presented under the Blueberry Garden brand) is a decentralized leveraged yield farming and prime brokerage platform on Ethereum mainnet. It allows users to supply collateral and borrow additional capital at up to 20x leverage to deploy into yield strategies such as Convex, ICHI Vault, and Aura Finance positions. The protocol's TVL stood at approximately $4.5 million before the February 2024 exploit and declined to roughly $3.15 million afterward — a drop of approximately 30%. The protocol targets sophisticated DeFi users comfortable with liquidation risk, smart contract risk, and oracle dependency risk. The leveraged nature of the product amplifies both gains and losses, and the February 2024 incident demonstrated that oracle misconfiguration in a leveraged environment can result in rapid and near-total drainage of lending pool liquidity. Post-relaunch security measures included replacing the faulty oracle with the correct implementation, adding HyperNative monitoring for on-chain anomaly detection, and conducting the Spearbit/0x52/Cuthalion0x review of core contracts.","heading":"Protocol Overview and Risk Profile","sources":[{"url":"https://defillama.com/protocol/blueberry","name":"defillama.com","type":"other","credibility":3},{"url":"https://v1.docs.blueberry.garden/","name":"v1.docs.blueberry.garden","type":"other","credibility":3},{"url":"https://medium.com/@blueberryprotocol/re-launch-security-update-49442502ec67","name":"medium.com","type":"other","credibility":3},{"url":"https://medium.com/@blueberryprotocol/blueberrys-security-first-approach-to-generalized-leverage-765c42dcd748","name":"medium.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2023-02","event":"Sherlock audit contest #1 (2023-02-blueberry) identifies high-severity issues including ineffective deadline checks and oracle staleness vulnerabilities.","source":"","date_original":"2023-02-01"},{"date":"2023-04","event":"Sherlock audit contest #2 (2023-04-blueberry) identifies sandwich attack risks in IchiVaultSpell and ConvexSpell withdrawals.","source":"","date_original":"2023-04-01"},{"date":"2023-05","event":"Sherlock audit contest #3 (2023-05-blueberry) conducted.","source":"","date_original":"2023-05-01"},{"date":"2023-07","event":"Sherlock audit contest #4 (2023-07-blueberry) conducted.","source":"","date_original":"2023-07-01"},{"date":"2024-01-29","event":"BLB token lockdrop campaign begins on Ethereum mainnet, offering 5% of total BLB supply to early lenders over a 56-day period.","source":""},{"date":"2024-02-22","event":"At 08:36 UTC, borrowing functionality in the new money market is activated prematurely — before the intended Monday launch of borrowing strategies. The money market is using CoreOracle, an incorrect oracle that prices assets with fewer than 18 decimals severely below market value.","source":""},{"date":"2024-02-23","event":"At 02:22 UTC, an attacker executes a flash loan attack using 1 WETH from Balancer, exploiting the oracle misconfiguration to drain 8,616 OHM, 913,263 USDC, and 6.87 WBTC across three lending markets, totaling 457.684 ETH (~$1.35M). c0ffeebabe.eth front-runs the attacker and routes 366.6 ETH to the Blueberry multisig. ~91 ETH is permanently lost to validator payments.","source":""},{"date":"2024-02-23","event":"Blueberry Protocol Foundation announces exploit on X (formerly Twitter), pauses all lending operations, and advises users to withdraw from lending markets.","source":""},{"date":"2024-02-24","event":"Blueberry Foundation publishes initial recovery statement committing to 100% repayment of affected lenders. Community TGE allocation increased from 5% to 10% of total supply as additional compensation for affected users.","source":""},{"date":"2024-02-25","event":"Post-mortem published confirming oracle misconfiguration as root cause. Composable Corp pays 10% bounty on recovered funds to c0ffeebabe.eth and collaborators.","source":""},{"date":"2024-03","event":"Post-exploit audits commissioned from Spearbit, 0x52, and Cuthalion0x. Results find no additional high-severity vulnerabilities threatening user funds beyond the oracle fix.","source":"","date_original":"2024-03-01"},{"date":"2024-06-04","event":"Blueberry Protocol raises $2.5M Series A funding led by White Star Capital, with participation from Varys Capital, SNZ Capital, Alchemix DAO, and others.","source":""},{"date":"2024-06-05","event":"BLB token IDO opens, running through June 10, 2024, raising approximately $190,000 at $0.0194 per BLB.","source":""}],"sources_used":[{"url":"https://medium.com/@blueberryprotocol/2-22-24-exploit-post-mortem-6f6be7c1dcc3","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://cointelegraph.com/news/defi-protocol-blueberry-pauses-after-exploit","name":"cointelegraph.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://beincrypto.com/white-hat-saves-million-defi-exploit/","name":"beincrypto.com","type":"other","archive_url":null,"credibility":3,"archive_error":"forbiddenaccess","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.web3isgoinggreat.com/single/blueberry-protocol-narrowly-avoids-1-3-million-hack","name":"web3isgoinggreat.com","type":"other","archive_url":"http://web.archive.org/web/20260207225149/https://www.web3isgoinggreat.com/single/blueberry-protocol-narrowly-avoids-1-3-million-hack","credibility":3,"archive_timestamp":"2026-02-07T22:51:49+00:00"},{"url":"https://cryptonews.com/news/blueberry-defi-protocol-suspends-lending-services-after-1-3m-exploit/","name":"cryptonews.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://bsc.news/post/defi-platform-blueberry-halts-operations-following-exploitation-attempt-what-happened","name":"bsc.news","type":"other","archive_url":null,"credibility":3,"archive_error":"error:gone","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.theblock.co/post/242136/mev-bot-runner-c0ffeebabe-eth-returns-5-4-million-amid-curve-exploit","name":"theblock.co","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://github.com/sherlock-audit/2023-02-blueberry-judging","name":"github.com","type":"other","archive_url":"http://web.archive.org/web/20260228031636/https://github.com/sherlock-audit/2023-02-blueberry-judging","credibility":3,"archive_timestamp":"2026-02-28T03:16:36+00:00"},{"url":"https://github.com/sherlock-audit/2023-07-blueberry-judging","name":"github.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://hacken.io/audits/blueberry-protocol/","name":"hacken.io","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://hackmd.io/@brainbot-services/recap_blueberry","name":"hackmd.io","type":"other","archive_url":"https://web.archive.org/web/20260830042810/https://hackmd.io/@brainbot-services/recap_blueberry","credibility":3,"archive_timestamp":"2026-08-30T04:28:10+00:00"},{"url":"https://medium.com/@blueberryprotocol/re-launch-security-update-49442502ec67","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://medium.com/@blueberryprotocol/blueberry-tokenomics-and-token-generation-event-lockdrop-airdrop-1ac267d30092","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://cryptorank.io/ico/blueberry-protocol","name":"cryptorank.io","type":"other","archive_url":"https://web.archive.org/web/20260829235529/https://cryptorank.io/ico/blueberry-protocol","credibility":3,"archive_timestamp":"2026-08-29T23:55:29+00:00"},{"url":"https://www.binance.com/en/square/post/2024-02-24-blueberry-protocol-to-compensate-users-after-vulnerability-attack-4536854784242","name":"binance.com","type":"other","archive_url":"https://web.archive.org/web/20260830044531/https://www.binance.com/en/square/post/2024-02-24-blueberry-protocol-to-compensate-users-after-vulnerability-attack-4536854784242","credibility":3,"archive_timestamp":"2026-08-30T04:45:31+00:00"},{"url":"https://medium.com/@blueberryprotocol/team-behind-blueberry-raises-1-2m-to-enable-capital-efficient-borrowing-on-ethereum-f1aef0a25023","name":"medium.com","type":"other","archive_url":"http://web.archive.org/web/20260421040105/https://medium.com/@blueberryprotocol/team-behind-blueberry-raises-1-2m-to-enable-capital-efficient-borrowing-on-ethereum-f1aef0a25023","credibility":3,"archive_timestamp":"2026-04-21T04:01:05+00:00"},{"url":"https://www.finsmes.com/2024/06/blueberry-protocol-raises-2-5m-series-a-funding.html","name":"finsmes.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.crunchbase.com/organization/blueberry-protocol","name":"crunchbase.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.linkedin.com/in/bailey-spraggins/","name":"linkedin.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://defillama.com/protocol/blueberry","name":"defillama.com","type":"other","archive_url":"http://web.archive.org/web/20251006144942/https://defillama.com/protocol/blueberry","credibility":3,"archive_timestamp":"2025-10-06T14:49:42+00:00"},{"url":"https://v1.docs.blueberry.garden/","name":"v1.docs.blueberry.garden","type":"other","archive_url":"http://web.archive.org/web/20260521170002/https://v1.docs.blueberry.garden/","credibility":3,"archive_timestamp":"2026-05-21T17:00:02+00:00"},{"url":"https://medium.com/@blueberryprotocol/blueberrys-security-first-approach-to-generalized-leverage-765c42dcd748","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:35.074655+00:00","updated_at":"2026-08-30T05:14:08.428226+00:00"}}