{"investigation":{"slug":"inverse-finance","entity_name":"Inverse Finance","trust_score":38,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"Inverse Finance is an Ethereum-based DeFi protocol known for its DOLA stablecoin and FiRM fixed-rate lending market, founded in late 2020 by Nour Haridy. The protocol suffered two oracle price manipulation exploits within two months in 2022 — the first in April for approximately $15.6 million and the second in June for a protocol loss of approximately $5.8 million — collectively representing one of the most significant serial oracle attack sequences in DeFi history. The protocol has since deprecated the vulnerable Anchor and Frontier lending markets, rebuilt on FiRM with Chainlink oracles, and undertaken a multi-year bad-debt repayment program.","sections":[{"content":"Inverse Finance was founded in late 2020 by Nour Haridy, a blockchain developer previously associated with Lamarkaz (Cairo's first blockchain lab), Mosendo, and Tykn B.V. The protocol launched around two primary products: the DOLA decentralized stablecoin, pegged to the US dollar and backed by overcollateralized assets, and the INV governance token, which allows holders to participate in DAO decision-making. The protocol initially offered the Anchor money market (later rebranded as Frontier) as its primary lending venue. Inverse Finance operates without a central legal entity, relying on the Inverse Finance DAO — comprising contributors and INV token holders — for governance decisions conducted largely via Snapshot off-chain voting. In December 2022, following the security incidents described below, the protocol launched FiRM (Fixed Rate Market), a redesigned lending protocol using a novel Personal Collateral Escrow architecture intended to isolate user funds and mitigate systemic oracle risk.","heading":"Protocol Background","sources":[{"url":"https://www.defipulse.com/blog/founder-fireside-chat-with-nour-haridy-of-inverse-finance","name":"defipulse.com","type":"other","credibility":3},{"url":"https://iq.wiki/wiki/nour-haridy","name":"iq.wiki","type":"other","credibility":3},{"url":"https://docs.inverse.finance/inverse-finance/inverse-finance/product-guide/firm","name":"docs.inverse.finance","type":"other","credibility":3}],"severity":"medium"},{"content":"On April 2, 2022 at approximately 11:04 AM UTC, an attacker exploited a critical vulnerability in the Keep3r TWAP (Time-Weighted Average Price) oracle used by Inverse Finance's Anchor money market to price the INV governance token. The oracle was designed with a 30-minute time window intended to prevent flash loan attacks; however, because only approximately 15 seconds elapsed between the attacker's price manipulation transaction and the borrowing transaction, the cumulative price update had not yet refreshed, allowing the manipulated price to propagate into collateral valuations. The attacker withdrew 901 ETH (approximately $2.7 million at the time) from the Tornado Cash mixer and used it to purchase INV on SushiSwap — swapping roughly 300 ETH for 374 INV — exploiting the shallow liquidity in the INV/ETH pair to spike the INV price to an artificial level of approximately $20,926. The attack was submitted as a transaction bundle directly to miners, bypassing the public mempool and preventing arbitrage bots from correcting the price before the borrowing step executed. Using the artificially inflated INV as collateral, the attacker borrowed 1,588 ETH, 94 WBTC, 3,999,669 DOLA, and 39 YFI, totalling approximately $15.6 million. The attacker's wallet address was identified as 0x8b4c1083cd6aef062298e1fa900df9832c8351b3. Inverse Finance immediately paused all borrowing on Anchor and announced it was working with Chainlink to build a replacement INV oracle. The protocol's DAO announced a commitment to repay 100% of affected wallets.","heading":"April 2022 Oracle Manipulation Exploit (~$15.6M)","sources":[{"url":"https://www.coindesk.com/tech/2022/04/02/defi-lender-inverse-finance-exploited-for-156-million","name":"coindesk.com","type":"other","credibility":3},{"url":"https://www.certik.com/resources/blog/inverse-finance-02-april-2022","name":"certik.com","type":"other","credibility":3},{"url":"https://therecord.media/more-than-15-million-stolen-after-hackers-exploit-defi-platform-inverse-finance","name":"therecord.media","type":"other","credibility":3},{"url":"https://medium.com/@RedStone_Finance/oracle-attacks-1-inverse-finance-15m-stolen-9fffb03d5171","name":"medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On June 16, 2022, Inverse Finance suffered a second oracle price manipulation attack, this time targeting the yvcrv3crypto market on the Frontier lending platform. The attacker obtained a flash loan of 27,000 Wrapped Bitcoin (wBTC) and traded it into Curve Finance's tricrypto pool, artificially inflating the price of the yvcrv3crypto LP token as reported by Inverse Finance's price oracle. Because Inverse's oracle estimated LP token value based on current asset balances within the pool — balances that the attacker could temporarily distort — the LP token appeared worth significantly more than its true value. The attacker used this inflated LP token as collateral to borrow a disproportionate amount of DOLA, the protocol's stablecoin. The attacker personally profited approximately $1.2–1.3 million; however, the protocol incurred a net bad-debt loss of approximately $5.8 million in DOLA that could not be recovered. According to blockchain analytics firm PeckShield, approximately 1,000 ETH of the illicit gains were deposited into Tornado Cash, with roughly 68 ETH remaining in the hacker's account at time of reporting. Inverse Finance paused borrowing on all Frontier platform assets, hired RiskDAO for security analysis, and publicly appealed to the attacker with an offer of a 'generous bounty' in exchange for returning the funds. No funds were returned. The second attack arriving just two months after the first drew significant criticism regarding the adequacy of the protocol's security response to the April incident, as the protocol had not undergone a comprehensive formal security audit between the two exploits.","heading":"June 2022 Oracle Manipulation Exploit (~$5.8M Protocol Loss)","sources":[{"url":"https://cryptoslate.com/inverse-finance-suffers-another-attack-hacker-steals-1-3-million-causes-5-8-million-protocol-loss/","name":"cryptoslate.com","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-inverse-finance-hack-june-2022","name":"halborn.com","type":"other","credibility":3},{"url":"https://www.certik.com/resources/blog/6LbL57WA3iMNm8zd7q111R-inverse-finance-incident-analysis","name":"certik.com","type":"other","credibility":3},{"url":"https://theregister.com/2022/06/17/inverse_finance_heist/","name":"theregister.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The two 2022 exploits left Inverse Finance carrying substantial bad debt — DOLA obligations that could not be repaid because the underlying collateral had been fraudulently borrowed against inflated valuations. As of October 2022, approximately $9.5 million in DOLA bad debt remained in the ecosystem. A further setback occurred on March 13, 2023, when Euler Finance — a separate DeFi lending protocol — was exploited for approximately $197 million in a flash loan attack; Inverse Finance held exposure to Euler, which contributed additional bad debt to its balance sheet. By the time DL News reported in July 2025, Inverse Finance had reduced its outstanding obligations to approximately $3.4 million from a peak exceeding $12 million. To accelerate repayment, on July 28, 2025, the protocol raised $2.6 million by selling 104,000 INV tokens to DeFi investors at 25 DOLA per token — tokens that were locked for six months and traded at a 72% premium above the sale price on the date of the transaction. Founder Nour Haridy described the action as fulfilling a 'moral obligation' to protect DOLA holders. The remaining $3.4 million was planned to be covered through borrowing from 40acres.finance. A transparency dashboard maintained at inverse.finance/transparency/bad-debts tracks the remaining obligations publicly.","heading":"Bad Debt, Euler Finance Exposure, and Recovery Efforts","sources":[{"url":"https://www.dlnews.com/articles/defi/inverse-finance-lures-defi-investors-to-plug-bad-debt/","name":"dlnews.com","type":"other","credibility":3},{"url":"https://finance.yahoo.com/news/inverse-finance-snags-2-6m-223633110.html","name":"finance.yahoo.com","type":"other","credibility":3},{"url":"https://therecord.media/cryptocurrency-heist-de-fi-euler","name":"therecord.media","type":"other","credibility":3},{"url":"https://www.inverse.finance/transparency/bad-debts","name":"inverse.finance","type":"other","credibility":3}],"severity":"medium"},{"content":"Both 2022 exploits shared a common root cause: Inverse Finance's reliance on on-chain TWAP oracles whose price windows could be manipulated by a sufficiently well-capitalized attacker. The April exploit abused the Keep3rV2Oracle, whose 30-minute TWAP window was effectively bypassed because the attack executed only 15 seconds after the price manipulation — the oracle had not yet updated the cumulative price. The June exploit abused a different oracle mechanism: one that estimated LP token value based on live asset balances within a Curve pool, which an attacker could temporarily distort through a large flash loan. Security researchers noted that the use of spot or short-window TWAP oracles for determining collateral values in lending markets is a recognized category of DeFi vulnerability. CertiK published post-mortems on both incidents. Following the April attack, Inverse Finance announced a migration to Chainlink Price Feeds for INV pricing. The FiRM protocol, launched December 2022, uses Chainlink oracles and was audited by Code4rena in October 2022. The protocol also established a bug bounty program on Immunefi. Halborn's post-mortem on the June attack noted the absence of a formal audit between the two incidents as a contributing factor to the second exploit.","heading":"Oracle Architecture and Security Failures","sources":[{"url":"https://www.certik.com/resources/blog/inverse-finance-02-april-2022","name":"certik.com","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-inverse-finance-hack-june-2022","name":"halborn.com","type":"other","credibility":3},{"url":"https://github.com/code-423n4/2022-10-inverse","name":"github.com","type":"other","credibility":3},{"url":"https://immunefi.com/bug-bounty/inversefinance/resources/","name":"immunefi.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the 2022 attacks, Inverse Finance deprecated both its Anchor and Frontier money markets and pivoted to the FiRM (Fixed Rate Market) protocol. FiRM introduces Personal Collateral Escrows, an architecture that keeps each user's collateral isolated rather than pooled, reducing the systemic risk of a single oracle manipulation affecting the entire protocol. DOLA continued to function as the protocol's stablecoin during the transition. By 2025, the protocol reported reaching $100 million in active loans on FiRM and had integrated Chainlink CCIP for cross-chain transfers of its yield-bearing sDOLA token. The INV token, which reached an all-time high of approximately $2,075 in March 2021, experienced severe price depreciation through 2022 coinciding with the exploits and broader crypto market conditions. DeFiLlama's TVL tracking and Inverse Finance's own transparency dashboards provide ongoing public visibility into protocol metrics. The protocol continues to operate under DAO governance with no disclosed central legal entity.","heading":"Protocol Restructuring and Current Status","sources":[{"url":"https://defillama.com/protocol/inverse-finance","name":"defillama.com","type":"other","credibility":3},{"url":"https://docs.inverse.finance/inverse-finance/inverse-finance/product-guide/firm","name":"docs.inverse.finance","type":"other","credibility":3},{"url":"https://www.chainlinkecosystem.com/ecosystem/inverse-finance","name":"chainlinkecosystem.com","type":"other","credibility":3},{"url":"https://www.dlnews.com/articles/defi/inverse-finance-lures-defi-investors-to-plug-bad-debt/","name":"dlnews.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2020-12","event":"Inverse Finance founded by Nour Haridy; initial products include the Anchor money market and DOLA stablecoin.","source":"","date_original":"2020-12-01"},{"date":"2021-03","event":"INV token reaches an all-time high of approximately $2,075.","source":"","date_original":"2021-03-01"},{"date":"2022-04-02","event":"First oracle manipulation exploit: attacker manipulates Keep3r TWAP oracle for INV/ETH on SushiSwap, borrows $15.6M in ETH, WBTC, YFI, and DOLA. Borrowing on Anchor immediately paused.","source":""},{"date":"2022-04-03","event":"Inverse Finance DAO proposes 100% repayment to affected wallets; announces migration to Chainlink oracle for INV pricing.","source":""},{"date":"2022-06-16","event":"Second oracle manipulation exploit: attacker uses 27,000 wBTC flash loan to inflate yvcrv3crypto LP token price on Frontier platform, causing $5.8M protocol loss with $1.2-1.3M directly stolen. Attacker deposits ~1,000 ETH to Tornado Cash.","source":""},{"date":"2022-06-17","event":"Inverse Finance pauses all Frontier borrowing, hires RiskDAO, issues public bounty appeal to attacker.","source":""},{"date":"2022-10","event":"Inverse Finance FiRM contracts audited via Code4rena competitive audit (code-423n4/2022-10-inverse).","source":"","date_original":"2022-10-01"},{"date":"2022-12-16","event":"FiRM (Fixed Rate Market) protocol launches on Ethereum mainnet with Chainlink oracles and Personal Collateral Escrow architecture.","source":""},{"date":"2023-03-13","event":"Euler Finance exploited for ~$197M; Inverse Finance's exposure to Euler contributes additional bad debt to the protocol's balance sheet.","source":""},{"date":"2025-07-28","event":"Inverse Finance raises $2.6M by selling 104,000 INV tokens to strategic DeFi investors at 25 DOLA each to accelerate bad-debt repayment, reducing remaining obligations to approximately $3.4M.","source":""}],"sources_used":[{"url":"https://www.defipulse.com/blog/founder-fireside-chat-with-nour-haridy-of-inverse-finance","name":"defipulse.com","type":"other","credibility":3},{"url":"https://iq.wiki/wiki/nour-haridy","name":"iq.wiki","type":"other","credibility":3},{"url":"https://docs.inverse.finance/inverse-finance/inverse-finance/product-guide/firm","name":"docs.inverse.finance","type":"other","credibility":3},{"url":"https://www.coindesk.com/tech/2022/04/02/defi-lender-inverse-finance-exploited-for-156-million","name":"coindesk.com","type":"other","credibility":3},{"url":"https://www.certik.com/resources/blog/inverse-finance-02-april-2022","name":"certik.com","type":"other","credibility":3},{"url":"https://therecord.media/more-than-15-million-stolen-after-hackers-exploit-defi-platform-inverse-finance","name":"therecord.media","type":"other","credibility":3},{"url":"https://medium.com/@RedStone_Finance/oracle-attacks-1-inverse-finance-15m-stolen-9fffb03d5171","name":"medium.com","type":"other","credibility":3},{"url":"https://cryptoslate.com/inverse-finance-suffers-another-attack-hacker-steals-1-3-million-causes-5-8-million-protocol-loss/","name":"cryptoslate.com","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-inverse-finance-hack-june-2022","name":"halborn.com","type":"other","credibility":3},{"url":"https://www.certik.com/resources/blog/6LbL57WA3iMNm8zd7q111R-inverse-finance-incident-analysis","name":"certik.com","type":"other","credibility":3},{"url":"https://theregister.com/2022/06/17/inverse_finance_heist/","name":"theregister.com","type":"other","credibility":3},{"url":"https://www.dlnews.com/articles/defi/inverse-finance-lures-defi-investors-to-plug-bad-debt/","name":"dlnews.com","type":"other","credibility":3},{"url":"https://finance.yahoo.com/news/inverse-finance-snags-2-6m-223633110.html","name":"finance.yahoo.com","type":"other","credibility":3},{"url":"https://therecord.media/cryptocurrency-heist-de-fi-euler","name":"therecord.media","type":"other","credibility":3},{"url":"https://www.inverse.finance/transparency/bad-debts","name":"inverse.finance","type":"other","credibility":3},{"url":"https://github.com/code-423n4/2022-10-inverse","name":"github.com","type":"other","credibility":3},{"url":"https://immunefi.com/bug-bounty/inversefinance/resources/","name":"immunefi.com","type":"other","credibility":3},{"url":"https://defillama.com/protocol/inverse-finance","name":"defillama.com","type":"other","credibility":3},{"url":"https://www.chainlinkecosystem.com/ecosystem/inverse-finance","name":"chainlinkecosystem.com","type":"other","credibility":3}],"source_tags":[],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-30T18:32:52.600663+00:00","updated_at":"2026-08-29T01:34:06.433+00:00"}}