{"investigation":{"slug":"inverse-finance-frontier","entity_name":"Inverse Finance Frontier","trust_score":10,"severity_base":null,"score_modifier":0,"confidence":1,"status":"published","content_type":"investigation","summary":"Inverse Finance Frontier (originally called Anchor) was a variable-rate lending market on Ethereum operated by Inverse Finance DAO, founded by Nour Haridy in 2020. The protocol suffered two separate oracle manipulation exploits in 2022 — one in April resulting in $15.6 million in losses and a second in June resulting in $5.8 million in bad debt — both attributed to vulnerabilities in how Frontier priced collateral assets. The protocol is now deprecated in favor of Inverse Finance's FiRM fixed-rate market, and the DAO continues to work down residual bad debt from both incidents.","sections":[{"content":"Inverse Finance DAO was launched on the Ethereum blockchain in 2020 by founder Nour Haridy, who previously worked as a blockchain architect. The protocol combined money markets, a native stablecoin (DOLA), and synthetic assets under a product originally called Anchor. Anchor was later rebranded and expanded as Frontier, a variable-rate lending market that allowed users to supply and borrow a range of assets using collateral priced by on-chain oracles. Frontier accepted a wide array of collateral types, including Yearn Finance vault tokens and Curve LP tokens, which became central to both 2022 exploits. As of 2023, Frontier has been formally deprecated and marked as a legacy product in Inverse Finance documentation, with the DAO transitioning users to its newer FiRM fixed-rate lending platform.","heading":"Background","sources":[{"url":"https://www.defipulse.com/blog/founder-fireside-chat-with-nour-haridy-of-inverse-finance","name":"","type":"other","credibility":3},{"url":"https://docs.inverse.finance/inverse-finance/inverse-finance/other/frontier","name":"","type":"other","credibility":3},{"url":"https://www.gate.com/learn/articles/what-is-inverse-finance-all-you-need-to-know-about-inv/2654","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"On April 2, 2022, at approximately 11:04 AM UTC, Inverse Finance's Frontier lending market (then called Anchor) was exploited via oracle price manipulation, resulting in losses of approximately $15.6 million. The attacker funded the operation by withdrawing 901 ETH from Tornado Cash and distributed smaller amounts across 241 wallet addresses through the Disperse contract, deploying five smart contracts to execute the attack. The core vulnerability was Frontier's reliance on a Keep3rV2 TWAP (time-weighted average price) oracle that sourced INV token prices from the INV/ETH SushiSwap liquidity pool. This pool carried very low liquidity, making it susceptible to price manipulation with relatively modest capital. The attacker swapped approximately 500 ETH for 1,700 INV on SushiSwap, exploiting the thin liquidity to produce a roughly 50x price distortion, inflating the INV price to approximately $20,926 per token. Critically, the TWAP oracle used a 30-minute sampling window, but a logic error in the Keep3rV2Oracle contract allowed the manipulated price to be accepted after only 15 seconds because the condition 'timeElapsed > periodSize' was bypassed. The attacker also engaged in transaction spamming to control block ordering and prevent arbitrage corrections from normalizing the price. Using approximately 1,700 INV tokens (actual fair value around $644,000) as collateral against the inflated oracle price, the attacker borrowed $15.6 million in assets: 1,588 ETH, 94 WBTC, 39.3 YFI, and 3,999,669 DOLA. The attacker's address is 0x7b792e49f640676b3706d666075e903b3a4deec6, the malicious contract is 0xea0c959bbb7476ddd6cd4204bdee82b790aa1562, and the exploit transaction hash is 0x958236266991bc3fe3b77feaacea120f172c0708ad01c7a715b255f218f9313c. Stolen assets were liquidated and approximately 42 transactions of 100 ETH each were routed through Tornado Cash to obscure fund movement. Security researcher Bert Miller described it as 'one of the most MEV-aware hacks,' noting the attacker 'held an oracle's price at an insane level across multiple blocks' while preventing arbitrage corrections. In response, Inverse Finance paused all borrow markets, offered a bounty for return of funds, and announced plans to work with Chainlink on a new INV price oracle.","heading":"The April 2022 Exploit","sources":[{"url":"https://www.coindesk.com/tech/2022/04/02/defi-lender-inverse-finance-exploited-for-156-million","name":"","type":"other","credibility":3},{"url":"https://www.certik.com/resources/blog/inverse-finance-02-april-2022","name":"","type":"other","credibility":3},{"url":"https://rekt.news/inverse-finance-rekt","name":"","type":"other","credibility":3},{"url":"https://therecord.media/more-than-15-million-stolen-after-hackers-exploit-defi-platform-inverse-finance","name":"","type":"other","credibility":3},{"url":"https://etherscan.io/address/0x7b792e49f640676b3706d666075e903b3a4deec6","name":"","type":"other","credibility":3},{"url":"https://etherscan.io/tx/0xf694b1e1ebc257cdfe86c902b446252a57d4c3bb418a36da27df3a09f39eacd8","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"On June 16, 2022, at approximately 4:47 AM ET, Inverse Finance's Frontier platform was exploited a second time via a flash loan-assisted oracle manipulation attack. Although the attacker's direct profit was approximately $1.2–1.3 million, the protocol incurred $5.83 million in bad DOLA debt as a result. The targeted market was the yvcrv3crypto market, which accepted Yearn Finance's yvCRV3Crypto vault token (representing a position in Curve's WETH-USDT-WBTC tricrypto pool) as collateral. The oracle used for this market sourced price data from Chainlink's feed on the underlying Curve pool's asset balances — specifically the balance of assets within the pool rather than the pool's internal exchange rate mechanism. This design introduced a manipulable surface: by temporarily distorting the composition of the Curve tricrypto pool using a large flash loan, the attacker could cause the oracle to report a higher collateral value. The attacker flash-borrowed approximately 27,000 Wrapped Bitcoin (wBTC), worth approximately $579 million at the time, from the Aave lending protocol. A portion of the WBTC was added as liquidity to Curve's WETH-USDT-WBTC pool, producing LP tokens that were deposited into Yearn's vault. The resulting yvcrv3crypto tokens were used as collateral on Frontier. The remaining WBTC was then swapped for approximately 75 million USDT within the same Curve pool, dramatically skewing the pool's composition and causing the oracle to reflect an inflated collateral price. Against this artificially elevated collateral, the attacker borrowed approximately $10 million in DOLA from Frontier, far exceeding the legitimate collateral value. The attacker extracted approximately 53.244 WBTC (~$1.13 million) and 99,976 USDT, which were converted to approximately 1,068 ETH (~$1.26 million). Roughly 900–1,000 ETH were routed through Tornado Cash. PeckShield reported that approximately 68 ETH remained in the attacker's wallet. The attacker's exploiter contract address is reported as 0xf508c58ce37ce40a40997c715075172691f92e2d. The $5.83 million net loss to the protocol represents the bad DOLA debt created — funds that cannot be recovered from borrowers — rather than direct theft of user deposits. This incident was the second oracle-based exploit on Frontier within a two-month period, raising significant questions about the protocol's security review processes for adding new collateral types.","heading":"The June 2022 Exploit","sources":[{"url":"https://www.coindesk.com/tech/2022/06/16/defi-protocol-inverse-finance-exploited-for-12m","name":"","type":"other","credibility":3},{"url":"https://cryptoslate.com/inverse-finance-suffers-another-attack-hacker-steals-1-3-million-causes-5-8-million-protocol-loss/","name":"","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-inverse-finance-hack-june-2022","name":"","type":"other","credibility":3},{"url":"https://www.certik.com/resources/blog/6LbL57WA3iMNm8zd7q111R-inverse-finance-incident-analysis","name":"","type":"other","credibility":3},{"url":"https://www.theregister.com/2022/06/17/inverse_finance_heist/","name":"","type":"other","credibility":3},{"url":"https://blocksecteam.medium.com/price-oracle-manipulation-attack-on-inverse-finance-a5544218ea91","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Both exploits are fully verifiable on the Ethereum blockchain. For the April 2022 exploit, the attacker's primary address is 0x7b792e49f640676b3706d666075e903b3a4deec6, labeled 'Inverse Finance Exploiter' on Etherscan. The malicious contract deployed for the attack is 0xea0c959bbb7476ddd6cd4204bdee82b790aa1562. The exploit transaction hash is 0x958236266991bc3fe3b77feaacea120f172c0708ad01c7a715b255f218f9313c. On-chain records confirm that 73.5 ETH (approximately $250,000) remained in the attacker's original wallet at the time of reporting, while the majority of funds were routed through Tornado Cash in 42 separate transactions of 100 ETH each. The attacker's initial funding — 901 ETH — was sourced from Tornado Cash, demonstrating deliberate obfuscation both before and after the attack. For the June 2022 exploit, the exploiter contract is reported as 0xf508c58ce37ce40a40997c715075172691f92e2d. PeckShield on-chain analysis confirmed that approximately 68 ETH remained in the attacker's wallet post-exploit, while 1,000 ETH were deposited to Tornado Cash. Inverse Finance maintains a public Transparency page at inverse.finance/transparency/bad-debts that tracks the residual bad debt from both incidents, providing ongoing on-chain accountability for the protocol's outstanding liabilities.","heading":"On-Chain Evidence","sources":[{"url":"https://etherscan.io/address/0x7b792e49f640676b3706d666075e903b3a4deec6","name":"","type":"other","credibility":3},{"url":"https://etherscan.io/tx/0xf694b1e1ebc257cdfe86c902b446252a57d4c3bb418a36da27df3a09f39eacd8","name":"","type":"other","credibility":3},{"url":"https://www.certik.com/resources/blog/inverse-finance-02-april-2022","name":"","type":"other","credibility":3},{"url":"https://cryptoslate.com/inverse-finance-suffers-another-attack-hacker-steals-1-3-million-causes-5-8-million-protocol-loss/","name":"","type":"other","credibility":3},{"url":"https://www.inverse.finance/transparency/bad-debts","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the April 2022 exploit, Inverse Finance paused all borrow markets on Frontier and committed to a 100% compensation plan for affected users. The protocol proposed using anTokens to represent user claims on lost funds and established a Debt Converter and Debt Repayer mechanism to allow affected users to recover value over time. In 2023, Inverse Finance raised $2.6 million from DeFi investors by selling 104,000 INV tokens at 25 DOLA per token — a significant discount from the market price of approximately $43 at the time of the sale — with a six-month lock-up. The proceeds were applied directly toward the outstanding bad debt. Founder Nour Haridy characterized the repayment as 'an investment into the future' and 'a moral obligation towards people who trusted Dola with their hard earned money.' As of the DL News report, approximately $3.4 million in residual bad debt remained after the fundraise, with the protocol planning to address it via borrowing from the 40acres.finance lending protocol. The Euler Finance hack in March 2023 added a further tranche of bad debt to Inverse Finance's obligations, compounding the recovery challenge. The DAO continued to direct protocol revenue and reserve allocations toward bad debt repayment through multiple on-chain governance proposals. The broader Inverse Finance ecosystem pivoted to FiRM, its fixed-rate lending platform, which reached $100 million in total loans — a milestone cited as evidence of protocol recovery momentum.","heading":"Recovery","sources":[{"url":"https://www.dlnews.com/articles/defi/inverse-finance-lures-defi-investors-to-plug-bad-debt/","name":"","type":"other","credibility":3},{"url":"https://www.inverse.finance/governance/proposals/mills/159","name":"","type":"other","credibility":3},{"url":"https://www.inverse.finance/transparency/bad-debts","name":"","type":"other","credibility":3},{"url":"https://therecord.media/more-than-15-million-stolen-after-hackers-exploit-defi-platform-inverse-finance","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Inverse Finance Frontier presents extreme historical risk. The protocol suffered two confirmed oracle manipulation exploits within 76 days in 2022, resulting in a combined realized loss to the protocol of approximately $21.4 million ($15.6 million in April and $5.83 million in bad DOLA debt in June). Both attacks exploited the same fundamental class of vulnerability: the use of manipulable on-chain price sources — a low-liquidity SushiSwap TWAP in April and a Chainlink feed based on pool balances in June — rather than robust, manipulation-resistant oracles. The April attack further exposed a logic error in the Keep3rV2Oracle contract that allowed the 30-minute TWAP to be bypassed after only 15 seconds. The recurrence of a structurally similar vulnerability within two months suggests insufficient security review processes at the time of the second incident. Both attackers routed funds through Tornado Cash, and neither has been publicly identified or held legally accountable. No regulatory or law enforcement actions against Inverse Finance or the attackers have been publicly reported. Frontier is now deprecated, reducing direct user exposure going forward. However, residual bad debt from both exploits continues to weigh on the DOLA stablecoin and the Inverse Finance DAO's treasury. Users who held positions on Frontier at the time of either exploit may still hold outstanding claims through the Debt Converter and Debt Repayer mechanisms. Any user considering DOLA or the broader Inverse Finance ecosystem should factor the unresolved bad debt obligations into their risk assessment.","heading":"Risk Assessment","sources":[{"url":"https://www.coindesk.com/tech/2022/04/02/defi-lender-inverse-finance-exploited-for-156-million","name":"","type":"other","credibility":3},{"url":"https://www.coindesk.com/tech/2022/06/16/defi-protocol-inverse-finance-exploited-for-12m","name":"","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-inverse-finance-hack-june-2022","name":"","type":"other","credibility":3},{"url":"https://www.dlnews.com/articles/defi/inverse-finance-lures-defi-investors-to-plug-bad-debt/","name":"","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2020","event":"Inverse Finance DAO launched on Ethereum by founder Nour Haridy, introducing the Anchor money market and the DOLA stablecoin.","source":"","date_original":"2020-01-01"},{"date":"2022-04-02","event":"April 2022 exploit: attacker manipulates the Keep3rV2 TWAP oracle via low-liquidity INV/ETH SushiSwap pool, inflating INV price ~50x and borrowing $15.6 million in ETH, WBTC, YFI, and DOLA. Funds routed through Tornado Cash. Borrow markets paused.","source":""},{"date":"2022-04-02","event":"Inverse Finance announces 100% compensation commitment for affected users and plans to integrate Chainlink oracle for INV pricing.","source":""},{"date":"2022-06-16","event":"June 2022 exploit: attacker uses a 27,000 WBTC flash loan from Aave to manipulate the Curve tricrypto pool balance oracle for the yvcrv3crypto market, borrowing ~$10 million in DOLA against inflated collateral. Protocol incurs $5.83 million in bad debt; attacker nets ~$1.26 million.","source":""},{"date":"2022-10-28","event":"Inverse Finance reports recovery of 6.5 million DOLA in bad debt repayment through protocol revenue and reserves.","source":""},{"date":"2023-03","event":"Euler Finance hack adds additional bad debt obligations to the Inverse Finance DAO.","source":"","date_original":"2023-03-01"},{"date":"2023-09","event":"Inverse Finance raises $2.6 million by selling 104,000 INV tokens at 25 DOLA per token to DeFi investors, applied toward bad debt repayment. Approximately $3.4 million in bad debt remains outstanding.","source":"","date_original":"2023-09-01"},{"date":"2023","event":"Frontier formally deprecated in Inverse Finance documentation; DAO transitions to FiRM fixed-rate lending platform.","source":"","date_original":"2023-01-01"}],"sources_used":[{"url":"https://www.defipulse.com/blog/founder-fireside-chat-with-nour-haridy-of-inverse-finance","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://docs.inverse.finance/inverse-finance/inverse-finance/other/frontier","name":"","type":"other","archive_url":"http://web.archive.org/web/20260113193218/https://docs.inverse.finance/inverse-finance/inverse-finance/other/frontier","credibility":3,"archive_timestamp":"2026-01-13T19:32:18+00:00"},{"url":"https://www.gate.com/learn/articles/what-is-inverse-finance-all-you-need-to-know-about-inv/2654","name":"","type":"other","archive_url":"https://web.archive.org/web/20260829151914/https://www.gate.com/learn/articles/what-is-inverse-finance-all-you-need-to-know-about-inv/2654","credibility":3,"archive_timestamp":"2026-08-29T15:19:14+00:00"},{"url":"https://www.coindesk.com/tech/2022/04/02/defi-lender-inverse-finance-exploited-for-156-million","name":"","type":"other","archive_url":"http://web.archive.org/web/20251202204609/https://www.coindesk.com/tech/2022/04/02/defi-lender-inverse-finance-exploited-for-156-million","credibility":3,"archive_timestamp":"2025-12-02T20:46:09+00:00"},{"url":"https://www.certik.com/resources/blog/inverse-finance-02-april-2022","name":"","type":"other","archive_url":"http://web.archive.org/web/20251016165118/https://www.certik.com/resources/blog/inverse-finance-02-april-2022","credibility":3,"archive_timestamp":"2025-10-16T16:51:18+00:00"},{"url":"https://rekt.news/inverse-finance-rekt","name":"","type":"other","archive_url":"http://web.archive.org/web/20260513155140/https://rekt.news/inverse-finance-rekt","credibility":3,"archive_timestamp":"2026-05-13T15:51:40+00:00"},{"url":"https://therecord.media/more-than-15-million-stolen-after-hackers-exploit-defi-platform-inverse-finance","name":"","type":"other","archive_url":"http://web.archive.org/web/20260608144825/https://therecord.media/more-than-15-million-stolen-after-hackers-exploit-defi-platform-inverse-finance","credibility":3,"archive_timestamp":"2026-06-08T14:48:25+00:00"},{"url":"https://etherscan.io/address/0x7b792e49f640676b3706d666075e903b3a4deec6","name":"","type":"other","archive_url":"https://web.archive.org/web/20260830121739/https://etherscan.io/address/0x7b792e49f640676b3706d666075e903b3a4deec6","credibility":3,"archive_timestamp":"2026-08-30T12:17:39+00:00"},{"url":"https://etherscan.io/tx/0xf694b1e1ebc257cdfe86c902b446252a57d4c3bb418a36da27df3a09f39eacd8","name":"","type":"other","archive_url":"https://web.archive.org/web/20260830160642/https://etherscan.io/tx/0xf694b1e1ebc257cdfe86c902b446252a57d4c3bb418a36da27df3a09f39eacd8","credibility":3,"archive_timestamp":"2026-08-30T16:06:42+00:00"},{"url":"https://www.coindesk.com/tech/2022/06/16/defi-protocol-inverse-finance-exploited-for-12m","name":"","type":"other","archive_url":"https://web.archive.org/web/20260915174520/https://www.coindesk.com/tech/2022/06/16/defi-protocol-inverse-finance-exploited-for-12m","credibility":3,"archive_timestamp":"2026-09-15T17:45:20+00:00"},{"url":"https://cryptoslate.com/inverse-finance-suffers-another-attack-hacker-steals-1-3-million-causes-5-8-million-protocol-loss/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260313043702/https://cryptoslate.com/inverse-finance-suffers-another-attack-hacker-steals-1-3-million-causes-5-8-million-protocol-loss/","credibility":3,"archive_timestamp":"2026-03-13T04:37:02+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-inverse-finance-hack-june-2022","name":"","type":"other","archive_url":"http://web.archive.org/web/20260207103312/https://www.halborn.com/blog/post/explained-the-inverse-finance-hack-june-2022","credibility":3,"archive_timestamp":"2026-02-07T10:33:12+00:00"},{"url":"https://www.certik.com/resources/blog/6LbL57WA3iMNm8zd7q111R-inverse-finance-incident-analysis","name":"","type":"other","archive_url":"https://web.archive.org/web/20260829185321/https://www.certik.com/blog/6LbL57WA3iMNm8zd7q111R-inverse-finance-incident-analysis","credibility":3,"archive_timestamp":"2026-08-29T18:53:21+00:00"},{"url":"https://www.theregister.com/2022/06/17/inverse_finance_heist/","name":"","type":"other","archive_url":"http://web.archive.org/web/20251208172242/https://www.theregister.com/2022/06/17/inverse_finance_heist/","credibility":3,"archive_timestamp":"2025-12-08T17:22:42+00:00"},{"url":"https://blocksecteam.medium.com/price-oracle-manipulation-attack-on-inverse-finance-a5544218ea91","name":"","type":"other","archive_url":"http://web.archive.org/web/20260725123146/https://blocksecteam.medium.com/price-oracle-manipulation-attack-on-inverse-finance-a5544218ea91","credibility":3,"archive_timestamp":"2026-07-25T12:31:46+00:00"},{"url":"https://www.inverse.finance/transparency/bad-debts","name":"","type":"other","archive_url":"http://web.archive.org/web/20260520160416/https://www.inverse.finance/transparency/bad-debts","credibility":3,"archive_timestamp":"2026-05-20T16:04:16+00:00"},{"url":"https://www.dlnews.com/articles/defi/inverse-finance-lures-defi-investors-to-plug-bad-debt/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260617134306/https://www.dlnews.com/articles/defi/inverse-finance-lures-defi-investors-to-plug-bad-debt/","credibility":3,"archive_timestamp":"2026-06-17T13:43:06+00:00"},{"url":"https://www.inverse.finance/governance/proposals/mills/159","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:50.190709+00:00","updated_at":"2026-09-15T17:57:07.927653+00:00"}}