{"investigation":{"slug":"lodestar-v0","entity_name":"Lodestar V0","trust_score":22,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"Lodestar V0 is the original deployment of Lodestar Finance, an algorithmic money market lending protocol on Arbitrum. On December 10, 2022, the protocol suffered a critical flash loan exploit in which an attacker manipulated the plvGLP price oracle to drain approximately $6.9 million in user funds. The protocol was subsequently relaunched as Lodestar V1 in July 2023; V0 remains abandoned with negligible TVL (~$95K) and the attacker was never publicly identified.","sections":[{"content":"Lodestar V0 was an algorithmic money market protocol deployed on the Arbitrum Layer 2 network. It allowed users to supply and borrow crypto assets including USDC, ETH, wBTC, GMX, and PlutusDAO's plvGLP token. The protocol used a Compound-style architecture with tiered interest rate models. The LODE governance token, with a total supply of 20 million, governed the protocol. Lodestar V0 is the original version of the platform; following the December 2022 exploit, the team relaunched as Lodestar V1 in July 2023.","heading":"Protocol Overview","sources":[{"url":"https://iq.wiki/wiki/lodestar-finance","name":"iq.wiki","type":"other","credibility":3},{"url":"https://docs.lodestarfinance.io/","name":"docs.lodestarfinance.io","type":"other","credibility":3}],"severity":"medium"},{"content":"On December 10, 2022, Lodestar V0 suffered a critical flash loan oracle manipulation attack resulting in the loss of approximately $6.5–6.9 million in user funds. The attacker secured eight flash loans totaling roughly $70.5 million in USDC, WETH, and DAI. The core vulnerability resided in the protocol's GLPOracle, which calculated the price of PlutusDAO's plvGLP token using a formula that could be manipulated via PlutusDAO's donate() function. By calling donate() on the GlpDepositor contract, the attacker staked GLP assets into the plvGLP vault without minting new plvGLP tokens, causing the contract's reported AUM to increase without a corresponding increase in token supply. This inflated the plvGLP-to-GLP exchange rate from approximately 1.07 to 1.83. The attacker then supplied the overvalued plvGLP as collateral on Lodestar and borrowed nearly all available protocol liquidity. After repaying the flash loans, the attacker netted approximately $5.8 million in profit. Roughly 2.8 million GLP (worth approximately $2.4 million) remained recoverable in the plvGLP vault. PlutusDAO, whose token was used in the attack, stated publicly that the exploit was solely a result of Lodestar's oracle implementation, not a vulnerability in the plvGLP contract itself.","heading":"December 2022 Flash Loan Exploit","sources":[{"url":"https://www.certik.com/resources/blog/TqTyq4vYHl8JzS7zyJye9-lodestar-finance-incident-analysis","name":"certik.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/lodestar-finance-exploited-in-flash-loan-attack","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-lodestar-finance-hack-november-2022","name":"halborn.com","type":"other","credibility":3},{"url":"https://medium.com/@plutus.fi/official-statement-on-the-lodestar-finance-exploit-cf2b501647f5","name":"medium.com","type":"other","credibility":3},{"url":"https://web3isgoinggreat.com/single/lodestar-finance-attacked","name":"web3isgoinggreat.com","type":"other","credibility":3}],"severity":"medium"},{"content":"CertiK and other security researchers noted that the Lodestar V0 exploit closely mirrored the attack methodology used against Mango Markets in October 2022, in which Avraham Eisenberg manipulated the MNGO token price to drain $116 million. Eisenberg had publicly described the technique on Twitter before the Lodestar attack. There is no evidence that Eisenberg was involved in the Lodestar exploit; the attacker's identity remains unknown. The same technique had previously been used against Moola Markets, resulting in $7.8 million in losses. With Lodestar, the cumulative losses to this class of oracle-manipulation exploit reached approximately $130.3 million across three incidents.","heading":"Attack Vector and Similarity to Mango Markets","sources":[{"url":"https://cointelegraph.com/news/hackers-copied-mango-markets-attacker-s-methods-to-exploit-lodestar-certik","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://www.certik.com/resources/blog/TqTyq4vYHl8JzS7zyJye9-lodestar-finance-incident-analysis","name":"certik.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The attacker's primary wallet address was identified on-chain as 0xb50f...5db13. Following the exploit, the stolen funds were bridged from Arbitrum to Ethereum mainnet and distributed across three externally owned addresses. The attacker's identity was never publicly confirmed. Lodestar Finance publicly appealed to the exploiter via their official Twitter account, offering a white-hat bounty arrangement and stating that 'recovering the funds of our users is the main priority.' No response from the attacker was ever publicly documented.","heading":"Attacker Identity and On-Chain Tracing","sources":[{"url":"https://www.certik.com/resources/blog/TqTyq4vYHl8JzS7zyJye9-lodestar-finance-incident-analysis","name":"certik.com","type":"other","credibility":3},{"url":"https://x.com/LodestarFinance/status/1601687317604839424","name":"x.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Lodestar Finance identified approximately 2.8 million GLP (worth roughly $2.4 million at the time) remaining in the plvGLP vault as recoverable. By October 2023, the team reported repaying approximately one-third of total losses to affected depositors using this recovered GLP. The team additionally allocated 750,000 esLODE tokens to further compensate hack victims; these tokens could be staked to earn protocol revenue and converted linearly to LODE over one year. A claims portal was established at claim.lodestarfinance.io. The majority of user losses — estimated at $4–5 million — remained unrecovered.","heading":"Recovery and Compensation Efforts","sources":[{"url":"https://iq.wiki/wiki/lodestar-finance","name":"iq.wiki","type":"other","credibility":3},{"url":"https://claim.lodestarfinance.io/","name":"claim.lodestarfinance.io","type":"other","credibility":3}],"severity":"medium"},{"content":"In July 2023, Lodestar Finance launched Lodestar V1, a redesigned version of the protocol on Arbitrum. The team announced the migration from V0 to V1 via their official Twitter account, noting that liquidity incentives had also migrated. The V1 deployment briefly attracted over $30 million in TVL. Lodestar V0 was effectively deprecated; as of 2026, the original V0 contract retains a residual TVL of approximately $95,000 with minimal activity. No regulatory actions, lawsuits, or criminal charges have been publicly filed in connection with the exploit.","heading":"Protocol Relaunch and Current Status","sources":[{"url":"https://x.com/LodestarFinance/status/1684418629297930240","name":"x.com","type":"other","credibility":3},{"url":"https://defillama.com/protocol/lodestar-finance","name":"defillama.com","type":"other","credibility":3},{"url":"https://defillama.com/protocol/lodestar-v1","name":"defillama.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Halborn Security published a post-mortem analysis of the Lodestar V0 exploit, characterizing the vulnerable oracle implementation as a preventable vulnerability class that should be identified during smart contract security audits prior to launch. The protocol's reliance on a custom GLPOracle for plvGLP — rather than a tamper-resistant external oracle such as Chainlink — was identified as the root cause. Lodestar used Chainlink price feeds for all other assets on the platform, but not for plvGLP. No pre-exploit audit reports are referenced in publicly available sources.","heading":"Security Audit History","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-lodestar-finance-hack-november-2022","name":"halborn.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2022-12-08","event":"Attacker wallet funded with approximately 1,500 ETH in preparation for the exploit.","source":""},{"date":"2022-12-10","event":"Flash loan oracle manipulation exploit executed against Lodestar V0 on Arbitrum; approximately $6.5–6.9 million drained from the protocol.","source":""},{"date":"2022-12-10","event":"Lodestar Finance team publicly acknowledged the exploit and appealed to the attacker for a white-hat agreement via Twitter.","source":""},{"date":"2022-12-10","event":"PlutusDAO published official statement clarifying the vulnerability was in Lodestar's oracle implementation, not the plvGLP contract.","source":""},{"date":"2022-12-11","event":"CertiK published incident analysis identifying attacker wallet 0xb50f...5db13 and detailing the on-chain attack flow.","source":""},{"date":"2022-12-12","event":"Halborn published post-mortem analysis classifying the exploit as a preventable oracle vulnerability.","source":""},{"date":"2023-04-08","event":"Lodestar Finance relaunched on Arbitrum, attracting over $30 million in TVL.","source":""},{"date":"2023-07-27","event":"Lodestar V1 launched; team announced migration of incentives from V0 to V1.","source":""},{"date":"2023-10","event":"Lodestar team reported approximately one-third of hack losses repaid to affected depositors; 750,000 esLODE tokens allocated for further compensation.","source":"","date_original":"2023-10-01"}],"sources_used":[{"url":"https://www.certik.com/resources/blog/TqTyq4vYHl8JzS7zyJye9-lodestar-finance-incident-analysis","name":"CertiK — Lodestar Finance Incident Analysis","type":"research","archive_url":"https://web.archive.org/web/20260725034833/https://www.certik.com/blog/TqTyq4vYHl8JzS7zyJye9-lodestar-finance-incident-analysis","credibility":2,"archive_timestamp":"2026-07-25T03:48:33+00:00"},{"url":"https://cointelegraph.com/news/lodestar-finance-exploited-in-flash-loan-attack","name":"CoinTelegraph — Lodestar Finance exploited in flash loan attack","type":"news_article","archive_url":"http://web.archive.org/web/20260418165951/https://cointelegraph.com/news/lodestar-finance-exploited-in-flash-loan-attack","credibility":2,"archive_timestamp":"2026-04-18T16:59:51+00:00"},{"url":"https://cointelegraph.com/news/hackers-copied-mango-markets-attacker-s-methods-to-exploit-lodestar-certik","name":"CoinTelegraph — Hackers copied Mango Markets attacker's methods to exploit Lodestar","type":"news_article","archive_url":"http://web.archive.org/web/20260120101047/https://cointelegraph.com/news/hackers-copied-mango-markets-attacker-s-methods-to-exploit-lodestar-certik","credibility":2,"archive_timestamp":"2026-01-20T10:10:47+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-lodestar-finance-hack-november-2022","name":"Halborn — Explained: The Lodestar Finance Hack (November 2022)","type":"research","archive_url":"http://web.archive.org/web/20260415072333/https://www.halborn.com/blog/post/explained-the-lodestar-finance-hack-november-2022","credibility":2,"archive_timestamp":"2026-04-15T07:23:33+00:00"},{"url":"https://web3isgoinggreat.com/single/lodestar-finance-attacked","name":"Web3 Is Going Great — Lodestar Finance attacked and drained","type":"community_report","archive_url":"http://web.archive.org/web/20260427094943/https://www.web3isgoinggreat.com/single/lodestar-finance-attacked","credibility":2,"archive_timestamp":"2026-04-27T09:49:43+00:00"},{"url":"https://medium.com/@plutus.fi/official-statement-on-the-lodestar-finance-exploit-cf2b501647f5","name":"PlutusDAO — Official Statement on the Lodestar Finance Exploit","type":"official","archive_url":null,"credibility":2,"archive_error":"forbiddenaccess","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://iq.wiki/wiki/lodestar-finance","name":"IQ.wiki — Lodestar Finance","type":"research","archive_url":"http://web.archive.org/web/20260213041337/https://iq.wiki/wiki/lodestar-finance","credibility":2,"archive_timestamp":"2026-02-13T04:13:37+00:00"},{"url":"https://defillama.com/protocol/lodestar-finance","name":"DeFiLlama — Lodestar Finance TVL","type":"on_chain","archive_url":"http://web.archive.org/web/20251006025314/https://defillama.com/protocol/lodestar-finance","credibility":2,"archive_timestamp":"2025-10-06T02:53:14+00:00"},{"url":"https://defillama.com/protocol/lodestar-v1","name":"DeFiLlama — Lodestar V1 TVL","type":"on_chain","archive_url":null,"credibility":2,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://x.com/LodestarFinance/status/1601687317604839424","name":"Lodestar Finance Twitter — Exploit acknowledgment and hacker outreach","type":"social_media","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://x.com/LodestarFinance/status/1684418629297930240","name":"Lodestar Finance Twitter — V1 launch announcement","type":"social_media","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://unchainedcrypto.com/defi-lending-platform-lodestar-finance-loses-6-9m-in-oracle-exploit/","name":"Unchained Crypto — DeFi Lending Platform Lodestar Finance Loses $6.9M in Oracle Exploit","type":"news_article","archive_url":"https://web.archive.org/web/20260724172919/https://unchainedcrypto.com/defi-lending-platform-lodestar-finance-loses-6-9m-in-oracle-exploit/","credibility":2,"archive_timestamp":"2026-07-24T17:29:19+00:00"},{"url":"https://eigenphi.substack.com/p/69m-lodestar-exploit-oracle-manipulations","name":"EigenPhi — $6.9M Lodestar Exploit: Oracle Manipulations","type":"research","archive_url":"http://web.archive.org/web/20260724163946/https://eigenphi.substack.com/p/69m-lodestar-exploit-oracle-manipulations","credibility":2,"archive_timestamp":"2026-07-24T16:39:46+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:46.037409+00:00","updated_at":"2026-08-29T01:35:46.95+00:00"}}