{"investigation":{"slug":"rodeo","entity_name":"Rodeo Finance","trust_score":12,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"Rodeo Finance was an Arbitrum-based leveraged yield protocol that allowed users to open leveraged positions in DeFi yield strategies using borrowed USDC from an integrated lending pool. The protocol suffered two separate security exploits in July 2023 within six days of each other, with the second — a TWAP oracle manipulation attack — draining approximately 472 ETH (roughly $888,000 net) and collapsing its total value locked from $20 million to under $500. The attacker bridged stolen funds to Ethereum, routed 150 ETH through Tornado Cash, and the protocol never fully recovered operationally.","sections":[{"content":"Rodeo Finance was a leveraged yield protocol deployed on the Arbitrum Layer-2 network. The protocol allowed users to borrow USDC from a lending pool and deploy those funds into whitelisted yield-bearing strategies, amplifying returns through leverage. Its native token, RDO, was used for governance and incentive distribution. The protocol maintained a 9-layer security framework described in its own documentation, including Chainlink price oracles for major assets, reentrancy guards, flash loan prevention, timelock-protected admin actions, and deposit caps. For less liquid or exotic assets not covered by Chainlink, the protocol relied on Time-Weighted Average Price (TWAP) oracles derived from on-chain liquidity pools — a design choice that would prove to be a critical vulnerability. The protocol had undergone at least one third-party audit conducted by Kalos prior to launch and maintained an ongoing relationship with auditors for between-audit reviews.","heading":"Protocol Overview","sources":[{"url":"https://medium.com/@Rodeo_Finance/rodeo-finance-security-f47da92f0c10","name":"Rodeo Finance Security Overview (Official Medium)","type":"official","credibility":2},{"url":"https://medium.com/@Rodeo_Finance/rodeo-post-mortem-overview-f35635c14101","name":"Rodeo Finance Exploit Post Mortem (Official Medium)","type":"official","credibility":2}],"severity":"medium"},{"content":"On July 5, 2023, Rodeo Finance was exploited for approximately $89,000 through a vulnerability in its mintProtocolReserves function. Blockchain security firm Hypernative Labs detected the attack. According to post-incident analysis by BlockSec Phalcon, the exploit had two primary root causes: manipulation of StrategyGamma's balance, which allowed a minimal USDC borrow without increasing recorded debt, and an abuse of the mintProtocolReserves function that stemmed from an untrusted external call. The team patched the vulnerability following this initial incident but did not halt operations entirely, leaving a more critical oracle-related vulnerability unaddressed. This first exploit served as an early indicator of weaknesses in the protocol's access control and input validation logic.","heading":"First Exploit — July 5, 2023 (mintProtocolReserves Vulnerability)","sources":[{"url":"https://x.com/Phalcon_xyz/status/1676511696603729921","name":"BlockSec Phalcon on X — mintProtocolReserves exploit details","type":"research","credibility":2},{"url":"https://cointelegraph.com/news/arbitrum-based-rodeo-finance-exploited-for-1-53m-the-second-time-in-a-week","name":"CoinTelegraph — Rodeo Finance exploited for second time, $1.5M stolen","type":"news_article","credibility":2},{"url":"https://protos.com/latest-attack-on-arbitrum-network-costs-rodeo-finance-885k-in-eth/","name":"Protos — Latest attack on Arbitrum network costs Rodeo Finance $885k in ETH","type":"news_article","credibility":2}],"severity":"high"},{"content":"At approximately 07:54 UTC on July 11, 2023, an attacker exploited a critical flaw in Rodeo Finance's TWAP oracle implementation for the ETH/unshETH strategy. The TWAP price was calculated by averaging the last four recorded price instances, with each update occurring every 45 minutes — creating a manipulation window. The attacker executed a multiblock sandwich attack: by inserting large trades around an oracle price update, they caused the unshETH price reported by the oracle to inflate from its fair value of approximately $1,880 per unit to approximately $4,219 per unit — more than double the correct price. With the oracle artificially inflated, the attacker called the Investor contract's earn() function, borrowing approximately $400,000 USDC from Rodeo's lending pool. The borrowed USDC was forced into the ETH-unshETH Camelot liquidity pair through an unconfigured strategy address, generating a severely mispriced position. Because the Health Factor check inside the protocol relied on the same manipulated oracle, the attacker's undercollateralized position passed internal validation. The attacker then unwound the position, capitalizing on the price differential via arbitrage. In total, approximately 472 ETH (net approximately $880,000 after partial recovery) was extracted. The gross loss was initially reported at $1.53 million; PeckShield subsequently revised the figure to approximately $888,000 after accounting for double-counting of fund movements and partial asset recovery.","heading":"Second Exploit — July 11, 2023 (TWAP Oracle Manipulation Attack)","sources":[{"url":"https://www.quillaudits.com/blog/hack-analysis/rodeo-finance-hack","name":"QuillAudits — Decoding Rodeo Finance Hack","type":"research","credibility":2},{"url":"https://medium.com/neptune-mutual/understanding-rodeo-finance-exploit-5425b30fbf20","name":"Neptune Mutual — Understanding Rodeo Finance Exploit","type":"research","credibility":2},{"url":"https://medium.com/@Rodeo_Finance/rodeo-post-mortem-overview-f35635c14101","name":"Rodeo Finance Exploit Post Mortem (Official)","type":"official","credibility":2},{"url":"https://decrypt.co/148068/layer-2-defi-project-rodeo-finance-hacked-472-ethereum","name":"Decrypt — Rodeo Finance Hacked for $888,000 in Ethereum","type":"news_article","credibility":2},{"url":"https://www.theblock.co/post/238819/arbitrum-rodeo-finance-1-5-million-defi-exploit","name":"The Block — Arbitrum-based Rodeo Finance loses $888,000 in latest DeFi exploit","type":"news_article","credibility":2}],"severity":"critical"},{"content":"The primary attacker wallet identified in the July 11 exploit is 0x2f3788F2396127061c46fC07BD0fcb91faAcE328. The attacker pre-funded this wallet with 50 ETH sourced from Tornado Cash before executing the attack, consistent with a deliberate obfuscation strategy. Following the exploit, the attacker bridged stolen ETH from Arbitrum to the Ethereum mainnet. On Ethereum, the attacker swapped 285 ETH for unshETH tokens and deposited them to Ankr's ETH2 staking contract, converting liquid funds into staked positions. An additional 150 ETH was transferred directly to Tornado Cash, a privacy mixer sanctioned by the U.S. Treasury's Office of Foreign Assets Control (OFAC) in August 2022. At the time of initial reporting, approximately 371 ETH (worth roughly $701,000) remained in the attacker's address. The attack transaction hash on Arbitrum is 0x98f1e234faac8b7f7ceaffe4e8e0581038678d95710b646db45ec3de47e6c3af. The use of Tornado Cash and ETH2 staking deposits significantly complicated efforts to recover or trace the stolen assets. ZachXBT, the on-chain investigator who tracks stolen crypto fund flows across DeFi, flagged Rodeo Finance in the context of this incident as part of broader monitoring of Tornado Cash-routed exploit proceeds.","heading":"Attacker On-Chain Trail and Fund Laundering","sources":[{"url":"https://www.quillaudits.com/blog/hack-analysis/rodeo-finance-hack","name":"QuillAudits — Decoding Rodeo Finance Hack (attacker address and tx hash)","type":"research","credibility":2},{"url":"https://medium.com/neptune-mutual/understanding-rodeo-finance-exploit-5425b30fbf20","name":"Neptune Mutual — Understanding Rodeo Finance Exploit (fund flow analysis)","type":"research","credibility":2},{"url":"https://cryptobriefing.com/defi-protocol-rodeo-finance-hacked-1-53m-of-eth-stolen/","name":"Crypto Briefing — DeFi Protocol Rodeo Finance Hacked; $1.53M of ETH Stolen","type":"news_article","credibility":2},{"url":"https://protos.com/latest-attack-on-arbitrum-network-costs-rodeo-finance-885k-in-eth/","name":"Protos — Latest attack on Arbitrum network costs Rodeo Finance $885k in ETH","type":"news_article","credibility":2}],"severity":"critical"},{"content":"Immediately following the July 11 exploit, the Rodeo Finance team paused the protocol, disabling all farms with TWAP-dependent price feeds. The team engaged third-party auditors and white hat security researchers to conduct a full review of the exploit and assess the remaining codebase for additional vulnerabilities. An on-chain message was sent to the attacker's wallet offering a white hat bounty in exchange for the return of funds; no funds were returned in response. The team also contacted law enforcement and cooperated with blockchain analytics efforts. On the recovery side, approximately $816,342 USDC worth of unshETH tokens left in the attacked contracts was recovered and transferred to the Rodeo protocol multisig, then swapped to USDC to eliminate market exposure. The team committed to repaying the approximately $880,000 net debt to USDC lending pool LPs on a weekly basis from treasury funds and potentially through RDO token derivatives, contingent on ongoing monitoring of protocol health. Vulnerable farms were to remain disabled until cleared by multiple auditors, and the team stated an intention to retain 'AAA+' audit firms with money market specialization going forward.","heading":"Team Response and Compensation Plan","sources":[{"url":"https://medium.com/@Rodeo_Finance/rodeo-post-mortem-overview-f35635c14101","name":"Rodeo Finance Exploit Post Mortem (Official Medium)","type":"official","credibility":2},{"url":"https://cointelegraph.com/news/arbitrum-based-rodeo-finance-exploited-for-1-53m-the-second-time-in-a-week","name":"CoinTelegraph — Rodeo Finance exploited for second time, $1.5M stolen","type":"news_article","credibility":2}],"severity":"high"},{"content":"The July 11 exploit produced immediate and severe market consequences for Rodeo Finance. The protocol's total value locked (TVL) collapsed from approximately $20 million to under $500 within hours of the exploit becoming public, representing a near-total flight of depositor capital. The native RDO token price declined approximately 60%, falling from around $0.20 to approximately $0.08. PeckShield, which first publicly flagged the attack with an on-chain alert to the Rodeo Finance Twitter account, initially reported a $1.53 million loss figure that was later revised to approximately $888,000 net after accounting for the partial fund recovery and a double-counting discrepancy in the initial assessment. The combined effect of two exploits within six days, the Tornado Cash routing of stolen funds, and the collapse in TVL left the protocol effectively non-operational. As of available reporting, the protocol did not resume full operations and its DeFi Llama TVL profile reflects the post-exploit near-zero state.","heading":"Market Impact and Protocol Collapse","sources":[{"url":"https://cryptobriefing.com/defi-protocol-rodeo-finance-hacked-1-53m-of-eth-stolen/","name":"CryptoBriefing — DeFi Protocol Rodeo Finance Hacked; $1.53M of ETH Stolen","type":"news_article","credibility":2},{"url":"https://decrypt.co/148068/layer-2-defi-project-rodeo-finance-hacked-472-ethereum","name":"Decrypt — Rodeo Finance Hacked for $888,000 in Ethereum","type":"news_article","credibility":2},{"url":"https://blockonomi.com/arbitrum-rodeo-finance-hacked-price-crashes-60/","name":"Blockonomi — Arbitrum: Rodeo Finance Hacked, Price Crashes 60%","type":"news_article","credibility":2},{"url":"https://defillama.com/protocol/rodeo","name":"DeFi Llama — Rodeo Protocol TVL","type":"on_chain","credibility":2}],"severity":"critical"},{"content":"Security researchers who analyzed the exploit identified the core design failure as Rodeo Finance's use of an on-chain TWAP oracle derived from a shallow-liquidity UniswapV2 pool (the ETH/unshETH pair) for pricing within its leveraged strategy system. TWAP oracles aggregate prices across a defined time window to resist single-block flash loan attacks, but they remain susceptible to multiblock manipulation when underlying pool liquidity is insufficient to make sustained price distortion cost-prohibitive. In Rodeo's case, the TWAP averaged four price observations at 45-minute intervals, but because the unshETH/WETH pool had limited depth, an attacker could profitably sandwich oracle update transactions over multiple blocks to sustain an artificial price deviation. The exploit demonstrated that the protocol's reliance on a custom TWAP for non-Chainlink assets, combined with inadequate slippage controls and an absence of circuit breakers, created a directly exploitable attack surface. Security analysts including those at QuillAudits and ImmuneByes noted that integrating a decentralized price oracle such as Chainlink for all assets, rather than relying on pool-derived TWAPs for exotic pairs, would have mitigated the attack vector. The case has been cited in subsequent DeFi security research as a representative example of TWAP oracle manipulation risk in low-liquidity pool contexts.","heading":"Oracle Design Failure and Security Analysis","sources":[{"url":"https://www.quillaudits.com/blog/hack-analysis/rodeo-finance-hack","name":"QuillAudits — Decoding Rodeo Finance Hack","type":"research","credibility":2},{"url":"https://immunebytes.com/blog/rodeo-finance-hack-analysis-report-july-11-2023/","name":"ImmuneByes — Rodeo Finance Hack Analysis Report July 11 2023","type":"research","credibility":2},{"url":"https://medium.com/neptune-mutual/understanding-rodeo-finance-exploit-5425b30fbf20","name":"Neptune Mutual — Understanding Rodeo Finance Exploit","type":"research","credibility":2}],"severity":"critical"}],"timeline":[{"date":"2023-07-05","event":"First exploit: approximately $89,000 stolen via a vulnerability in the mintProtocolReserves function and StrategyGamma balance manipulation. Hypernative Labs detected the attack.","source":"CoinTelegraph","source_url":"https://cointelegraph.com/news/arbitrum-based-rodeo-finance-exploited-for-1-53m-the-second-time-in-a-week"},{"date":"2023-07-11","event":"Second exploit at approximately 07:54 UTC: attacker (0x2f3788F2396127061c46fC07BD0fcb91faAcE328) executes a multiblock TWAP oracle sandwich attack on the ETH/unshETH strategy. 472 ETH (~$888,000 net) drained from the USDC lending pool. PeckShield first publicly alerts the team on Twitter.","source":"QuillAudits / Rodeo Finance Post Mortem","source_url":"https://www.quillaudits.com/blog/hack-analysis/rodeo-finance-hack"},{"date":"2023-07-11","event":"Rodeo Finance pauses all protocol operations. TWAP-dependent farms disabled. Team initiates forensic analysis and contacts law enforcement.","source":"Rodeo Finance Official Post Mortem","source_url":"https://medium.com/@Rodeo_Finance/rodeo-post-mortem-overview-f35635c14101"},{"date":"2023-07-11","event":"Attacker bridges stolen ETH from Arbitrum to Ethereum mainnet. 285 ETH swapped for unshETH and deposited to Ankr ETH2 staking. 150 ETH sent to Tornado Cash. Approximately 371 ETH remains in attacker wallet.","source":"Neptune Mutual Exploit Analysis","source_url":"https://medium.com/neptune-mutual/understanding-rodeo-finance-exploit-5425b30fbf20"},{"date":"2023-07-11","event":"RDO token price drops approximately 60%, from ~$0.20 to ~$0.08. Protocol TVL collapses from $20 million to under $500.","source":"Blockonomi / CryptoBriefing","source_url":"https://blockonomi.com/arbitrum-rodeo-finance-hacked-price-crashes-60/"},{"date":"2023-07-12","event":"Team recovers approximately $816,342 USDC worth of unshETH left in exploited contracts. Funds transferred to Rodeo multisig and swapped to USDC. Team announces weekly repayment plan for USDC pool LP losses from treasury.","source":"Rodeo Finance Official Post Mortem","source_url":"https://medium.com/@Rodeo_Finance/rodeo-post-mortem-overview-f35635c14101"},{"date":"2023-07-12","event":"On-chain white hat bounty message sent to attacker wallet. No funds returned. Third-party auditors engaged for full codebase review before any potential relaunch.","source":"Rodeo Finance Official Post Mortem","source_url":"https://medium.com/@Rodeo_Finance/rodeo-post-mortem-overview-f35635c14101"}],"sources_used":[{"url":"https://medium.com/@Rodeo_Finance/rodeo-post-mortem-overview-f35635c14101","name":"Rodeo Finance Exploit Post Mortem (Official Medium)","type":"official","archive_url":"http://web.archive.org/web/20260610104508/https://medium.com/@Rodeo_Finance/rodeo-post-mortem-overview-f35635c14101","credibility":2,"archive_timestamp":"2026-06-10T10:45:08+00:00"},{"url":"https://medium.com/@Rodeo_Finance/rodeo-finance-security-f47da92f0c10","name":"Rodeo Finance Security Overview (Official Medium)","type":"official","archive_url":null,"credibility":2,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.quillaudits.com/blog/hack-analysis/rodeo-finance-hack","name":"QuillAudits — Decoding Rodeo Finance Hack","type":"research","archive_url":"http://web.archive.org/web/20260213170158/https://www.quillaudits.com/blog/hack-analysis/rodeo-finance-hack","credibility":2,"archive_timestamp":"2026-02-13T17:01:58+00:00"},{"url":"https://immunebytes.com/blog/rodeo-finance-hack-analysis-report-july-11-2023/","name":"ImmuneByes — Rodeo Finance Hack Analysis Report July 11 2023","type":"research","archive_url":null,"credibility":2,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://medium.com/neptune-mutual/understanding-rodeo-finance-exploit-5425b30fbf20","name":"Neptune Mutual — Understanding Rodeo Finance Exploit","type":"research","archive_url":null,"credibility":2,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.theblock.co/post/238819/arbitrum-rodeo-finance-1-5-million-defi-exploit","name":"The Block — Arbitrum-based Rodeo Finance loses $888,000 in latest DeFi exploit","type":"news_article","archive_url":null,"credibility":2,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://cointelegraph.com/news/arbitrum-based-rodeo-finance-exploited-for-1-53m-the-second-time-in-a-week","name":"CoinTelegraph — Rodeo Finance exploited for second time, $1.5M stolen","type":"news_article","archive_url":"http://web.archive.org/web/20260720154416/https://cointelegraph.com/news/arbitrum-based-rodeo-finance-exploited-for-1-53m-the-second-time-in-a-week","credibility":2,"archive_timestamp":"2026-07-20T15:44:16+00:00"},{"url":"https://decrypt.co/148068/layer-2-defi-project-rodeo-finance-hacked-472-ethereum","name":"Decrypt — Rodeo Finance Hacked for $888,000 in Ethereum","type":"news_article","archive_url":"http://web.archive.org/web/20260509145616/https://decrypt.co/148068/layer-2-defi-project-rodeo-finance-hacked-472-ethereum","credibility":2,"archive_timestamp":"2026-05-09T14:56:16+00:00"},{"url":"https://cryptobriefing.com/defi-protocol-rodeo-finance-hacked-1-53m-of-eth-stolen/","name":"CryptoBriefing — DeFi Protocol Rodeo Finance Hacked; $1.53M of ETH Stolen","type":"news_article","archive_url":"http://web.archive.org/web/20251208112109/https://cryptobriefing.com/defi-protocol-rodeo-finance-hacked-1-53m-of-eth-stolen/","credibility":2,"archive_timestamp":"2025-12-08T11:21:09+00:00"},{"url":"https://protos.com/latest-attack-on-arbitrum-network-costs-rodeo-finance-885k-in-eth/","name":"Protos — Latest attack on Arbitrum network costs Rodeo Finance $885k in ETH","type":"news_article","archive_url":"http://web.archive.org/web/20260511082019/https://protos.com/latest-attack-on-arbitrum-network-costs-rodeo-finance-885k-in-eth/","credibility":2,"archive_timestamp":"2026-05-11T08:20:19+00:00"},{"url":"https://blockonomi.com/arbitrum-rodeo-finance-hacked-price-crashes-60/","name":"Blockonomi — Arbitrum: Rodeo Finance Hacked, Price Crashes 60%","type":"news_article","archive_url":"https://web.archive.org/web/20260725083324/https://blockonomi.com/pepperstone-review/","credibility":2,"archive_timestamp":"2026-07-25T08:33:24+00:00"},{"url":"https://x.com/Phalcon_xyz/status/1676511696603729921","name":"BlockSec Phalcon on X — mintProtocolReserves vulnerability details","type":"social_media","archive_url":null,"credibility":2,"archive_timestamp":null},{"url":"https://defillama.com/protocol/rodeo","name":"DeFi Llama — Rodeo Protocol TVL","type":"on_chain","archive_url":"http://web.archive.org/web/20250813193729/https://defillama.com/protocol/rodeo","credibility":2,"archive_timestamp":"2025-08-13T19:37:29+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:40.502632+00:00","updated_at":"2026-08-29T01:35:01.628+00:00"}}