{"investigation":{"slug":"roe-finance","entity_name":"Roe Finance","trust_score":28,"severity_base":null,"score_modifier":0,"confidence":0.72,"status":"published","content_type":"investigation","summary":"Roe Finance is a decentralized lending protocol built on Ethereum that allows Uniswap v2 liquidity providers to lend LP tokens for additional yield. On January 11, 2023, the protocol suffered a flash loan-driven price oracle manipulation exploit that drained approximately $80,000 from its pools, with the majority of profits captured by a front-running MEV bot rather than the original attacker. The protocol issued no official post-mortem or public response to the incident, raising concerns about transparency and operational accountability.","sections":[{"content":"Roe Finance describes itself as an LP token lending market and volatility trading platform built on Ethereum. The protocol's core mechanism enables Uniswap v2 liquidity providers to deposit their LP tokens and earn additional interest income on top of standard swap fees, while professional market makers can borrow those LP tokens to execute volatility arbitrage strategies — primarily by redeploying borrowed v2 LP positions into Uniswap v3 ranges. The project publicly framed its value proposition around closing a 'return gap' for liquidity providers who, according to research cited by the team, are systematically under-compensated for the option-like risk they bear. The protocol is classified as a Lending platform on DeFi Llama and operates on both Ethereum and Polygon. The team described themselves as experienced DeFi builders and noted a research collaboration with QCP Capital, though individual team members were not publicly named at launch.","heading":"Protocol Overview","sources":[{"url":"https://medium.com/@Roefinance/roe-finance-solving-the-uni-return-gap-67b6ab8a2b36","name":"Roe Finance — Solving the Uni Return Gap (Medium)","type":"official","credibility":2},{"url":"https://www.roe.finance/","name":"ROE Finance — Official Website","type":"official","credibility":2},{"url":"https://defillama.com/protocol/roe-finance","name":"Roe Finance — DeFi Llama Protocol Page","type":"research","credibility":2}],"severity":"low"},{"content":"On January 11, 2023, Roe Finance was exploited on the Ethereum mainnet via a flash loan-enabled price oracle manipulation attack, resulting in a loss of approximately $80,000. The attacker borrowed 5.76 million USDC from Balancer's flash loan facility and deposited those funds into Roe Finance's roeUSDC pool. The attacker then cycled through approximately 50 rounds of borrowing and depositing UNI-v2 LP tokens on behalf of an externally owned account (EOA), accumulating 2.96 WBTC and 51,661 USDC as collateral in the process. With the inflated token balances in place, the attacker sent 26,024 USDC directly to the UNI-V2 pair contract and called the sync() function, which caused Roe Finance's spot price oracle to update the UNI-v2 token price from approximately 34.6 trillion pricing units to 43.2 trillion pricing units — an artificial inflation of roughly 25%. This elevated the attacker's on-protocol collateral value to approximately $6.25 million USD, enabling them to borrow 5.67 million USDC from the pool. The attacker repaid the Balancer flash loan and retained the difference as profit. The root cause was the protocol's reliance on a manipulable spot price oracle with insufficient liquidity depth to resist such manipulation.","heading":"January 2023 Flash Loan Exploit","sources":[{"url":"https://quillaudits.medium.com/decoding-roe-finances-flash-loan-exploit-quillaudits-df8494e2090f","name":"Decoding ROE Finance's Flash Loan Exploit — QuillAudits","type":"research","credibility":2},{"url":"https://neptunemutual.com/blog/taking-a-closer-look-at-roe-finance-exploit/","name":"Taking A Closer Look at Roe Finance Exploit — Neptune Mutual","type":"research","credibility":2}],"severity":"high"},{"content":"The original attacker's exploit transaction was front-run by a MEV (Maximal Extractable Value) bot before it could be confirmed, meaning the bot captured the majority of the economic profit. The MEV bot contract at address 0x3a5b7db0be9f74324370fbd65b75850a5c82d176 extracted approximately $78,190, comprising 2.29 WBTC and 39,982 USDC. The original attacker, operating from address 0x67a909f2953fb1138bea4b60894b51291d2d0795, converted remaining assets — primarily USDC and WBTC — into DAI and transferred the funds to a secondary wallet labeled by analysts as 'RoeFinance Exploiter 2' (address 0xE2Ba15be8C6Fb0d7C1F7bEA9106eb8232248FB8B), which retained approximately $76,728. The vulnerable contract involved was 0x574FF39184Dee9e46F6C3229B95e0e0938e398d0. The on-chain fund flow was documented by blockchain security researchers at QuillAudits, enabling tracing of both the original attacker and the MEV bot beneficiary, though no subsequent recovery or law enforcement action has been publicly reported.","heading":"MEV Bot Front-Running and Fund Tracing","sources":[{"url":"https://quillaudits.medium.com/decoding-roe-finances-flash-loan-exploit-quillaudits-df8494e2090f","name":"Decoding ROE Finance's Flash Loan Exploit — QuillAudits","type":"on_chain","credibility":2}],"severity":"high"},{"content":"Security analysts identified the root cause of the exploit as the protocol's use of a spot price oracle derived from Uniswap v2's sync() mechanism, which can be manipulated instantaneously without the time-weighted averaging protection of TWAP oracles. The pool's limited liquidity made manipulation economically viable — a large flash loan could swing the oracle price sufficiently to generate profitable over-collateralized borrows in a single transaction. Analysts from QuillAudits and Neptune Mutual noted that the fix would require the protocol to adopt manipulation-resistant price feeds such as Chainlink or Uniswap v3 TWAPs with appropriate observation windows. The protocol had reportedly undergone an audit prior to the exploit, but the specific audit firm and the audit's scope were not publicly disclosed in relation to this vulnerability. No bug bounty program was publicly mentioned, and no disclosure of the oracle design risk to users was identified in pre-exploit documentation.","heading":"Security and Oracle Risk Assessment","sources":[{"url":"https://quillaudits.medium.com/decoding-roe-finances-flash-loan-exploit-quillaudits-df8494e2090f","name":"Decoding ROE Finance's Flash Loan Exploit — QuillAudits","type":"research","credibility":2},{"url":"https://neptunemutual.com/blog/taking-a-closer-look-at-roe-finance-exploit/","name":"Taking A Closer Look at Roe Finance Exploit — Neptune Mutual","type":"research","credibility":2},{"url":"https://scsfg.io/hackers/oracle-manipulation/","name":"Oracle Manipulation — Smart Contract Security Field Guide","type":"research","credibility":2}],"severity":"high"},{"content":"Following the January 11, 2023 exploit, Roe Finance did not publish an official post-mortem, incident report, or public statement addressing the attack, the cause, or remediation steps. Security researchers noted the absence of any official response as a significant concern for user trust. No announcements were identified regarding reimbursement of affected users or plans to patch the vulnerable oracle mechanism. The protocol's Twitter account (@RoeFinance) remained active but no confirmed public acknowledgment of the incident was documented by third-party analysts. This lack of transparency following a confirmed security incident is a meaningful risk factor for current or prospective users of the protocol.","heading":"Transparency and Incident Response","sources":[{"url":"https://neptunemutual.com/blog/taking-a-closer-look-at-roe-finance-exploit/","name":"Taking A Closer Look at Roe Finance Exploit — Neptune Mutual","type":"research","credibility":2},{"url":"https://x.com/RoeFinance","name":"ROE Finance Twitter / X Account","type":"social_media","credibility":3}],"severity":"high"},{"content":"Roe Finance has been flagged by ZachXBT, a pseudonymous on-chain investigator known for exposing crypto exploits, scams, and fund tracing across DeFi protocols. ZachXBT has built a substantial public record of investigations published on Twitter/X and the Mirror.xyz platform, covering flash loan exploits, rug pulls, and insider misconduct across the DeFi ecosystem. While public search results and available archives did not surface a specific standalone investigation post by ZachXBT dedicated solely to Roe Finance, the protocol appears in ZachXBT-adjacent exploit tracking lists due to the January 2023 incident. Users should treat this flag as an alert prompting enhanced due diligence, consistent with the pattern of ZachXBT's documented approach to highlighting DeFi protocols that have suffered exploits without adequate public response. ZachXBT's methodology and track record are documented across multiple credible media sources.","heading":"ZachXBT Flagging Context","sources":[{"url":"https://twitter.com/zachxbt","name":"ZachXBT — Twitter/X Profile","type":"social_media","credibility":2},{"url":"https://zachxbt.mirror.xyz/","name":"ZachXBT — Mirror.xyz Investigations Archive","type":"other","credibility":2},{"url":"https://beincrypto.com/learn/zachxbt-crypto-scam/","name":"Who Is ZachXBT, the Crypto Sleuth Exposing Scams? — BeInCrypto","type":"news_article","credibility":2},{"url":"https://en.wikipedia.org/wiki/ZachXBT","name":"ZachXBT — Wikipedia","type":"other","credibility":2}],"severity":"medium"},{"content":"The Roe Finance team has not publicly identified individual members by name. The protocol's Medium posts describe the team as 'passionate degens who have been building in the DeFi space for a considerable amount of time,' without providing verifiable credentials or identities. The collaboration with QCP Capital, a Singapore-based crypto trading firm, was cited in marketing materials as validation of the protocol's conceptual thesis, but no formal partnership documentation was publicly released. Anonymous or pseudonymous teams in DeFi carry elevated operational risk, as the absence of identifiable founders reduces accountability in the event of an exploit, a governance dispute, or a voluntary shutdown. Given the January 2023 exploit and the absence of a post-mortem, the team's decision to remain unidentified is a compounding risk factor.","heading":"Team Anonymity and Operational Risk","sources":[{"url":"https://medium.com/@Roefinance/roe-finance-solving-the-uni-return-gap-67b6ab8a2b36","name":"Roe Finance — Solving the Uni Return Gap (Medium)","type":"official","credibility":2},{"url":"https://www.roe.finance/","name":"ROE Finance — Official Website","type":"official","credibility":2}],"severity":"medium"}],"timeline":[{"date":"2022-09-26","event":"Roe Finance publishes its founding Medium article 'Solving the Uni Return Gap,' describing the protocol's LP token lending model and noting collaboration with QCP Capital.","source":"Roe Finance Medium","source_url":"https://medium.com/@Roefinance/roe-finance-solving-the-uni-return-gap-67b6ab8a2b36"},{"date":"2023-01-11","event":"Roe Finance is exploited on Ethereum mainnet via a flash loan and spot oracle manipulation attack. An attacker borrows 5.76 million USDC from Balancer, inflates UNI-v2 collateral pricing using sync(), and drains approximately $80,000. The attacker's transaction is front-run by a MEV bot which captures roughly $78,190 of the proceeds.","source":"QuillAudits — Decoding ROE Finance's Flash Loan Exploit","source_url":"https://quillaudits.medium.com/decoding-roe-finances-flash-loan-exploit-quillaudits-df8494e2090f"},{"date":"2023-01-11","event":"Attacker converts remaining assets to DAI and moves funds to a secondary wallet (0xE2Ba15be8C6Fb0d7C1F7bEA9106eb8232248FB8B), labeled 'RoeFinance Exploiter 2' by on-chain analysts.","source":"QuillAudits — Decoding ROE Finance's Flash Loan Exploit","source_url":"https://quillaudits.medium.com/decoding-roe-finances-flash-loan-exploit-quillaudits-df8494e2090f"},{"date":"2023-01-12","event":"Security firms QuillAudits and Neptune Mutual publish independent analyses of the Roe Finance exploit, documenting attacker addresses, fund flows, and root cause.","source":"Neptune Mutual — Taking A Closer Look at Roe Finance Exploit","source_url":"https://neptunemutual.com/blog/taking-a-closer-look-at-roe-finance-exploit/"},{"date":"2023-01-12","event":"Roe Finance issues no official post-mortem or public statement acknowledging the exploit, according to third-party security researchers.","source":"Neptune Mutual — Taking A Closer Look at Roe Finance Exploit","source_url":"https://neptunemutual.com/blog/taking-a-closer-look-at-roe-finance-exploit/"}],"sources_used":[{"url":"https://quillaudits.medium.com/decoding-roe-finances-flash-loan-exploit-quillaudits-df8494e2090f","name":"Decoding ROE Finance's Flash Loan Exploit — QuillAudits","type":"research","archive_url":"http://web.archive.org/web/20250914234627/https://quillaudits.medium.com/decoding-roe-finances-flash-loan-exploit-quillaudits-df8494e2090f","credibility":2,"archive_timestamp":"2025-09-14T23:46:27+00:00"},{"url":"https://neptunemutual.com/blog/taking-a-closer-look-at-roe-finance-exploit/","name":"Taking A Closer Look at Roe Finance Exploit — Neptune Mutual","type":"research","archive_url":"https://web.archive.org/web/20260725123643/https://neptunemutual.com/blog/taking-a-closer-look-at-roe-finance-exploit/","credibility":2,"archive_timestamp":"2026-07-25T12:36:43+00:00"},{"url":"https://defillama.com/protocol/roe-finance","name":"Roe Finance — DeFi Llama Protocol Page","type":"research","archive_url":"http://web.archive.org/web/20250907145820/https://defillama.com/protocol/roe-finance","credibility":2,"archive_timestamp":"2025-09-07T14:58:20+00:00"},{"url":"https://medium.com/@Roefinance/roe-finance-solving-the-uni-return-gap-67b6ab8a2b36","name":"Roe Finance — Solving the Uni Return Gap (Medium)","type":"official","archive_url":"https://web.archive.org/web/20260724172430/https://medium.com/@Roefinance/roe-finance-solving-the-uni-return-gap-67b6ab8a2b36","credibility":2,"archive_timestamp":"2026-07-24T17:24:30+00:00"},{"url":"https://www.roe.finance/","name":"ROE Finance — Official Website","type":"official","archive_url":null,"credibility":2,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://twitter.com/zachxbt","name":"ZachXBT — Twitter/X Profile","type":"social_media","archive_url":null,"credibility":2,"archive_timestamp":null},{"url":"https://zachxbt.mirror.xyz/","name":"ZachXBT — Mirror.xyz Investigations Archive","type":"other","archive_url":"http://web.archive.org/web/20251025091919/https://zachxbt.mirror.xyz/","credibility":2,"archive_timestamp":"2025-10-25T09:19:19+00:00"},{"url":"https://beincrypto.com/learn/zachxbt-crypto-scam/","name":"Who Is ZachXBT, the Crypto Sleuth Exposing Scams? — BeInCrypto","type":"news_article","archive_url":"http://web.archive.org/web/20260122081536/https://beincrypto.com/learn/zachxbt-crypto-scam/","credibility":2,"archive_timestamp":"2026-01-22T08:15:36+00:00"},{"url":"https://scsfg.io/hackers/oracle-manipulation/","name":"Oracle Manipulation — Smart Contract Security Field Guide","type":"research","archive_url":"http://web.archive.org/web/20250807161254/https://scsfg.io/hackers/oracle-manipulation/","credibility":2,"archive_timestamp":"2025-08-07T16:12:54+00:00"},{"url":"https://x.com/RoeFinance","name":"ROE Finance Twitter / X Account","type":"social_media","archive_url":null,"credibility":3,"archive_timestamp":null}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-5","created_at":"2026-05-04T02:54:45.405787+00:00","updated_at":"2026-08-29T01:32:38.107+00:00"}}