{"investigation":{"slug":"uwu-lend","entity_name":"UwU Lend","trust_score":10,"severity_base":null,"score_modifier":0,"confidence":1,"status":"published","content_type":"investigation","summary":"UwU Lend is an Ethereum-based DeFi lending protocol forked from Aave V2, launched in September 2022 and operated by Michael Patryn (known pseudonymously as 0xSifu), a co-founder of the collapsed Canadian crypto exchange QuadrigaCX and a convicted felon. In June 2024, the protocol was exploited twice by the same attacker — first for approximately $19.3 million on June 10 and again for $3.7 million on June 13 — via oracle price manipulation using flash loans, bringing combined losses to approximately $23 million.","sections":[{"content":"UwU Lend is a non-custodial liquidity market protocol on Ethereum, launched in September 2022. The protocol's codebase is forked from Aave V2's open-source smart contract infrastructure. Its native token is UwU (contract: 0x55C08ca52497e2f1534B59E2917BF524D4765257 on Ethereum mainnet). UwU Lend differentiates itself from Aave through a revenue-sharing model that distributes half of all platform fees to token holders. The protocol accepted a range of collateral assets and operated without an on-chain governance system. According to Exponential DeFi, UwU Lend had no formal governance and used assets that other analysts characterized as risky as eligible collateral. The protocol was founded by Michael Patryn, operating under the pseudonym 0xSifu.","heading":"Background","sources":[{"url":"https://exponential.fi/protocols/uwu/bdf71040-0a05-48ee-a50b-87b7b621c852","name":"","type":"other","credibility":3},{"url":"https://etherscan.io/token/0x55C08ca52497e2f1534B59E2917BF524D4765257","name":"","type":"other","credibility":3},{"url":"https://medium.com/uwu-lend/part-two-uwu-lend-84e14ee58b76","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"On June 10, 2024, UwU Lend suffered a major exploit resulting in losses of approximately $19.3 million, later revised upward to roughly $19.5 million by various security researchers. The attacker (wallet: 0x841ddf093f5188989fa1524e7b893de64b421f47, labeled 'UwU Lend Exploiter' on Etherscan) executed a sophisticated multi-transaction flash loan attack. The exploit targeted a critical vulnerability in the protocol's sUSDe price oracle, which derived its price from the median of 11 sources, five of which were instantaneous spot prices from Curve Finance pools (FRAXUSDe, USDeUSDC, USDeDAI, USDecrvUSD, and GHOUSDe). The attacker took a flash loan of approximately $3.796 billion (reported variously as 40,000–80,000 ETH equivalent) from multiple DeFi protocols including Aave V2, Aave V3, Uniswap V3, Balancer, Maker, Spark, and Morpho. Using these borrowed funds, the attacker manipulated the price of sUSDe downward in the targeted Curve pools, artificially deflating the oracle's reported value to approximately $0.99, then reversed the manipulation to $1.03, triggering profitable liquidations of their own position. The exploit used the Curve Finance get_p function to read instantaneous spot prices — a method Curve Finance itself had explicitly warned against using in production oracles. The attacker repeatedly cycled through this borrow-manipulate-liquidate sequence within the same transaction block, compounding gains. Cyvers' threat monitoring systems raised an alert when the stolen amount reached approximately $14 million. By the time the protocol paused, confirmed losses were approximately $19.3 million in ETH, crvUSD, bLUSD, and USDC, which the attacker converted to ETH. Three key exploit transaction hashes documented by SlowMist include: 0xca1bbf3b320662c89232006f1ec6624b56242850f07e0f1dadbe4f69ba0d6ac3, 0xb3f067618ce54bc26a960b660cfc28f9ea0315e2e9a1a855ede1508eb4017376, and 0x242a0fb4fde9de0dc2fd42e8db743cbc197ffa2bf6a036ba0bba303df296408b. After the first exploit, the UwU Lend team paused the protocol and announced the vulnerability had been patched. On June 13, 2024 — just three days later — the same attacker executed a second exploit, draining an additional $3.7 million. The second attack did not require oracle manipulation; instead, the attacker used sUSDe tokens retained from the first exploit as collateral that the protocol still treated as legitimate, draining the uDAI, uWETH, uLUSD, uFRAX, uCRVUSD, and uUSDT pools. B.Protocol CEO Yaron Velner noted publicly that the second attack 'did not entail any manipulation — just malicious intent and erroneous configuration on UwU's side.' Combined losses from both exploits totaled approximately $23 million. In response to the first exploit, founder Michael Patryn (0xSifu) offered the attacker a 20% bounty (approximately $4 million) to return the remaining funds. The protocol subsequently committed to repaying all bad debt, and by the morning after the second exploit had repaid approximately $9.7 million of the original theft.","heading":"The Dual Exploits (June 2024)","sources":[{"url":"https://slowmist.medium.com/analysis-of-the-uwu-lend-hack-9502b2c06dbe","name":"","type":"other","credibility":3},{"url":"https://unchainedcrypto.com/uwu-lend-hacker-steals-another-3-7-million-from-protocol/","name":"","type":"other","credibility":3},{"url":"https://cryptonews.com/news/uwu-lend-reacts-to-23-million-hack-pauses-protocol-and-negotiates-with-hacker/","name":"","type":"other","credibility":3},{"url":"https://www.quillaudits.com/blog/hack-analysis/uwu-lend-hack","name":"","type":"other","credibility":3},{"url":"https://cryptoslate.com/hacker-drains-19-5-million-from-uwu-lend-in-price-oracle-exploit/","name":"","type":"other","credibility":3},{"url":"https://unchainedcrypto.com/0xsifu-offers-20-bounty-to-hackers-after-19-million-uwu-lend-exploit/","name":"","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/uwu-lend-hack-20-million","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"On-chain forensics have documented the attacker's full fund flow. The exploiter wallet (0x841ddf093f5188989fa1524e7b893de64b421f47) was initially funded with 0.98 ETH sourced from Tornado Cash in five separate transfers, indicating deliberate use of obfuscation tooling prior to the attack. Etherscan has permanently labeled this address as 'UwU Lend Exploiter.' Following the exploit, the attacker began moving and laundering funds through Tornado Cash. According to ChainCatcher/Paddle, approximately 1,000 ETH (equivalent to roughly $3.66 million) was transferred to Tornado Cash in an early laundering tranche. MerkleScience tracked further fund movements: 1,292.98 ETH was transferred to a secondary address (0x48d7c1dd4214b41eda3301bca434348f8d1c5eb6), and 4,000 ETH was transferred to a further staging address (0x050c7e9c62bf991841827f37745ddadb563feb70). By October 2024, a linked address had successfully laundered an additional 2,009 ETH through Tornado Cash, bringing the total laundered amount to approximately 6,353 ETH (based on BitcoinWorld reporting). The vulnerable smart contract address exploited in the first attack is documented as 0x9bc6333081266e55d88942e277fc809b485698b9. The attack's root cause — use of Curve Finance's get_p instantaneous spot price function in a production oracle without time-weighted averaging or smoothing — was identifiable from the contract code prior to the exploit, and the QuillAudits post-mortem noted this was contrary to Curve Finance's own documented warnings.","heading":"On-Chain Evidence","sources":[{"url":"https://etherscan.io/address/0x841ddf093f5188989fa1524e7b893de64b421f47","name":"","type":"other","credibility":3},{"url":"https://slowmist.medium.com/analysis-of-the-uwu-lend-hack-9502b2c06dbe","name":"","type":"other","credibility":3},{"url":"https://www.chaincatcher.com/en/article/2129245","name":"","type":"other","credibility":3},{"url":"https://www.merklescience.com/blog/investigating-the-uwu-lend-hack-and-flow-of-funds","name":"","type":"other","credibility":3},{"url":"https://bitcoinworld.co.in/uwu-lend-exploiter-launders-eth/","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"UwU Lend was founded by Michael Patryn, who operates under the pseudonym 0xSifu. Patryn was born Omar Dhanani and has a documented criminal history in the United States. He was arrested as part of a Secret Service sting operation targeting ShadowCrew, an online criminal organization, and in 2007 admitted to conspiring in separate criminal cases for burglary, grand larceny, and computer fraud. He subsequently served time in a U.S. federal prison and was deported to Canada, after which he changed his name twice — first to Omar Patryn, then to Michael Patryn — a pattern confirmed by The Globe and Mail through Canadian authorities. Patryn co-founded QuadrigaCX, a Canadian cryptocurrency exchange, alongside Gerald Cotten. Patryn states he departed from active involvement in 2016. QuadrigaCX collapsed in 2019 following the reported death of Cotten, with over $200 million in customer funds unaccounted for. The Ontario Securities Commission later determined that QuadrigaCX had operated as a Ponzi scheme. In January 2022, blockchain investigator ZachXBT publicly identified 0xSifu as Michael Patryn while 0xSifu was serving as the anonymous treasury manager and co-founder of Wonderland, a popular DeFi protocol that at its peak managed over $1 billion in assets. Following the doxxing, Wonderland's community voted to remove Patryn from his role. He subsequently returned to Wonderland in February 2022 following an informal community vote and was later hired as Risk Officer in September 2022 with approximately 90% approval. After the Wonderland controversy, Patryn launched UwU Lend in September 2022. Following the June 2024 exploits, Patryn responded publicly on behalf of the protocol, offered the hacker bounty negotiations, and committed to repaying bad debt — though the attacker did not return any funds. Critics and community observers have pointed to the combination of Patryn's background, the protocol's lack of formal governance, and the oracle design flaws as compounding risk factors that made UwU Lend a particularly high-risk protocol.","heading":"Team & Controversy (0xSifu Connection)","sources":[{"url":"https://en.wikipedia.org/wiki/Michael_Patryn","name":"","type":"other","credibility":3},{"url":"https://www.coindesk.com/markets/2022/01/27/wonderland-rattled-after-cofounder-tied-to-alleged-quadrigacx-190m-exit-scam","name":"","type":"other","credibility":3},{"url":"https://www.dlnews.com/articles/defi/uwu-founder-offers-bounty-to-settle-flash-loan-exploit/","name":"","type":"other","credibility":3},{"url":"https://protos.com/sifus-uwu-lend-reportedly-hacked-for-20m-curves-egorov-among-affected/","name":"","type":"other","credibility":3},{"url":"https://beincrypto.com/wonderland-cfo-outed-as-ex-convict-and-quadrigacx-co-founder-michael-patryn-steps-down/","name":"","type":"other","credibility":3},{"url":"https://watcher.guru/news/crypto-scandal-defi-project-wonderland-is-run-by-felon-michael-patryn-with-ties-to-quadrigacx-fraud","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"UwU Lend presents a confluence of severe risk factors across technical security, operational governance, and founder credibility dimensions. On the technical side, the protocol's oracle design relied on instantaneous spot prices from Curve Finance pools — a methodology explicitly discouraged by Curve Finance — creating a directly exploitable flash loan attack surface. This vulnerability was reportedly cleared by auditors prior to the exploits, raising questions about audit quality and scope. The second exploit occurring three days after the first, despite the team's claim of a patch, demonstrates inadequate post-incident response and a failure to account for residual attacker collateral positions. On the governance side, the protocol operated without formal on-chain governance, concentrating decision-making with Patryn and the team. No community mechanism existed to enact emergency risk parameter changes or collateral policy revisions. From a founder credibility standpoint, Michael Patryn (0xSifu) has a documented criminal history (burglary, grand larceny, computer fraud), was co-founder of an exchange that the Ontario Securities Commission determined operated as a Ponzi scheme (QuadrigaCX), and was removed from a prior DeFi treasury role (Wonderland) following community backlash upon doxxing. The attacker funded operations via Tornado Cash and subsequently laundered proceeds through Tornado Cash, with no known asset recovery as of mid-2024. The protocol's commitment to repay bad debt was partially fulfilled ($9.7 million repaid), but the remaining gap and the full absence of fund recovery leave users with material unrecovered losses. Given the combination of a confirmed $23 million exploit, documented oracle security failures, a founder with a serious criminal record and prior involvement in a collapsed exchange, no governance framework, and extensive use of Tornado Cash by the attacker with no recovery, UwU Lend carries an extremely high risk profile. Users should treat any remaining protocol interactions as high risk of total loss.","heading":"Risk Assessment","sources":[{"url":"https://cyvers.ai/blog/uwu-lend-23m-exploit-oracle-vulnerabilities-exposed","name":"","type":"other","credibility":3},{"url":"https://www.quillaudits.com/blog/hack-analysis/uwu-lend-hack","name":"","type":"other","credibility":3},{"url":"https://exponential.fi/protocols/uwu/bdf71040-0a05-48ee-a50b-87b7b621c852","name":"","type":"other","credibility":3},{"url":"https://cryptobriefing.com/uwu-lend-second-hack-update/","name":"","type":"other","credibility":3},{"url":"https://en.wikipedia.org/wiki/Michael_Patryn","name":"","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2022-01-27","event":"ZachXBT publicly identifies 0xSifu as Michael Patryn, co-founder of QuadrigaCX; Wonderland community votes to remove him from treasury management role","source":""},{"date":"2022-02","event":"Patryn returns to Wonderland following an informal community vote","source":"","date_original":"2022-02-01"},{"date":"2022-09","event":"UwU Lend launches on Ethereum mainnet, forked from Aave V2, founded by Michael Patryn (0xSifu)","source":"","date_original":"2022-09-01"},{"date":"2024-06-10","event":"First exploit: Attacker (0x841ddf093f5188989fa1524e7b893de64b421f47) manipulates UwU Lend's sUSDe oracle via Curve Finance spot prices using a ~$3.796 billion flash loan, draining approximately $19.3 million in ETH, crvUSD, bLUSD, and USDC; protocol paused by team","source":""},{"date":"2024-06-11","event":"Michael Patryn (0xSifu) offers the attacker a 20% bounty (approximately $4 million) to return stolen funds; team announces vulnerability patched","source":""},{"date":"2024-06-13","event":"Second exploit: Same attacker uses residual sUSDe collateral from first hack to drain uDAI, uWETH, uLUSD, uFRAX, uCRVUSD, and uUSDT pools for an additional $3.7 million; combined losses reach approximately $23 million","source":""},{"date":"2024-06-14","event":"Protocol reports repayment of approximately $9.7 million in bad debt; attacker does not return funds","source":""},{"date":"2024-06-15","event":"Attacker transfers approximately 1,000 ETH (roughly $3.66 million) to Tornado Cash in initial laundering tranche","source":""},{"date":"2024-10-09","event":"Linked attacker address launders an additional 2,009 ETH through Tornado Cash; total laundered by associated addresses reaches approximately 6,353 ETH","source":""}],"sources_used":[{"url":"https://exponential.fi/protocols/uwu/bdf71040-0a05-48ee-a50b-87b7b621c852","name":"","type":"other","archive_url":"http://web.archive.org/web/20250915064056/https://exponential.fi/protocols/uwu/bdf71040-0a05-48ee-a50b-87b7b621c852","credibility":3,"archive_timestamp":"2025-09-15T06:40:56+00:00"},{"url":"https://etherscan.io/token/0x55C08ca52497e2f1534B59E2917BF524D4765257","name":"","type":"other","archive_url":"http://web.archive.org/web/20251018153851/https://etherscan.io/token/0x55C08ca52497e2f1534B59E2917BF524D4765257","credibility":3,"archive_timestamp":"2025-10-18T15:38:51+00:00"},{"url":"https://medium.com/uwu-lend/part-two-uwu-lend-84e14ee58b76","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://slowmist.medium.com/analysis-of-the-uwu-lend-hack-9502b2c06dbe","name":"","type":"other","archive_url":"http://web.archive.org/web/20260303135803/https://slowmist.medium.com/analysis-of-the-uwu-lend-hack-9502b2c06dbe","credibility":3,"archive_timestamp":"2026-03-03T13:58:03+00:00"},{"url":"https://unchainedcrypto.com/uwu-lend-hacker-steals-another-3-7-million-from-protocol/","name":"","type":"other","archive_url":"https://web.archive.org/web/20260830003105/https://unchainedcrypto.com/uwu-lend-hacker-steals-another-3-7-million-from-protocol/","credibility":3,"archive_timestamp":"2026-08-30T00:31:05+00:00"},{"url":"https://cryptonews.com/news/uwu-lend-reacts-to-23-million-hack-pauses-protocol-and-negotiates-with-hacker/","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.quillaudits.com/blog/hack-analysis/uwu-lend-hack","name":"","type":"other","archive_url":"http://web.archive.org/web/20260515104856/https://www.quillaudits.com/blog/hack-analysis/uwu-lend-hack","credibility":3,"archive_timestamp":"2026-05-15T10:48:56+00:00"},{"url":"https://cryptoslate.com/hacker-drains-19-5-million-from-uwu-lend-in-price-oracle-exploit/","name":"","type":"other","archive_url":"https://web.archive.org/web/20260830042518/https://cryptoslate.com/hacker-drains-19-5-million-from-uwu-lend-in-price-oracle-exploit/","credibility":3,"archive_timestamp":"2026-08-30T04:25:18+00:00"},{"url":"https://unchainedcrypto.com/0xsifu-offers-20-bounty-to-hackers-after-19-million-uwu-lend-exploit/","name":"","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://cointelegraph.com/news/uwu-lend-hack-20-million","name":"","type":"other","archive_url":"http://web.archive.org/web/20260725213830/https://cointelegraph.com/news/uwu-lend-hack-20-million","credibility":3,"archive_timestamp":"2026-07-25T21:38:30+00:00"},{"url":"https://etherscan.io/address/0x841ddf093f5188989fa1524e7b893de64b421f47","name":"","type":"other","archive_url":"http://web.archive.org/web/20251018233910/https://etherscan.io/address/0x841dDf093f5188989fA1524e7B893de64B421f47","credibility":3,"archive_timestamp":"2025-10-18T23:39:10+00:00"},{"url":"https://www.chaincatcher.com/en/article/2129245","name":"","type":"other","archive_url":"https://web.archive.org/web/20260829185352/https://www.chaincatcher.com/en/article/2129245","credibility":3,"archive_timestamp":"2026-08-29T18:53:52+00:00"},{"url":"https://www.merklescience.com/blog/investigating-the-uwu-lend-hack-and-flow-of-funds","name":"","type":"other","archive_url":"http://web.archive.org/web/20260308034314/https://www.merklescience.com/blog/investigating-the-uwu-lend-hack-and-flow-of-funds","credibility":3,"archive_timestamp":"2026-03-08T03:43:14+00:00"},{"url":"https://bitcoinworld.co.in/uwu-lend-exploiter-launders-eth/","name":"","type":"other","archive_url":"https://web.archive.org/web/20260829232937/https://bitcoinworld.co.in/uwu-lend-exploiter-launders-eth/","credibility":3,"archive_timestamp":"2026-08-29T23:29:37+00:00"},{"url":"https://en.wikipedia.org/wiki/Michael_Patryn","name":"","type":"other","archive_url":"http://web.archive.org/web/20251002115617/https://en.wikipedia.org/wiki/Michael_Patryn","credibility":3,"archive_timestamp":"2025-10-02T11:56:17+00:00"},{"url":"https://www.coindesk.com/markets/2022/01/27/wonderland-rattled-after-cofounder-tied-to-alleged-quadrigacx-190m-exit-scam","name":"","type":"other","archive_url":"http://web.archive.org/web/20250103225729/https://www.coindesk.com/markets/2022/01/27/wonderland-rattled-after-cofounder-tied-to-alleged-quadrigacx-190m-exit-scam","credibility":3,"archive_timestamp":"2025-01-03T22:57:29+00:00"},{"url":"https://www.dlnews.com/articles/defi/uwu-founder-offers-bounty-to-settle-flash-loan-exploit/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260625015533/https://www.dlnews.com/articles/defi/uwu-founder-offers-bounty-to-settle-flash-loan-exploit/","credibility":3,"archive_timestamp":"2026-06-25T01:55:33+00:00"},{"url":"https://protos.com/sifus-uwu-lend-reportedly-hacked-for-20m-curves-egorov-among-affected/","name":"","type":"other","archive_url":"https://web.archive.org/web/20260829141007/https://protos.com/sifus-uwu-lend-reportedly-hacked-for-20m-curves-egorov-among-affected/","credibility":3,"archive_timestamp":"2026-08-29T14:10:07+00:00"},{"url":"https://beincrypto.com/wonderland-cfo-outed-as-ex-convict-and-quadrigacx-co-founder-michael-patryn-steps-down/","name":"","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://watcher.guru/news/crypto-scandal-defi-project-wonderland-is-run-by-felon-michael-patryn-with-ties-to-quadrigacx-fraud","name":"","type":"other","archive_url":"http://web.archive.org/web/20260311163717/https://watcher.guru/news/crypto-scandal-defi-project-wonderland-is-run-by-felon-michael-patryn-with-ties-to-quadrigacx-fraud","credibility":3,"archive_timestamp":"2026-03-11T16:37:17+00:00"},{"url":"https://cyvers.ai/blog/uwu-lend-23m-exploit-oracle-vulnerabilities-exposed","name":"","type":"other","archive_url":"http://web.archive.org/web/20260419110343/https://cyvers.ai/blog/uwu-lend-23m-exploit-oracle-vulnerabilities-exposed","credibility":3,"archive_timestamp":"2026-04-19T11:03:43+00:00"},{"url":"https://cryptobriefing.com/uwu-lend-second-hack-update/","name":"","type":"other","archive_url":"http://web.archive.org/web/20251205084309/https://cryptobriefing.com/uwu-lend-second-hack-update/","credibility":3,"archive_timestamp":"2025-12-05T08:43:09+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-5","created_at":"2026-05-04T02:54:31.838774+00:00","updated_at":"2026-08-30T05:14:07.715934+00:00"}}