Share on XShare on LinkedInShare on Telegram
Security Decisions/ After launchWeb3 Security

Understanding Price Oracle Manipulation Attacks in DeFi

Price oracle manipulation jumped to SC03 in OWASP's 2026 Smart Contract Top 10 — and Loopscale, KiloEx, Palmswap, and Bunni V2 show why. Learn how flash loans, TWAP exploits, forged signatures, and stale feeds let attackers feed contracts false prices, the four-step attack chain behind losses like GMX's $42M, and how aggregation, deviation checks, and audits help prevent it.

Author
QuillAudits Team
•January 1, 1970
Understanding Price Oracle Manipulation Attacks in DeFi
Share on XShare on LinkedInShare on Telegram

The decision · answer in brief

Price oracle manipulation jumped to SC03 in OWASP's 2026 Smart Contract Top 10 — and Loopscale, KiloEx, Palmswap, and Bunni V2 show why. Learn how flash loans, TWAP exploits, forged signatures, and stale feeds let attackers feed contracts false prices, the four-step attack chain behind losses like GMX's $42M, and how aggregation, deviation checks, and audits help prevent it.

Blockchain Oracle Security: Understanding Price Manipulation

Blockchain oracle security comes down to one question: can a smart contract trust the price it just received? This post explains how price oracle manipulation attacks work, why OWASP promoted the category to SC03 in its 2026 Smart Contract Top 10, and what recent hacks like Loopscale, KiloEx, Palmswap, and Bunni V2 reveal about preventing the next one.

If you're building a lending market, a perpetuals exchange, or anything that liquidates positions based on price, this is the vulnerability class most likely to end your protocol in a single transaction.

What Is Price Oracle Manipulation?

An oracle feeds off-chain or on-chain price data into a smart contract that has no native way to know what an asset is worth. Price oracle manipulation happens when an attacker distorts that data, or exploits a weakness in how it's delivered, so the contract acts on a number that doesn't reflect real market conditions.

OWASP's Smart Contract Top 10 2026 defines it plainly: "Price oracle manipulation describes any situation where a smart contract relies on price or valuation data that can be directly or indirectly influenced by an attacker, causing the protocol to make decisions based on incorrect values." That covers a wide range of techniques, from pumping a thin liquidity pool to forging a signed price update, but the outcome is always the same. The contract believes a lie and acts on it.

If you need the basics on how oracles work before diving into attacks on them, QuillAudits' blockchain oracle explainer covers Decentralized Oracle Networks and provider models. This post assumes that baseline and focuses on what goes wrong.

Why Oracles Are a Trust Boundary in DeFi

OWASP frames oracles as a trust boundary: "Oracles are trust boundaries: the contract implicitly trusts that the price it receives reflects real-world or on-chain market conditions." A trust boundary is the point where a system stops verifying and starts assuming. Once a contract crosses that line, every downstream decision, collateral valuation, liquidation threshold, swap rate, inherits whatever the oracle handed it.

That's what makes oracle manipulation different from a typical logic bug. The contract code can be flawless and still get exploited, because the vulnerability sits in the data source, not the data consumer. A lending protocol with airtight liquidation math still liquidates the wrong way if the price feed it reads is wrong.

How Do Attackers Break Blockchain Oracle Security?

Attackers manipulate oracles in three broad ways: they distort the market price an on-chain oracle reads in real time, they exploit a short or thin measurement window like a TWAP (Time-Weighted Average Price), or they abuse stale, unsigned, or poorly validated data feeds. Each targets a different weak point in the pricing pipeline, and protocols often get hit by combinations of them.

Spot Price Manipulation via Flash Loans and JIT Liquidity

The most common technique borrows a large sum through a flash loan, an uncollateralized loan that must be repaid within the same transaction, and uses it to swap heavily against a pool the target protocol reads for pricing. If the oracle pulls its price straight from that pool's reserves, a single large swap can move the reported price far from the real market rate before anyone reacts.

The NGP Token exploit in September 2025 followed this pattern almost exactly: the protocol's getPrice() function relied solely on DEX pair reserves, which an attacker skewed with a flash loan to steal roughly $2 million, according to OWASP's Smart Contract Top 10 2026.

Just-in-time (JIT) liquidity variants work the other way. An attacker adds a large amount of liquidity right before a price-sensitive transaction and removes it immediately after, briefly changing the pool's composition (and its reported price) in a narrow window designed to catch exactly one victim transaction.

TWAP Window Manipulation in Low-Liquidity Pools

Time-Weighted Average Price feeds exist specifically to blunt single-block manipulation, averaging price over a window instead of reading the instantaneous spot price. But a TWAP is only as resistant as its window is long and its underlying pool is deep. In a low-liquidity pool, an attacker with enough capital, often borrowed, can sustain a skewed price across multiple blocks within a short TWAP window and still move the average meaningfully.

This is why a short TWAP window on a thin pool gives a false sense of security. The mechanism is sound in principle; the parameters chosen around it are what usually fail.

Stale Data, Signer Compromise, and Poor Deviation Checks

Not every oracle failure is an active price attack. Some are failures to update, validate, or verify at all. A feed that stops refreshing and freezes at its last known value can be just as dangerous as one that's actively manipulated, especially for a tokenized real-world asset whose price should be moving. QuillAudits' coverage of Coinbase's tokenized-stock oracle risk walks through exactly this failure mode: Chainlink's equity feed pricing tokens like AAPLc and AMZNc only carries real market data five days a week, so it freezes at Friday's close while on-chain trading continues through the weekend.

Signer-based oracles carry a different risk: if the private keys or infrastructure signing price updates are compromised, an attacker can push arbitrary "valid" prices without touching any on-chain liquidity at all. QuillAudits' analysis of the Ostium price report signer compromise is a useful contrast case here: it's an infrastructure compromise, not an on-chain manipulation, but it lands the attacker in the same place, a price the contract wrongly trusts. And even with valid signatures and fresh data, a protocol that skips deviation checks, sanity limits on how far a new price can move from the last one, will accept a forged or extreme value without complaint.

Why Did OWASP Rank This SC03 in the 2026 Smart Contract Top 10?

The Common Attack Chain: Flash Loan, Oracle Manipulation, Logic Flaw, Extraction

OWASP describes a recurring four-step chain behind most oracle manipulation losses:

  1. Flash loan supplies the attacker with capital far beyond their own holdings, repayable within the same transaction.
  2. Oracle manipulation uses that capital to skew the price a target contract reads.
  3. Business-logic flaw lets the distorted price open an undercollateralized position, mint against inflated collateral, or trigger a liquidation that shouldn't happen.
  4. Unchecked external call lets the attacker withdraw or extract the resulting funds before the price (or the protocol) can correct itself.

GMX's July 2025 exploit shows how this chain plays out even when oracle manipulation is the enabler rather than the primary bug. Attackers pushed the global BTC short price down roughly 57 times using flash loans, then redeemed GLP tokens at the resulting inflated value, a sequence that cost the protocol $42 million, per OWASP's writeup. Reentrancy was the root technical flaw, but the price manipulation is what made the reentrant call profitable at that scale.

Real Exploits: What Recent Hacks Reveal

The clearest way to understand oracle manipulation is to look at how it actually happened, not just how it could. Four exploits from QuillAudits' hack-analysis coverage cover most of the failure modes above: mispriced collateral, forged signatures, and AMM spot-price manipulation combined with a rounding bug.

ProtocolDateLossMechanism
LoopscaleApril 26, 2025$5.8MVault mispriced RateX PT tokens as collateral
KiloExApril 14, 2025$7.4MForged signed price data via an exposed TrustedForwarder
PalmswapJuly 25, 2023~$900kManipulated USDP/PLP exchange-rate calculation
Bunni V2September 2, 2025$8.3-8.4MSwap-driven price shift combined with a withdrawal rounding error

Loopscale's $5.8M Vault Mispricing (April 2025)

On April 26, 2025, Loopscale lost $5.8 million, about 12% of the protocol's total value locked, after an attacker manipulated how the protocol's vault priced RateX PT tokens used as collateral. Once the vault reported an inflated valuation for those tokens, the attacker borrowed against collateral that was worth far less than the contract believed.

QuillAudits' analysis of the Loopscale exploit recommends using a Time-Weighted Average Price for pricing assets like this specifically to prevent this class of vulnerability, since a TWAP would have smoothed out the momentary distortion the attacker created rather than pricing the collateral off a manipulable snapshot.

KiloEx's $7.4M Signature Bypass (April 2025)

KiloEx's April 14, 2025 exploit shows what happens when the oracle's delivery mechanism, not just its price source, is exposed. A publicly accessible TrustedForwarder contract let an attacker submit forged signed price data. The attacker first set ETH's price to $100 and opened a leveraged position, then repriced ETH to $10,000 to extract funds against that position. Total losses reached $7.4 million across chains, with $3.4 million drained from the Base vault alone, according to QuillAudits' breakdown.

Here's the catch: the underlying signature scheme wasn't broken. The forwarder contract that was supposed to gate who could submit signed prices simply wasn't restricted, so the attacker didn't need to compromise a signer at all, just call a function that should never have been public.

Palmswap and Bunni V2: Spot-Price Manipulation in AMMs

Palmswap and Bunni V2 sit two years apart but land on the same underlying problem: an automated market maker's own trading activity can be turned into an oracle input, and an attacker who can move that activity can move the price.

Palmswap lost roughly $900,000 on July 25, 2023, when an attacker exploited a flaw in how the exchange rate between USDP and PLP was calculated during liquidity add and remove operations, according to QuillAudits' exploit writeup. Manipulating that calculation during the add/remove sequence let the attacker extract value the pool never actually held.

Bunni V2's exploit on September 2, 2025 combined two failures at once. An attacker used swaps to shift the pool's price dynamics, then exploited a precision and rounding error in the protocol's withdrawal logic to drain funds, costing $2.4 million on Ethereum and $5.9 million on UniChain for a total of $8.3 to $8.4 million, per QuillAudits' analysis. It's worth being precise about the root cause here: the rounding bug did the actual damage, but it was only reachable because the attacker could push the pool's price where the rounding error became exploitable. That combination, price manipulation opening the door for a separate logic flaw, is the same pattern OWASP describes in its four-step attack chain above.

Both cases sit within a broader set of DeFi attack surfaces; QuillAudits' DeFi attack vectors guide lists oracle manipulation as one of several named vectors worth reviewing alongside reentrancy and flash loan abuse. And if your concern is specifically prediction markets rather than lending or perps, oracle resolution attacks target a related but distinct surface: manipulating how a market resolves rather than what price it reads mid-trade.

How Do You Strengthen Blockchain Oracle Security?

No single fix closes off price oracle manipulation entirely, because the attack surface spans data sourcing, aggregation, timing, and access control. Effective prevention layers multiple defenses so that beating one still leaves an attacker facing the next.

Aggregate Sources, Enforce TWAP Windows and Staleness Thresholds

Pulling a price from a single pool or a single signer gives an attacker one target to manipulate. Aggregating multiple independent sources, and rejecting a price if those sources disagree beyond a set tolerance, removes the single point of failure. Layer that with an appropriately sized TWAP window, long enough that a flash-loan-funded attacker can't sustain a skewed price across it, and a staleness threshold that rejects any price older than a defined limit, so a frozen feed can't silently pass as current.

Circuit Breakers, Deviation Checks, and Independent Audits

Deviation checks reject a new price update that moves too far from the last accepted value in too short a time, catching exactly the kind of spike KiloEx's forged $100-to-$10,000 ETH price would have triggered had one been in place. Circuit breakers take that further, pausing price-sensitive functions like borrowing, minting, or liquidation entirely when a deviation threshold is crossed, buying time for a human or a watchdog contract to review before funds move.

None of these mechanisms are self-verifying. A DeFi Protocol Audit can review a lending platform, DEX, or yield aggregator's oracle integration against exactly this checklist, since QuillAudits' DeFi Protocol Audit service explicitly lists oracle manipulation among the vulnerability classes it tests for through manual review and automated testing. Worth being clear about what an audit is and isn't: it's a point-in-time engagement, so it reduces the odds that a known manipulation pattern slips into production, but it can't catch a genuinely novel attack technique discovered after launch.

Final Thoughts

Price oracle manipulation earned its SC03 ranking in OWASP's 2026 Smart Contract Top 10 because it keeps working, on new protocols, with new variations, against defenses that looked sufficient until an attacker with a flash loan proved otherwise. Loopscale, KiloEx, Palmswap, and Bunni V2 span two years and four different specific mechanisms, but every one of them comes back to a contract trusting a price it should have verified more carefully.

If you're designing or reviewing a protocol that prices anything on-chain, treat the oracle integration as its own attack surface, not a solved problem you inherit from a provider. A DeFi Protocol Audit is a reasonable place to start checking that integration before launch. For a deeper technical reference on the category, OWASP's SC03 Price Oracle Manipulation page is worth reading directly, and QuillAudits' research section tracks ongoing hack analysis as new exploits surface.

Explore more Security Decisions

Contents

Tell Us About Your Project
Subscribe to Newsletter
hashing bits image
Loading...

WE SECURE EVERYTHING YOU BUILD.

From day-zero risk mapping to exchange-ready audits, QuillAudits helps projects grow with confidence. Smart contracts, dApps, infrastructure, compliance: secured end to end.

QuillAudits Logo


ISO 27001Circle Alliance Program
Uniswap FoundationAethiropt-collectivePolygon SPNBNB Chain Kickstart

All Rights Reserved. © 2026. QuillAudits - LLC