← Radar

Incident case file

Sign in to watch

Edel Finance — wGOOGLx/GOOGLx Oracle Manipulation — Whitehat Settlement Offered

Incident date July 1, 2026

1 views

ContainedEthereumOracle manipulation / wrapped exchange-rate exploitCluster: EDEL-ORACLE-2026-07

Estimated loss

$403.4K

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

75%

Facts and investigation

Attacker: 0x58428161bB55c14A413945f06cbDeC157F411C76

Funds moved to: Attacker swapped all six drained token balances for 224 ETH (~$353K) and deposited into Tornado Cash. Exploit transaction: 0xe2320086b2815d21b0927839bd0e306466c29a68d38d5361e99dd21ec5472612 (Block 25434062, 2026-07-01 00:24:47 UTC). Breakdown of assets drained in the single exploit tx: USDC $204,221.63, wSPYx $91,752.12, wQQQx $46,641.52, wMSTRx $25,274.87, wNVDAx $19,766.69, wTSLAx $15,744.96 — total $403,401.79. CertiK's initial alert (~$204K) covered only one affected market; the team later
Edel identified and paused all V1 lending contracts immediately upon detection. The team extended a formal whitehat settlement offer to the attacker, providing a defined window to return remaining funds in exchange for an authorized security bounty (status of negotiation not yet resolved as of last update). No other wallet addresses (victim treasury, deployer) were disclosed in available sources.

Timeline: T0 (2026-07-01, ~00:24:47 UTC, Block 25434062): Attacker exploits a wrapped xStocks exchange-rate manipulation between wGOOGLx and GOOGLx, causing wGOOGLx collateral to be valued at approximately 78x its correct value. The attacker uses the inflated collateral to borrow against 6 Edel Lending markets (wTSLAx, wNVDAx, wMSTRx, wQQQx, wSPYx, USDC), extracting a combined $403,401.79. T+minutes: All drained tokens are swapped for 224 ETH (~$353K) and deposited into Tornado Cash. T+same day (04:42 UTC): CertiK Alert publishes an initial alert citing ~$204K in losses on a single Edel Lending market (skylens.certik.com trace link). T+same day (04:42-15:x UTC): CertiK publishes a follow-up confirming 6 Edel markets were affected in total and that the attacker consolidated all proceeds into 224 ETH deposited to Tornado Cash. T+same day: Edel Finance publishes an official statement confirming the exploit, pausing all V1 contracts, committing to absorb the bad debt and restore all depositor balances 1:1 (no depositor bears any loss), announcing Edel V2 with a redesigned oracle architecture to prevent this exploit class, and confirming a formal whitehat settlement offer extended to the attacker with a defined return window in exchange for an authorized bug bounty. Root cause: the vulnerability was isolated to the wrapped xStocks exchange-rate mechanism (wGOOGLx/GOOGLx), not the underlying Chainlink oracle, which continued to report the correct GOOGL price (~$357) throughout the incident. Status as of report compilation: Contained, whitehat negotiation ongoing, full technical post-mortem promised but not yet published.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)