← Radar

Incident case file

Sign in to watch

Rhea Finance — Fake Token Pool / Margin Trading Exploit (NEAR Protocol)

Incident date April 16, 2026

0 views

Partially recoveredNEAR ProtocolEthereumZcashOracle manipulationCluster: RHEA-NEAR-2026-04

Estimated loss

$18.4M

Victims identified

8
Victim group joining is coming soon.

Investigation

55%

Facts and investigation

Attacker: 0xBb5Fa936469CaDb8907f3aEF80F5B53f55Bc11f6

Funds moved to: Multiple NEAR + Ethereum + Zcash addresses. 3,495,342 USDC returned to 0x237e67d9cAcAD42b4aCE31d61f444d14BEA78E39. 13,500 ZEC routed into Zcash shielded pool (cryptographically unrecoverable).
USDC return address: 0x237e67d9cAcAD42b4aCE31d61f444d14BEA78E39. Original USDC source: 0xBb5Fa936469CaDb8907f3aEF80F5B53f55Bc11f6.

Timeline: April 16, 2026 — CertiK Alert flags exploit; initial estimate $7.6M. Attacker deployed fake token contracts on NEAR and added liquidity to freshly created pools, tricking the margin parser into accepting fake collateral. Opened large number of undercollateralized margin positions → forced liquidations drained the reserve pool. Tether freezes $3.29M USDT same day. NEAR Intents co-founder sends on-chain message identifying the attacker. April 17 — First partial return: 3,495,342 USDC transferred back. Post-mortem revises total losses to $18.4M. 13,500 ZEC (~$4.5M) permanently lost in Zcash shielded pool.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)