Incident case file
Sign in to watchSecured Finance Order-Book Price Manipulation, Intercepted by MEV Bot 'coffeebabe.eth' — $104K
0 views
Estimated loss
Affected users
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
1 beatOn September 5, 2026, an attacker exploited a flaw in Secured Finance's order-book price calculation, a fixed-rate lending protocol operating across Ethereum, Arbitrum and Filecoin. Rather than using an independent price feed, the protocol derived its own accounting price purely from same-block trades without verifying they occurred between genuine counterparties. The attacker used a flash loan to place both sides of a trade with themselves, pushing the recorded price to near-maximum, which caused the order book to record the attacker's lending position as vastly overvalued collateral. However, the attacker's own final withdrawal transaction reverted due to insufficient gas. Approximately 48 seconds later, an automated MEV bot known by the ENS name 'coffeebabe.eth' — a well-known searcher with a public history dating back to intercepting the July 2023 Curve Finance exploit and returning the funds — detected and front-ran the opportunity, capturing roughly 0.9 WBTC (~$72,000) and 28.8 ETH. True to its established pattern, the bot forwarded nearly all the intercepted ETH to the ultrasound.money block builder as a priority tip, retaining only about $29 for itself. A second, unrelated MEV bot captured the remaining USDC portion. Total loss to the protocol across all captured assets was approximately $104,000. Secured Finance's affected lending markets and TokenVaults remain paused on all three chains pending review.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)