Incident case file
Sign in to watchSilo Finance V2 — Isolated Leverage Contract Approval Exploit (Oracle Manipulation)
0 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: TODO — Etherscan-labelled Silo Finance Exploiter (multiple addresses flagged by Hypernative)
Timeline: On April 3, 2026, an attacker exploited a misconfigured oracle combined with overly broad approvals in Silo Finance V2 newly deployed isolated Leverage contract on Arbitrum. The vulnerability targeted the leverage smart contract improper input validation on swapArgs (user-controlled exchange proxy), allowing manipulation of the oracle during leveraged operations. 14:29 UTC Hypernative flags both attacker addresses, alerts CEXs. 14:47 UTC Silo team announces Leverage contract paused. 15:01 UTC Silo informs Certora. 15:30-17:00 UTC Certora war room confirms root cause; vulnerability strictly limited to leverage-module users; core Silo unaffected. Funds drained were Silo own (testing phase).
Sources and coverage
- Articlecertora.comhttps://www.certora.com/blog/silo-incident-report-contract-exploit
- Articlecryptotimes.iohttps://www.cryptotimes.io/2026/04/20/cryptos-635m-april-nightmare-15-hacks-30-days-worst-month-in-crypto-history/
- Articleblocksec.comhttps://blocksec.com/blog/weekly-web3-security-incident-roundup-apr-6-apr-12-2026
- Articlechainsec.iohttps://chainsec.io/defi-hacks
- Articlephemex.comhttps://phemex.com/blogs/defi-hacks-2026-bridge-exploits-explained
- Articlethestreet.comhttps://www.thestreet.com/crypto/markets/major-defi-hack-becomes-the-largest-of-2026-yet
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)