• The white hat hacker was able to exploit an oracle glitch on the Arbitrum-based decentralized finance (DeFi) lending platform Tender.fi and stole $1.59 million worth of crypto assets.
• The hacker left an on-chain message for Tender.fi and negotiated a bounty agreement with the project’s official Twitter handle.
• The exploiter returned nearly all the funds, keeping roughly $97,000 as a reward.

Tender.fi Exploit

On March 7, a white hat hacker exploited an oracle glitch on the Arbitrum-based decentralized finance (DeFi) lending platform Tender.fi and stole $1.59 million worth of crypto assets with just a deposit of one GMX token worth $71 as collateral. The hacker left an on-chain message for Tender.fi, saying, „It looks like your oracle was misconfigured. contact me to sort this out.“


A few hours after the incident happened, Tender.fi disclosed that it had contacted the attacker to negotiate and discuss the terms of a bounty agreement in order to remedy the situation peacefully without any further damage done to its system or users‘ funds involved in it; however, no details were revealed yet about what kind of agreement they reached out at that time but they did confirm that they will update us with more information when they have it soon enough afterwards when everything is settled down between both parties.

Returned Funds

Afterwards, nine hours after exploiting the bug successfully, the white hat hacker returned nearly all those stolen funds back to their original holders, keeping roughly around $97,000 as his reward for finding the bug.

Ongoing Investigations

Investigations are still ongoing into what exactly happened during this incident and further details are awaited into what other arrangements were made between both parties.


In conclusion, this exploit has proven how vulnerable DeFi platforms can be even with minimal security measures implemented, and why extra precautions need to be taken by developers while building such platforms going forward.

