Share this article

How Deus Finance Was Exploited for $13.4M on Fantom

The attack, which used a flash loan, was the second in two months.

Updated Apr 9, 2024, 11:48 p.m. Published Apr 28, 2022, 8:13 a.m.
(Sitade/Getty Images)
(Sitade/Getty Images)

Decentralized finance (DeFi) application Deus Finance was exploited for the second time in two months, with the attacker gaining more than $13.4 million of cryptocurrency in early Asian hours today, security researchers at PeckShield said in a tweet. The exploit occurred on the Fantom Network.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the The Protocol Newsletter today. See all newsletters
  • Deus allows developers to build financial services such as futures trading, lending and options on its platform. (Disclosure: The writer of this report is a liquidity provider for Deus on Ethereum, Fantom and BNB Chain.)
  • The attacker used a flash loan to trick the way Deus's smart contracts read data on the platform’s liquidity pools. This allowed the attacker to artificially inflate the value of some assets, borrow funds and make a profit after repaying the loan.
  • Some $143 million were borrowed as a flash loan, blockchain data appear to show. The hacker was able to make a profit of $13.4 million. PeckShield said the total losses to the protocol could be much higher.
  • The Deus ecosystem comprises two tokens: DEUS and DEI. DEUS is the governance token on the platform. Minting DEI, a stablecoin pegged 1:1 to the U.S. dollar, burns DEUS, and redeeming DEI mints DEUS, according to developer documents.
  • Thursday’s exploit was the second in two months on the protocol, which was attacked in a similar manner in March for $3 million.

How the attack took place

Using the flash loan, Deus’ attackers were able to temporarily manipulate prices on a liquidity pool consisting of the USD coin (USDC) stablecoin and DEI, and use the manipulated DEI price to borrow and drain the pool.

Flash loans allow DeFi users to take out millions of dollars as a loan against zero collateral. This isn’t crypto magic or free money: The loan must be repaid before the transaction ends or the smart contract reverses the transaction – as if the loan never existed.

On the other end, liquidity pools, such as the USDC and DEI pool on Deus, rely on so-called oracles to ensure they are correctly priced at all times and any borrowing is within limits that don’t exceed the total value of those pools. Oracles are blockchain-based tools that provide smart contracts with trusted external information. These are required because blockchains can immutably store data, but can’t verify if the input data are accurate.

On Thursday, the attackers were able to take out a flash loan of over 143 million USDC, and used that to swap 9.5 million DEI, according to PeckShield. This caused the price of DEI to suddenly become more expensive than the usual exchange rate of $1.

How the hacker made away with $13.4 million. (PeckShield)
How the hacker made away with $13.4 million. (PeckShield)

The attacker then used some 71,000 DEI to borrow over 17.2 million DEI using the manipulated prices. The flash loan was then repaid, and the attacker managed to pocket $13.4 million.

DEUS prices fell 16.5% in the past 24 hours, CoinGecko data show. A bulk of these losses came after the exploit was made public. Deus had not responded to a request for comment by publication time.

More For You

Protocol Research: GoPlus Security

GP Basic Image

What to know:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.

More For You

NFT Project Pudgy Penguins Takes Over Las Vegas Sphere in Holiday Campaign

Pudgy Penguins NFT are on a holiday rally. (Screenshot)

The NFT brand’s animated segments will air on the Sphere across Christmas week, signaling the crypto company's move into real-world consumer markets.

What to know:

  • Pudgy Penguins will run an ad campaign at the Las Vegas Sphere during Christmas week, one of the few crypto brands to secure a spot at the high-profile venue.
  • The NFT project, which launched on Ethereum in 2021, has expanded into physical toys and digital gaming as part of a broader consumer push.
  • Pudgy Penguins briefly overtook Bored Apes in floor price earlier this year and recently launched its PENGU token on Solana, now trading on major exchanges.