Inverse Finance said on April 2, 2022 that its Anchor money market had been exploited after an attacker manipulated the price oracle for INV, the protocol’s governance token. The attacker then used the inflated collateral value to borrow DOLA, ether, wrapped bitcoin and YFI. Inverse put the borrowed assets’ contemporaneous value at approximately $15.6 million.
The incident mattered beyond one mid-sized decentralized-finance lender. Anchor’s contracts performed loans against a price supplied by an oracle, but the reference market could be moved with enough capital. The episode exposed how a lending system can remain operational at the code level while its economic assumptions fail.
A thin market became the attack surface
Inverse’s April 2 account said the attacker targeted the INV/ETH price oracle using trades on SushiSwap. The purchases drove INV sharply higher in the market observed by the oracle. The attacker deposited the newly acquired INV through the protocol, received xINV, and borrowed assets against the resulting collateral valuation before ordinary trading could restore the price.
CoinDesk’s April 2 report, citing Inverse and security firm PeckShield, identified the borrowed amounts as 1,588 ETH, 94 WBTC, 39 YFI and 3,999,669 DOLA. Those quantities are more precise than the dollar headline. The $15.6 million figure was an event-day valuation of four volatile or market-linked assets, not a withdrawal of $15.6 million in cash, and the source did not publish one common price timestamp for converting every asset.
The same report said the attacker had first withdrawn 901 ETH from Tornado Cash and used the capital across decentralized-exchange trades. The Block reported that the central manipulation involved 500 ETH and that blockchain records placed the key exploit transaction just after 11:00 UTC. The Etherscan transaction record fixes the main on-chain execution at April 2, 2022, while attribution of intent and control remained analytical rather than a legal finding.
Why the oracle design mattered
An oracle connects a smart contract to prices formed elsewhere. For a lending market, that price determines how much a borrower’s collateral is worth and therefore how much the borrower may take out. If the observed trading pool is shallow enough, a large trade can distort the reference price even when the underlying tokens and lending contracts continue functioning as programmed.
This was not described on April 2 as a conventional private-key theft. Nor was the manipulation itself a simple flash-loan-funded trade. The attacker committed substantial capital, creating the risk that arbitrageurs could reverse the distortion before the borrowing sequence completed. That distinction matters because defenses designed primarily to block same-transaction flash-loan manipulation did not necessarily stop a well-funded sequence spanning successive blocks.
Inverse said on April 2 that it paused borrowing on Anchor. CoinDesk also reported that the protocol planned to work with Chainlink on a replacement INV oracle and intended to propose full reimbursement for wallets affected by the manipulation. Those were response commitments on April 2, not proof that an oracle migration or repayment had already been completed.
Institutional lesson on April 2
The verified development was a protocol loss and emergency shutdown, not a broad crypto-market move. No bitcoin, ether or INV return is calculated here because the reviewed sources do not supply a consistent exchange, currency pair, start time and end time from which to isolate an event response.
For lenders, the immediate issue was the full dependency chain behind a collateral price: liquidity depth, observation window, update logic and the speed at which an attacker could borrow against a distorted reading. Governance and open-source contracts could make those rules visible, but visibility alone did not make the economic input resistant to manipulation.
Later context
On April 4, 2022, Inverse’s fuller incident account attributed the failure to an error in the time-weighted-average-price oracle’s sampling method and reiterated the approximately $15.6 million total. On April 13, an Inverse governance proposal described the manipulation as capital-intensive and linked it to a new risk-working-group proposal. A June 21 technical review by CertiK reconstructed the principal transaction and estimated approximately $14.5 million of asset loss, illustrating how valuation time and methodology can produce a different dollar total from Inverse’s event-day figure.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

