Rari Capital said an attacker drained approximately 2,600 ETH from its Ethereum Pool on May 8, 2021, exploiting the pool’s integration with Alpha Finance Lab’s ibETH token. The protocol’s same-day post-mortem valued the loss at about $10 million when it was written and said it represented 60% of user funds in that pool. Those dollar and percentage figures are Rari’s contemporaneous estimates, not independent Coinburn calculations.

The incident mattered beyond one yield product. It exposed how a DeFi aggregator could inherit assumptions from a connected protocol, even when the aggregator’s own integration had been reviewed. In composable finance, a contract may behave exactly as coded and still become unsafe when another contract can temporarily distort an input that the first system treats as reliable.

What the records show

Rari’s account said the Ethereum Pool placed ETH into Alpha Finance’s ibETH as a yield-generating strategy. The pool valued that position using the ratio of ibETH’s reported total ETH to its total token supply. According to the post-mortem, Alpha’s work function allowed an external caller to invoke other contracts before the reported total-ETH value returned to its normal state.

Rari described a repeated sequence: the attacker borrowed ETH through a dYdX flash loan, deposited it into the Rari pool, pushed the ibETH total-ETH value artificially higher, and withdrew more ETH than had been deposited. When the temporary distortion ended, the pool was left with the loss. This is Rari’s technical explanation as of May 8, 2021; it should not be mistaken for a judicial finding or a complete independent audit.

Ethereum’s public transaction record independently fixes the activity to May 8. One successful transaction in the identified sequence was timestamped 14:38:27 UTC and shows calls involving the address later labeled by Etherscan as the Rari Capital exploiter, Alpha Finance’s ibETH token and Rari pool contracts. The chain record verifies transaction execution and timing. Address labels and the interpretation of the full sequence still depend on attribution and analysis outside the raw ledger.

Why the integration failed

The crucial weakness was not a conventional password compromise. It was a valuation dependency that could be manipulated during an external call. Rari’s pool accepted the transient ibETH state as a usable price input and issued a withdrawal against that inflated accounting value. The attacker used atomic, borrowed liquidity to magnify the discrepancy without needing to hold the full capital beforehand.

Rari also said its Alpha integration had been audited by Quantstamp, but that neither the contributors nor the auditor had recognized these conditions. That statement is attributable to Rari; Coinburn did not locate a contemporaneous Quantstamp report that independently resolved responsibility for the missed interaction.

Immediate response and limits

Rari said the contracts were paused before further extraction and outlined proposed safeguards: protocol-to-protocol review of integrations, invariant checks, restrictions on deposits and withdrawals in the same block, internal reviews of connected protocols and additional outside audits. On May 8, these were commitments, not completed fixes.

The surviving evidence strongly establishes the exploit, date, affected pool and described mechanism. It does not establish a single independently audited loss figure to the last wei, a venue-specific dollar conversion window, the attacker’s real-world identity or whether every proposed safeguard was later implemented. The event-day conclusion is therefore narrow: composability created a security dependency that Rari’s controls did not catch before user funds were lost.

Primary sourceRari Capital Ethereum Pool post-mortem, May 8, 2021

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.