Incident Overview and Loss Scale
On July 1, 2026, decentralized lending protocol Edel Finance fell victim to a sophisticated attack, resulting in approximately $403,000 in bad debt. The team promptly paused all V1 contracts upon detecting the anomaly. Currently, V1 remains suspended, with a planned timeline of approximately 48 hours to resume normal operations, including enabling user withdrawals.
Attack Vector: wGOOGLx Collateral Price Manipulation
According to security firm CertiK's monitoring, the attacker exploited the dependency between the wGOOGLx collateral price and the underlying GOOGLx balance within the protocol. Specifically, the price of wGOOGLx was determined by the protocol's GOOGLx holdings. By manipulating the on-chain liquidity or oracle for GOOGLx, the attacker artificially inflated the valuation of wGOOGLx, allowing them to borrow far more than the backing collateral. This attack vector resembles classic "flash loan + price manipulation" schemes, but the key weakness here lies in a single asset's balance directly dictating a derivative token's price. The attacker siphoned approximately $204,000 during the exploit.
Team Response and User Protection
Edel Finance released a statement assuring users that no individual will incur losses from this incident. The team will fully absorb the bad debt and restore affected depositors' balances on a 1:1 basis. This decisive move demonstrates the team's commitment to safeguarding user funds and prevents a potential liquidity crunch that could have cascaded across the protocol. V1 contracts remain paused, and the team targets a 48-hour window to restore withdrawal functionality, after which users can reclaim their assets normally.
Coordination and White-Hat Resolution
The Edel team confirmed they have traced the attacker's on-chain transaction history and are actively coordinating with exchanges and ecosystem partners to freeze or recover the stolen funds. In parallel, the team issued a formal white-hat settlement offer: the attacker must return the remaining funds within a specified deadline in exchange for a bug bounty. This is a common industry practice to minimize losses and avoid protracted legal battles. Should the attacker fail to comply, the team may pursue further legal or on-chain enforcement measures.
This incident serves as a stark reminder for DeFi protocols: collateral models that rely on internal asset balances for pricing carry severe security risks. Protocols should adopt diversified oracle sources and stricter price protection mechanisms to mitigate such vulnerabilities.

