Edel Finance Loses $403K in wGOOGLx Price Manipulation Attack; Team Bears Bad Debt, Aims to Resume Withdrawals in 48 Hours

Edel Finance Loses $403K in wGOOGLx Price Manipulation Attack; Team Bears Bad Debt, Aims to Resume Withdrawals in 48 Hours

N
News Editor
2026-07-01 07:57:30
Lending protocol Edel Finance suffered a price manipulation attack exploiting its wGOOGLx collateral mechanism, resulting in approximately $403,000 in bad debt. The team has paused all V1 contracts and plans to restore normal operations, including withdrawals, within 48 hours. Users will face no losses as the team will absorb the bad debt and restore affected deposits at a 1:1 ratio. The attacker netted about $204,000 through the exploit. Edel has tracked the on-chain trail, is coordinating with exchanges, and has offered a white-hat bounty to the attacker. The incident highlights the vulnerability of collateral pricing reliant on a single asset's internal balance.
Edel FinanceattackDeFi securitywGOOGLxprice manipulationbad debtwhite-hatCertiK

Incident Overview and Loss Scale

On July 1, 2026, decentralized lending protocol Edel Finance fell victim to a sophisticated attack, resulting in approximately $403,000 in bad debt. The team promptly paused all V1 contracts upon detecting the anomaly. Currently, V1 remains suspended, with a planned timeline of approximately 48 hours to resume normal operations, including enabling user withdrawals.

Attack Vector: wGOOGLx Collateral Price Manipulation

According to security firm CertiK's monitoring, the attacker exploited the dependency between the wGOOGLx collateral price and the underlying GOOGLx balance within the protocol. Specifically, the price of wGOOGLx was determined by the protocol's GOOGLx holdings. By manipulating the on-chain liquidity or oracle for GOOGLx, the attacker artificially inflated the valuation of wGOOGLx, allowing them to borrow far more than the backing collateral. This attack vector resembles classic "flash loan + price manipulation" schemes, but the key weakness here lies in a single asset's balance directly dictating a derivative token's price. The attacker siphoned approximately $204,000 during the exploit.

Team Response and User Protection

Edel Finance released a statement assuring users that no individual will incur losses from this incident. The team will fully absorb the bad debt and restore affected depositors' balances on a 1:1 basis. This decisive move demonstrates the team's commitment to safeguarding user funds and prevents a potential liquidity crunch that could have cascaded across the protocol. V1 contracts remain paused, and the team targets a 48-hour window to restore withdrawal functionality, after which users can reclaim their assets normally.

Coordination and White-Hat Resolution

The Edel team confirmed they have traced the attacker's on-chain transaction history and are actively coordinating with exchanges and ecosystem partners to freeze or recover the stolen funds. In parallel, the team issued a formal white-hat settlement offer: the attacker must return the remaining funds within a specified deadline in exchange for a bug bounty. This is a common industry practice to minimize losses and avoid protracted legal battles. Should the attacker fail to comply, the team may pursue further legal or on-chain enforcement measures.

This incident serves as a stark reminder for DeFi protocols: collateral models that rely on internal asset balances for pricing carry severe security risks. Protocols should adopt diversified oracle sources and stricter price protection mechanisms to mitigate such vulnerabilities.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.