Major Security Breach Hits Rhea Finance
Rhea Finance, a lending protocol built in the NEAR ecosystem, has disclosed a major DeFi exploit that resulted in losses of about $18.4 million. According to the project’s post-mortem, the attacker abused vulnerabilities in the platform’s margin trading function, manipulated swap routes, and drained liquidity from the main pool. The incident adds to growing concerns around the security of complex DeFi trading and lending systems.
In its detailed explanation, Rhea Finance said the attacker used fake token pools to reroute borrowed debt tokens through abnormal paths. That process left a large number of positions undercollateralized and ultimately triggered widespread liquidations across the platform. The damage was not limited to the protocol itself, as users were also exposed to losses tied to forced liquidations and weakened collateral positions.
DeFi Risk Controls Under Pressure Again
The exploit underscores persistent weaknesses in DeFi infrastructure, especially around slippage protection and swap-path validation. If malicious actors can redirect trades through fake pools or unsupported routes, the impact can quickly spread from a single trading function to the broader lending and liquidation framework. In leveraged environments, such flaws can cascade into systemic losses within minutes.
Rhea Finance said it plans to use available resources to recover losses for affected users. The incident has also weighed on sentiment around the protocol’s native token, RHEA, while fueling broader debate over DeFi security in the NEAR ecosystem. For the market, the event serves as another reminder that as protocols add more advanced trading features, security checks around routing logic, pool verification, and abnormal market conditions remain essential.

