Rhea Finance, a DeFi protocol built on NEAR, has suffered a major exploit after an attacker manipulated its oracle pricing system and withdrew at least $7.6 million in crypto assets, according to an alert issued by blockchain security firm CertiK.
Fake tokens and new pools were used to distort price feeds
CertiK’s on-chain analysis shows the exploit was structured around price manipulation rather than a simple contract bug. The attacker first deployed malicious fake token contracts on-chain, then added initial liquidity for those tokens in newly created pools. By controlling these fresh pools, the attacker was able to mislead the protocol’s oracle and validation layer into reading false asset prices and valuations.
Once the pricing mechanism was thrown off, the protocol’s defenses failed to detect the mismatch. That opened the door for the attacker to extract assets from the Rhea Finance treasury, with losses reaching at least $7.6 million.
Related addresses have been flagged on-chain
In its alert, CertiK included a Nearblocks link and identified wallet or contract addresses closely tied to the exploit. Security researchers are still tracking the movement of the stolen funds on-chain.
The incident highlights oracle exposure in low-liquidity environments
Based on the disclosed details, the case points again to a familiar weak spot in DeFi: oracle designs that can be influenced by thin or newly established liquidity pools. For users with exposure to Rhea Finance, the immediate focus is on official damage reports and any remediation notice issued by the protocol, while interaction with the platform remains a clear risk.

