TechFlow reports, on July 22, SlowMist issued a security warning stating that 42DAO suffered an attack, with losses of approximately $912,000. The attack was caused by the attacker exploiting the abnormally low price of BTCB provided by the Median Oracle, executing the exploit through the poke mechanism of the Spotter contract and the bark mechanism of the Dog contract.
Analysis shows that the Spotter module lacked price deviation checks, maximum drawdown limits, and minimum price protection, allowing abnormally low prices to be written directly into the Vat; subsequently, the Dog module, lacking liquidation delays and oracle price validation, directly used this price to initiate immediate liquidations on multiple BTCB vaults. This attack was completed via a single transaction and profited from liquidation arbitrage.




