Skip to content
-
Subscribe to our newsletter & never miss our best posts. Subscribe Now!
Coin Gazette Coin Gazette Coin Gazette

Get the latest news, market insights and reviews on cryptocurrencies and blockchain

Coin Gazette Coin Gazette Coin Gazette

Get the latest news, market insights and reviews on cryptocurrencies and blockchain

  • Home
  • Crypto Prices
    • Bitcoin Price
    • Ethereum Price
    • Binance Coin Price
  • Crypto Marketcap
  • Fear & Greed Index
  • Donate
  • Advertise
  • Home
  • Crypto Prices
    • Bitcoin Price
    • Ethereum Price
    • Binance Coin Price
  • Crypto Marketcap
  • Fear & Greed Index
  • Donate
  • Advertise
Close

Search

Coin Gazette Coin Gazette Coin Gazette

Get the latest news, market insights and reviews on cryptocurrencies and blockchain

Coin Gazette Coin Gazette Coin Gazette

Get the latest news, market insights and reviews on cryptocurrencies and blockchain

  • Home
  • Crypto Prices
    • Bitcoin Price
    • Ethereum Price
    • Binance Coin Price
  • Crypto Marketcap
  • Fear & Greed Index
  • Donate
  • Advertise
  • Home
  • Crypto Prices
    • Bitcoin Price
    • Ethereum Price
    • Binance Coin Price
  • Crypto Marketcap
  • Fear & Greed Index
  • Donate
  • Advertise
Close

Search

Home/Defi/Scallop Protocol Hit by Flash Loan Exploit, $142K Drained in Targeted Oracle Attack
Scallop logo, hacker silhouette, exploit headline, SUI tokens
DefiSecurity

Scallop Protocol Hit by Flash Loan Exploit, $142K Drained in Targeted Oracle Attack

By Coin Gazette Editorial
April 26, 2026 2 Min Read
Comments Off on Scallop Protocol Hit by Flash Loan Exploit, $142K Drained in Targeted Oracle Attack

Scallop Protocol, a lending platform built on the Sui blockchain, suffered a flash‑loan exploit on Sunday that resulted in the loss of approximately $142,000, equivalent to 150,000 SUI making this a second exploit so far after the KelpDAO exploit. Early reports indicate the attack was the result of a highly targeted oracle manipulation, allowing the exploiter to drain funds without interacting with Scallop’s core contracts.

A Precision Exploit on a Deprecated Contract

According to the post on X, the attacker did not compromise Scallop’s main protocol logic. Instead, they exploited a deprecated side contract—a component no longer meant to be in active use but still accessible on-chain. This overlooked contract became the attack vector, revealing what analysts are calling a deeper design flaw in the protocol’s architecture.

The exploit combined:

  • A flash loan, providing the attacker with temporary capital
  • Oracle manipulation, enabling them to distort asset pricing
  • A deprecated contract, which lacked updated safeguards

This combination allowed the attacker to artificially influence price feeds and extract value before the system could react.

Why This Attack Matters

While the dollar amount is relatively small compared to major DeFi exploits, the nature of the attack raises important concerns:

1. Deprecated Contracts Remain a Hidden Liability

Even when no longer in use, old contracts can remain callable on-chain. If not properly disabled or migrated, they become silent attack surfaces.

2. Oracle Manipulation Remains a Top DeFi Threat

Manipulating price feeds—especially in low‑liquidity environments—continues to be one of the most common and effective exploit strategies.

3. Sui Ecosystem Security Under Scrutiny

As Sui-based protocols grow, attackers are increasingly probing for weak points in newer ecosystems.

Community and Market Reaction

The exploit was quickly flagged by crypto news aggregators and security analysts. While Scallop has not yet released a full post‑mortem, the community is already calling for:

  • A comprehensive audit of all legacy and deprecated contracts
  • Stronger oracle protections
  • A formal incident response plan

Despite the breach, there is no indication that Scallop’s primary lending pools or user deposits were directly compromised.

What Comes Next

A full technical breakdown is expected once Scallop completes its internal investigation. The key questions now are:

  • How long was the deprecated contract left active?
  • Why was it not decommissioned or permission‑restricted?
  • What changes will be implemented to prevent similar exploits?

For now, the incident serves as a reminder that DeFi security is only as strong as its oldest, least‑maintained component.

Tags:

DeFi ExploitsFlash Loan ExploitOracle ManipulationScallop ProtocolSui Blockchain
Author

Coin Gazette Editorial

Follow Me
Other Articles
BCO.fedde2ea 30d0 4c23 8a16 52ce0bfb28f7
Previous

Aave Nears Full Recovery Funding After KelpDAO Exploit

A cyber‑themed digital illustration showing vulnerabilities across cryptocurrency sectors. A robotic head with glowing blue eyes represents AI; stacked servers and a padlock signal security risks. In the center, glowing Ethereum blocks and a red warning triangle highlight DeFi threats. On the right, a bridge and laptop with a red skull symbolize Layer‑2 exploit dangers. The background features a world map with glowing nodes, broken chains, and red alert icons.
Next

Top 4 Crypto Sectors Most Vulnerable to Exploits

On Social

FacebookTwitter/XInstagramTelegram
✉️

Stay in the Loop

Get the latest updates delivered straight to your inbox.

Recent Posts

  • Big Shift For Crypto Prediction Markets: Hyperliquid Removes External Oracle Dependency
  • XRP Channel Pattern Points To $5, Says Korean Analyst
  • Iran Diplomats Push Peace Talks in Doha as Bitcoin Holds $77,700 and Oil Drops 6%
  • What Is 1,000 XRP Worth at $5, $10, and $30? Analyst Does the Math
  • Top Analyst Lets Claude AI Run His $80,000 Altcoin Portfolio After Losing Half His Investment

About Us

Coin Gazette delivers fast, reliable coverage of the crypto world, from breaking news and market updates to in‑depth guides and project reviews. Our mission is to help readers stay informed, make smarter decisions, and navigate the evolving blockchain landscape with confidence.

Useful Links

  • About Us
  • Contact Us
  • Advertise
  • Give us a tip

Follow Us On

FacebookTwitter/XInstagramTelegram
Copyright 2026 — Coin Gazette. All rights reserved. Blogsy WordPress Theme