LlamaRisk Releases sDOLA Attack Postmortem: $822k Borrower Losses, Curve DAO May Compensate
**Attack Details and Impact**
LlamaRisk published a postmortem analyzing the sDOLA market liquidations on LlamaLend. The exploit resulted in:
- **$822,000 in borrower losses** through forced liquidations
- **~$200,000 profit** for the attacker
- Lenders remained unaffected
**Root Cause**
The attack exploited a combination of factors:
- Price oracle vulnerability to donation attacks
- Limited sDOLA liquidity outside the collateral market
- Specific handling requirements for vault collaterals in LlamaLend
**Potential Compensation**
Curve DAO is considering compensating affected borrowers for the $822k loss, pending community discussion and governance vote.
**Security Learnings**
The incident provided critical insights before LlamaLend V2's release. Developers noted the attacker likely would have earned more through a responsible security disclosure than the exploit itself. The team is now incorporating oracle code from unreleased 2-way markets as mitigation for future vault collateral markets.
