📈 Get daily crypto insights that make you smarter about your money

New Gold Protocol Drained of $1.9 Million in Price Oracle Flash Loan Attack on BNB Chain

The New Gold Protocol (NGP) suffered a devastating exploit on September 18, 2025, losing approximately $1.9 million in a flash loan-powered price oracle manipulation attack on BNB Chain. The incident wiped out 88% of the token’s market value within minutes, underscoring the persistent risks that poorly audited smart contracts pose to the broader cryptocurrency ecosystem. As Bitcoin traded at $117,137 and Ethereum at $4,589 on the day of the attack, the NGP exploit served as a stark reminder that even as the market reaches new heights, protocol-level vulnerabilities remain a critical threat vector.

The Exploit Mechanics

The attacker executed a sophisticated two-step price inflation attack that exploited a fundamental flaw in NGP’s pricing mechanism. The protocol relied on DEX pair token reserve balances to calculate the NGP token price, creating an oracle vulnerability that was trivially exploitable through flash loans.

Six hours before the main exploit, the attacker purchased NGP tokens through several preliminary accounts at normal market prices. Once the flash loan was secured, the attacker swapped large amounts of USDT for NGP on the DEX pair, artificially inflating the token’s apparent price. This price manipulation bypassed the protocol’s maximum purchase limit and cooldown safety checks by directing the resulting NGP tokens to a zero (dead) address — a whitelisted address that was not subject to the same restrictions as regular user wallets.

With the price artificially inflated and safety checks circumvented, the attacker sold all previously accumulated NGP tokens at the manipulated price, extracting approximately $1.9 million in USDT from the protocol’s liquidity pools. The entire sequence was executed within a single transaction block, leaving no time for intervention.

Affected Systems

The attack targeted the New Gold Protocol’s core smart contract on BNB Chain. The whitelisted addresses that were exploited included the NGP token address itself, the mintAddress, and a dead (zero) address. The protocol had only recently gone live for trading on BNB Chain, meaning it was still in its early launch phase when the vulnerability was exploited.

The forensic analysis, conducted by Hacken’s security team, revealed that the attacker’s address (0x8618314270528e245fbbb6fba54e245bb61a8d47) immediately converted the stolen 1.9 million USDT into Binance-pegged ETH. From there, 443 ETH was bridged to the Ethereum mainnet via the Across protocol and subsequently deposited into Tornado Cash to obfuscate the transaction trail — a pattern consistent with sophisticated DeFi exploitation and laundering operations.

The Mitigation Strategy

The root cause of the exploit was the protocol’s dependence on DEX reserve balances for price discovery, a well-known vulnerability class in DeFi. Mitigating such attacks requires multiple layers of defense. First, protocols must implement battle-tested price oracles such as Chainlink or Pyth Network, which aggregate prices from multiple independent sources and are resistant to single-source manipulation. Second, access control lists — particularly whitelisted addresses — must be audited rigorously to prevent dead or administrative addresses from being used as bypass vectors.

Stress testing that simulates real-world attack scenarios, including flash loan-based price manipulation, should be mandatory before any protocol goes live. Independent third-party security audits from multiple firms provide overlapping coverage and increase the likelihood of catching edge-case vulnerabilities that a single auditor might miss.

Lessons Learned

The NGP hack reinforces several critical lessons for the crypto community. Price oracle manipulation remains one of the most common and costly attack vectors in DeFi, with losses from oracle-related exploits exceeding hundreds of millions of dollars across the industry. Protocols that rely on DEX reserve balances or single-source pricing mechanisms are fundamentally vulnerable to flash loan attacks, which can be executed with zero upfront capital.

The speed of the attack — from initial positioning to fund extraction — demonstrates that once a vulnerability is identified by malicious actors, the window for response is measured in seconds, not minutes or hours. This reality underscores the importance of proactive security measures over reactive incident response.

User Action Required

Users who held NGP tokens at the time of the exploit should monitor the protocol’s official channels for updates on any compensation or recovery plans. Given that the stolen funds were laundered through Tornado Cash, the likelihood of recovery is low. All DeFi users should verify that the protocols they interact with use audited, manipulation-resistant price oracles and have undergone multiple independent security reviews. When a new protocol launches, particularly one with novel tokenomics, exercising caution and limiting exposure during the initial trading period is a prudent risk management strategy.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Always conduct your own research before interacting with any cryptocurrency protocol.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

27 thoughts on “New Gold Protocol Drained of $1.9 Million in Price Oracle Flash Loan Attack on BNB Chain”

  1. using spot DEX reserves as your oracle in 2025 is not a mistake its a choice. Chainlink was free. TWAP was free. they picked the gameable option on purpose

  2. using DEX pair reserves as your price oracle in 2025 is negligence pure and simple. TWAP oracles have been standard since 2021. no excuse

  3. whitelisting a dead address for unrestricted withdrawals is the kind of thing that should fail a code review in 5 minutes. who approved that

    1. Liesl W. the dead address bypass is wild. protocols still giving special permissions to burn addresses in 2025. NGP team should refund users from their own pocket

  4. swapping USDT for NGP to inflate the price then dumping pre-bought tokens through a whitelisted dead address. textbook oracle manipulation with extra steps

    1. flash_crash_ pre-buying tokens 6 hours before the exploit then dumping through a whitelisted address. this was planned not opportunistic

      1. 6 hours of pre-positioning and nobody at NGP thought to flag unusual buying activity on their own token. zero on-chain monitoring for a project handling millions

  5. Anastasia Volkova

    88% of NGP market cap wiped in minutes and the attack was a single transaction block. flash loans combined with bad oracle design are still the most reliable exploit vector in DeFi

    1. flash_anatomy

      Anastasia Volkova the dead address whitelist bypass is the part nobody talks about. protocols give special permissions to burn addresses and wonder why exploits happen

      1. whitelisting a dead address for withdrawals is next level negligence. thats not a bug thats a backdoor with a bow on top

      2. flash_anatomy whitelisting a dead address for withdrawals is such an obvious failure mode. how does that even pass a basic code review

        1. whitelisting a dead address for withdrawals in 2025 is beyond negligent. how many more oracle exploits before teams take the hint

          1. Petra Korhonen the answer is infinitely more. protocols will keep skipping oracle integrations because shipping fast matters more than security audits to these teams

  6. 88% value wipe in minutes. the attacker pre-positioned 6 hours early too. NGP team had zero monitoring on their own liquidity pools apparently

  7. using DEX pair reserves as a price oracle is 2021 level mistakes. projects in 2025 still doing this deserve the exploit honestly

    1. Cheng Y. calling it a 2021 mistake is generous. even in 2020 people knew spot DEX reserves were gameable. NGP chose cheapest oracle available and paid for it

      1. oracle_skeptic_77

        twap_oracle_fan calling it a 2021 mistake is generous. chainlink was free and available. NGP chose not to use it because they didnt want to wait for integration

  8. TWAP oracles have been the bare minimum since 2021 and projects in 2025 still use spot DEX reserves for pricing. at this point its choosing to be vulnerable

  9. 1.9M gone because they used spot DEX reserves for pricing. this was solved in 2020 with TWAP oracles. some teams deserve the exploit

  10. dex_reserve_rat

    NGP used spot DEX pair reserves for price feeds in September 2025. Chainlink push oracle was literally free and they chose not to integrate it

    1. dex_reserve_rat_ free oracle integration and they skipped it. the 1.9M loss is a tax on laziness at this point

      1. dex_reserve_rat Chainlink push oracle was literally free and they used spot DEX reserves instead. 1.9M is the cost of pure laziness

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$77,332.00-0.9%ETH$2,470.88+0.1%SOL$99.97-1.2%BNB$715.38-0.2%XRP$1.36-1.7%ADA$0.2093-1.9%DOGE$0.0841-1.4%DOT$1.15+4.6%AVAX$7.54-3.1%LINK$11.55-2.0%UNI$6.13+2.4%ATOM$1.76-3.2%LTC$53.28+1.6%ARB$0.1455-2.5%NEAR$2.51+2.6%FIL$0.7947-1.3%SUI$0.7409-3.1%BTC$77,332.00-0.9%ETH$2,470.88+0.1%SOL$99.97-1.2%BNB$715.38-0.2%XRP$1.36-1.7%ADA$0.2093-1.9%DOGE$0.0841-1.4%DOT$1.15+4.6%AVAX$7.54-3.1%LINK$11.55-2.0%UNI$6.13+2.4%ATOM$1.76-3.2%LTC$53.28+1.6%ARB$0.1455-2.5%NEAR$2.51+2.6%FIL$0.7947-1.3%SUI$0.7409-3.1%
Scroll to Top