📈 Get daily crypto insights that make you smarter about your money

Sonne Finance Loses Million in Timelock Exploit on Optimism Network

The decentralized lending protocol Sonne Finance suffered a devastating exploit on May 14, 2024, losing approximately $20 million in what security researchers have identified as a sophisticated timelock manipulation attack. The incident underscores the persistent vulnerabilities facing DeFi platforms built on forked codebases, even as the broader crypto market navigates a period of elevated prices and increased on-chain activity.

The Exploit Mechanics

The attacker targeted a well-known vulnerability in Compound v2 forks known as the “donation attack.” This technique involves manipulating the collateral factors of a lending pool to artificially inflate the value of deposited collateral. In this case, the vulnerability was exploited through a misalignment in the execution timing of critical governance transactions. Sonne Finance had recently passed a proposal to integrate VELO markets, with transactions scheduled on a multi-sig wallet featuring a 2-day timelock. The attacker anticipated the execution window and positioned four transactions to execute precisely when the timelock ended, setting up the markets before triggering the collateral factor increase.

Affected Systems

The attack primarily impacted Sonne Finance, a non-custodial decentralized exchange operating on the Optimism network. The protocol, which allows users to lend and borrow various cryptocurrencies, saw its lending pools drained of approximately $20 million in digital assets. The native token of Sonne Finance plunged 55% in the hours following the attack, reflecting investor panic and a sharp loss of confidence. The exploit also exposed risks in the broader ecosystem of Compound v2 forks, many of which share similar architectural vulnerabilities. Optimism, the Layer 2 network hosting the protocol, was not itself compromised, but the incident highlights the growing target surface on Ethereum Layer 2 solutions as DeFi activity migrates to these networks.

The Mitigation Strategy

Following the attack, the Sonne Finance team took immediate action by pausing all markets to prevent further losses. The protocol sent an on-chain message to the exploiter, offering a 10% bounty in exchange for the return of 90% of the stolen funds. Security Alliance contributors from Seal911 intervened swiftly, managing to salvage approximately $6.5 million by adding a minimal amount of VELO to the affected markets before the attacker could drain them completely. The Immunefi platform, which tracks crypto losses, reported that May 2024 saw $52 million in total losses across the industry, a 12% decrease compared to May 2023. Hacks accounted for $50 million across 14 incidents, while fraud represented just $1.7 million or 3.3% of total losses.

Lessons Learned

The Sonne Finance exploit reinforces several critical lessons for DeFi protocols. First, timelock mechanisms must be designed with front-running protection to prevent attackers from anticipating and exploiting governance execution windows. Second, protocols built on forked code inherit not just functionality but also known vulnerabilities from their parent codebases. Third, the speed of response matters enormously — the Seal911 team saved $6.5 million by acting within minutes. Finally, the dominance of DeFi targets in May 2024 losses, with CeFi platforms experiencing zero major attacks, suggests that decentralized architectures remain more vulnerable to technical exploits than their centralized counterparts.

User Action Required

Users who had funds deposited in Sonne Finance should monitor official channels for updates on the recovery process and any potential reimbursement plans. Those interacting with other Compound v2 forks should verify whether their platforms have implemented patches for the donation attack vulnerability. As Bitcoin trades at approximately $61,400 and Ethereum at $2,928, the broader market remains in a bullish phase, but investors should exercise heightened due diligence when allocating capital to DeFi protocols, particularly those on newer Layer 2 networks. Always verify audit reports and check whether protocols have implemented time-tested security measures before depositing significant funds.

Disclaimer: This article is for informational purposes only and does not constitute financial advice. Always conduct your own research before making investment decisions.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

26 thoughts on “Sonne Finance Loses Million in Timelock Exploit on Optimism Network”

  1. rekt_shepherd_

    compound v2 forks and the donation attack vector, its literally in every audit report since 2022. how does a team launching on optimism miss this

    1. null_penguin_

      bro the attacker queued 4 txs to execute right when the timelock ended. thats not sophisticated, thats just watching the mempool with patience lol

      1. 4 transactions queued to execute the second the timelock expired. attacker was just watching the mempool with patience lol not exactly a zero day

      2. watching the mempool for timelock expiry is basic MEV strategy. the attacker was patient, not genius. teams need to randomize execution windows or use commit-reveal

    2. rekt_shepherd_ every compound v2 audit since 2022 literally has this in the findings section. teams just ctrl+f for critical and ignore the rest

      1. every compound v2 audit since 2022 flagged the donation attack yet sonne still lost 20m on may 14

    3. compound v2 donation attack is literally chapter 1 in every defi audit guide since 2022. if your protocol forks it you need to address every known vulnerability by default

      1. every compound v2 fork has the same donation attack in its audit findings. teams see it, acknowledge it, then somehow still ship without fixing it

        1. Mia K. audit reports have become paperwork not warnings. teams check the box and launch because fixing delays the token

          1. delay_axis_ audit reports have literally become checkbox compliance. teams treat critical findings as suggestions and investors eat the cost

      2. timelock watching is basic MEV strategy. the attack wasn”’t genius, just patient. randomize execution windows or use commit-reveal

        1. timelock watching as mev strategy on optimism allowed the 20m loss via 4 queued transactions on sonne finance

  2. Dmitri Volkov

    The timelock window exploit is the real story here. Scheduling governance transactions on a 2-day timelock with no slippage protection gave the attacker a predictable execution window. Teams need to stagger these.

  3. Sonne forked Compound v2 and shipped without fixing the donation attack. the audit report literally listed it as a known issue. they launched anyway

    1. fork_grader_ the audit report literally listed the donation attack as a known issue and sonne shipped anyway. this wasnt a hack it was negligence

      1. sol_amoeba_ negligence is exactly the right word. the audit flagged it, the team shipped anyway, and 20M disappeared. at what point does this become legally actionable

        1. the audit literally listed the donation attack as a known issue. at what point does shipping a known vulnerability become fraud not negligence

    2. time_lock_smith_

      fork_grader_ every Compound v2 audit since 2022 flags the donation vector. teams treat audit findings as paperwork not warnings

  4. $20m gone because a governance proposal execution window was predictable. defi governance needs an overhaul, timelocks alone are not enough

    1. timelocks are transparent by design, maybe thats the problem. execution privacy for governance actions would prevent front-running

      1. time_lock_smith_

        txfeemonitor execution privacy for governance actions would prevent front-running but then teams lose transparency. theres no clean fix for predictable timelocks

  5. governance_nihilist

    compound v2 forks keep making the same donation attack mistake. it”’s like reading a vulnerability report and then shipping anyway

    1. rektarchivist_

      Dmitri Volkov staggered execution is a nice idea but even OTC desks struggle with that. the real fix is private mempools for governance txs

  6. four txs queued to fire the second the timelock expired. sonne basically left the front door open with a schedule attached

    1. Yannick P. the attacker was watching the clock for them. timelocks without execution randomization is governance malpractice

  7. mempool_oracle_

    4 txs queued to fire the second the timelock expired and nobody at Sonne thought to add a delay buffer. literally watching the clock for them

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$64,975.00+0.1%ETH$1,914.59-0.1%SOL$76.69+1.2%BNB$604.08+0.2%XRP$1.03-0.5%ADA$0.1959-1.5%DOGE$0.0697-0.7%DOT$0.7994-1.8%AVAX$6.480.0%LINK$8.19-1.4%UNI$4.04+1.5%ATOM$1.37-0.9%LTC$45.56-1.1%ARB$0.0780-0.1%NEAR$1.61-0.2%FIL$0.7034-1.3%SUI$0.6898+0.1%BTC$64,975.00+0.1%ETH$1,914.59-0.1%SOL$76.69+1.2%BNB$604.08+0.2%XRP$1.03-0.5%ADA$0.1959-1.5%DOGE$0.0697-0.7%DOT$0.7994-1.8%AVAX$6.480.0%LINK$8.19-1.4%UNI$4.04+1.5%ATOM$1.37-0.9%LTC$45.56-1.1%ARB$0.0780-0.1%NEAR$1.61-0.2%FIL$0.7034-1.3%SUI$0.6898+0.1%
Scroll to Top