ERC4626 Weakness Persists: Inertia Exploit Exposes DeFi Lending Risks

The May 23 2026 Inertia exploit drained roughly $152000 by exploiting a known ERC4626 vulnerability and weak oracle protections. Stake DAO suffered a

Share
ERC4626 Weakness Persists: Inertia Exploit Exposes DeFi Lending Risks

Hero: Dramatic digital illustration of a DeFi lending protocol breach on Ethereum, with red-highlighted ERC4626 token vaults leaking funds into a hacker's wallet while blockchain nodes flash warnings

Summary

  • The May 23 2026 Inertia exploit drained roughly $152000 by exploiting a known ERC4626 vulnerability and weak oracle protections.
  • Stake DAO suffered a separate key compromise on Arbitrum that allowed minting of 5.4 trillion vsdCRV tokens.
  • Both incidents show that ERC4626 implementation flaws and key management errors continue to bypass standard security audits.

The Inertia protocol lost roughly $152000 on May 23 2026. Hackers manipulated its roETH market by exploiting an ERC4626 flaw and weak oracle safeguards. Monitoring systems flagged the anomaly that day.

This matched a known pattern of risks in vault standards.

Inertia confirmed they restored every affected asset. The protocol returned to full operation.

Stake DAO suffered a separate hit on Arbitrum. The two events highlight persistent problems in DeFi lending.

Context

ERC4626 aimed to standardize tokenized vaults across DeFi. Many lending protocols adopted it for collateral and yield strategies. Reports from prior years already flagged manipulation vectors when oracles lacked strong protections.

Those same vectors stayed active in production code by May 2026.

Inertia relied on ERC4626 vaults for its roETH market. The protocol never closed the documented gaps.

Details

The Inertia exploit centered on price manipulation inside the ERC4626 implementation. Weak oracle feeds let the attacker inflate collateral values and drain multiple markets. AMBCrypto and BingX reporting tied the $152000 loss directly to this combination of flaws.

Stake DAO faced a different failure mode. An attacker compromised the deployer private key on Arbitrum and minted 5.4 trillion vsdCRV tokens. The attacker swapped portions of the minted supply for ETH before the team could respond.

"Inertia lending is fully operational and secure. All affected user assets remain restored."

, Inertia official statement (Inertia Security Incident)

Audits cut some risks but leave gaps in implementation and key management. Both protocols had passed reviews. The core issues remained until the exploits hit.

Outlook

Developers and auditors must treat ERC4626 oracle protections and deployer key controls as top priorities. Protocols that skip these fixes stay exposed to similar attacks.