Mirror Protocol, one of Terra’s decentralized finance platforms, has been reportedly hit by a new wave of attacks. Community members are concerned about a suspected issue with the LUNC price oracles.
According to a post on the Terra Research Forum on May 28, 2022, by pseudonymous “Mirroruser,” the DeFi application Mirror Protocol, built on Terra, is supposedly vulnerable to another exploit. On May 30, ‘@FatManTerra’ tweeted about the purported attack, drawing the crypto community’s attention.
According to FatMan, who has been posting comments on the Terra research forum for the past few weeks, a defect in the LUNC pricing oracle has purportedly drained over $2 million, with the potential for more in the newest exploit. He claimed that the bug in the oracle program could cause all of Mirror’s liquidity pools to get depleted.

The Mirror Protocol is a DeFi (decentralized finance) platform that allows users to produce and trade mAssets (i.e., “mirrored assets”) that “reflect” stock prices, including major stocks listed on US exchanges.
According to The Block, Mirror Protocol was hacked for $90 million in October 2021 on the old Terra blockchain, which went undiscovered until last week.
Terra’s new blockchain went live over the weekend, with an airdrop of new LUNA tokens to users as part of a larger strategy by the developers to revive the ecosystem.
Terra’s Collapse Made the Damage Worse
Mirror was built around synthetic assets that allowed users to gain exposure to assets such as stocks and cryptocurrencies through the Terra ecosystem.
That business model became increasingly difficult to sustain after the collapse of TerraUSD and LUNA in May 2022. The launch of Terra 2.0 also created confusion between the new LUNA token and the original Terra token, which became LUNC. That distinction was central to the May exploit because the protocol’s oracle effectively used the wrong asset price.
Also Read: Taiko Halts Bridge Operations After $1.7 Million Exploit
Oracle risk remains a DeFi problem
Mirror’s exploit is particularly relevant because oracle manipulation remains one of the recurring attack patterns in DeFi.
Oracles determine how smart contracts understand the value of assets. If an attacker can manipulate, delay or exploit an inaccurate price feed, they may be able to borrow against inflated collateral, trigger liquidations or manipulate other protocol functions.
The lesson from Mirror was therefore bigger than one failed Terra application. A protocol can have functioning smart contracts and still be vulnerable if the external data those contracts rely on is inaccurate.
Enjoyed this? Bookmark DeFi Planet, explore related topics, and follow us on Twitter, LinkedIn, Facebook, Instagram, Threads, and CoinMarketCap Community for seamless access to high-quality industry insights
Take control of your crypto portfolio with DEFI PLANET PRO, DeFi Planet’s suite of analytics tools.
























































































