120 Seconds to Lose $3 Million: The “No Vulnerability” Defense Vesu Can’t Escape

(SeaPRwire) –

By: Ethan Gallagher

Two minutes. That is all it took. Forty-seven positions were liquidated. Three million dollars in collateral vanished. The feed corrected itself before most users even knew something was wrong. Vesu called it “not a vulnerability.” Pragma called it a “bad input.” Nobody is offering a refund timeline. And here is the thing nobody wants to say out loud in the room. This is not a Vesu problem. This is not a Pragma problem. This is a design-level choice that every single oracle-dependent lending protocol in DeFi has made. You are trusting a single external data feed to gate your entire collateral pool. When that feed glitches, the machine does not pause. It does not ask for confirmation. It executes. And execution in an automated liquidation engine means someone else’s collateral is now in a liquidator’s wallet. You can call it a “bad price feed.” You can call it “faulty upstream data.” You can call the smart contracts “operating as designed.” The vocabulary does not matter. The $3 million does. Vesu users should be asking one question right now. How do I know my position is safe on this protocol tomorrow, if the only thing between my collateral and a liquidation trigger is a price tick from an external oracle that can go wrong in two minutes?

Let me lay out exactly what Vesu confirmed publicly. On September 4, 2026, the incident window was between 04:08 and 04:10 UTC. A faulty Pragma price feed supplied incorrect data to Vesu’s liquidation engine. The engine flagged 47 positions as eligible for liquidation. Automated liquidators removed approximately $3 million in collateral. The feed corrected itself within two minutes. Vesu stated its smart contracts were “operating as designed” and contained no vulnerability. The protocol had nothing to patch. In an overcollateralized lending market, borrowers deposit assets worth more than their loan. The protocol checks the ratio of collateral to debt using an external price feed. If that feed shows the ratio dropping below the required level, liquidations begin automatically. Vesu attributed the event to bad inputs, not faulty execution. Pragma has deployed a fix. Affected pools have been suspended as a precaution. Vesu is working with StarkWare, the Starknet Foundation, and the curators of the affected pools to recover funds. A full technical report is expected to follow. Vesu did not disclose which assets were affected. Vesu did not disclose how far the prices differed from real market rates. Vesu did not disclose how much collateral the liquidators retained. There is no guaranteed reimbursement amount. There is no payment date. Users whose positions were liquidated were asked to open a support ticket on Vesu’s Discord. Earn product users were advised to keep their positions open because closing them early could affect refund eligibility.

Here is where the official narrative starts to thin out. Vesu says the contracts are fine. That may be true from a code perspective. But “fine” is not the right word for a system that automatically liquidates three million dollars of collateral in two minutes because an upstream feed had a glitch. The contracts did what they were coded to do. The coding assumed the oracle data was correct. That assumption is the vulnerability. It is just a vulnerability in the architecture, not in the code. Vesu did not name the affected assets. That means users cannot even verify whether their specific collateral type was overpriced or underpriced by the bad feed. If the feed showed a stablecoin at $0.80 instead of $1.00, collateral positions in that asset would look underwater. If the feed showed a volatile token spiking to triple its market price, the effect would be different. The nature of the bad data changes who is hurt and how badly. Vesu is treating this as an operational incident. The industry should be treating it as an infrastructure audit. In March 2026, Aave experienced a stale parameter incident that caused an estimated $26 to $27 million in unintended wstETH liquidations. Aave reviewed its oracle update rates and fallback systems afterward. Vesu has not announced any changes to its oracle setup beyond Pragma’s root-cause fix. There is no redundant oracle. There is no cross-check. There is no circuit breaker. There is no delay between a price anomaly and a liquidation execution. There is no mechanism that asks “wait, is this price even real?” before liquidating someone’s collateral. The liquidators who took that $3 million acted within the rules. They followed the protocol. They earned their incentive. The system rewarded them for doing exactly what it told them to do. The problem is that the system was telling them to take collateral based on a price that was not real.

The real story here is about dependency. Smart contracts are blind. They cannot read off-chain market prices. They rely entirely on oracle systems to source, aggregate, and deliver price data on-chain. A failure at any stage can trigger incorrect trades or liquidations. Vesu depends on Pragma. Pragma depends on upstream data sources. Those sources depend on their own feeds. Every link in that chain is a single point of failure. When one link breaks, the liquidation engine keeps running because it was never designed to stop. This is the oracle supply chain problem that DeFi has been ignoring. It is the same problem as any industry that outsources its most critical sensor to a third-party vendor without building redundancy into the control loop. Vesu will publish its report. Pragma will deploy patches. The affected pools will reopen. Users will get whatever recovery package emerges from negotiations with Starknet organizations and liquidators. And the next protocol that ships with a single-oracle dependency will get hit the same way. Until every lending protocol treats oracle infrastructure as mission-critical, actively monitors feed quality in real time, builds fallback mechanisms with independent price sources, and implements circuit breakers that halt liquidations when anomalies are detected, the “operating as designed” defense will keep working. Contracts will keep executing. Collateral will keep disappearing. And users will keep opening Discord support tickets while someone else pockets their collateral.

Author bio: Ethan Gallagher is a Silicon Valley Hardware Architect and Infrastructure Strategist specializing in distributed systems reliability, oracle architecture audits, and cross-protocol risk modeling for blockchain-native financial infrastructure.