Library · Crypto, word by word · Scams and security
What is oracle manipulation?
Oracle manipulation is an attack in which someone distorts the price or data a smart contract reads from an oracle, then uses the false value to borrow too much, trigger liquidations or buy assets too cheaply. It often targets apps that read a price from a single thin trading pool.
What it means for you
If you lend, borrow or provide liquidity, a manipulated price can liquidate your position or drain the pool you deposited into, though you did nothing wrong. You can check an app's documentation for where its prices come from: one pool's spot price is easier to move than an average over time or a feed drawn from many independent sources.
How it works
A smart contract cannot see the outside world; it acts on whatever data an oracle supplies, so that data must be correct for the contract to behave correctly. If a lending contract reads the spot price of a single exchange pool, an attacker can take out a flash loan, make a large trade that pushes that price far off, borrow against the inflated value, and repay the loan in the same transaction. Defences ethereum.org describes include decentralized oracle networks that draw on many sources, and time-weighted average prices (TWAP), which a single recent trade cannot move much.
An example
Say a lending app values a token by its price in one small pool. An attacker borrows a large sum through a flash loan, buys the token in that pool and triples its quoted price. The app now values the attacker's collateral at three times its real worth and lends against it. The attacker repays the flash loan and keeps the difference.
Sources: ethereum.org: Smart contract security (oracle manipulation), ethereum.org: Oracles · checked 4 October 2026
Often confused with
Related words
Educational content, not financial advice. Written by hand and checked against the source named above. Something wrong? Tell us and we reply within two business days.