Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnSquareMore
New Gold Protocol Loses $2M in Price Oracle Hack, NGP Token Collapses by 88%

New Gold Protocol Loses $2M in Price Oracle Hack, NGP Token Collapses by 88%

CoinspeakerCoinspeaker2025/09/17 16:00
By:By Zoran Spirkovski Editor Julia Sakovich

The New Gold Protocol has been exploited for $2M after an attacker manipulated its price oracle with a flash load, leading the asset to collapse by 88%.

Key Notes

  • The attacker stole ~$2 million worth of ETH from the New Gold Protocol on Sept.18.
  • The exploit involved a flash loan that successfully manipulated the price oracle enabling the attacker to bypass security checks in the smart contract.
  • The NGP token is down 88% as the attacker obfuscates their funds through Tornado Cash.

New Gold Protocol, a DeFi staking project, lost around 443.8 Ethereum ETH $4 599 24h volatility: 2.2% Market cap: $555.19 B Vol. 24h: $42.83 B , valued at $2 million, in an exploit on Sept 18. The attack caused the project’s native NGP token to crash by 88%, wiping out most of its market value in less than an hour.

The incident was flagged by multiple blockchain security firms, including PeckShield and Blockaid. Both firms confirmed the amount stolen and tracked the movement of the funds. Blockaid’s analysis identified the specific vulnerability that the attacker used.

🚨 Community Alert:

Blockaid’s exploit detection system identified multiple malicious transactions targeting the NGP token on BSC.
Roughly $2M has been drained.

↓ We’re monitoring in real time and will share updates below pic.twitter.com/efxXma0REQ

— Blockaid (@blockaid_) September 17, 2025

Flash Loan Attack Manipulated Price Oracle

According to the Blockaid report, the hack was a price oracle manipulation attack. The protocol’s smart contract had a critical flaw; it determined the NGP token’s price by looking at the asset reserves in a single Uniswap liquidity pool. This method is insecure because a single pool’s price can be easily manipulated.

The attacker used a flash loan to borrow a large amount of assets. A flash loan consists of a series of transactions that borrow and return a loan within the same transaction. They used these assets to temporarily skew the reserves in the liquidity pool, tricking the protocol into thinking the NGP token was nearly worthless. This allowed the hacker to bypass a maximum purchase limit and buy a huge number of NGP tokens at minimal prices.

The next transactions in the chain, reversed the initial trade and repaid the flash loan, netting the hacker a 443.8 ETH profit. The funds were then taken to the Ethereum network and deposited into the Torando Cash mixer to obfuscate the trail.

This exploit highlights several red flags that surrounded the project. Unlike legitimate, audited tokens, NGP operated with little transparency and was plagued by extremely low trading volume. This incident is part of a larger pattern, as reports show that rising crypto hacks are becoming more frequent. It also adds to the debate over developer liability, a topic that crypto firms urge lawmakers to address.

next
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

2025 TGE Survival Ranking: Who Will Rise to the Top and Who Will Fall? Complete Grading of 30+ New Tokens, AVICI Dominates S+

The article analyzes the TGE performance of multiple blockchain projects, evaluating project performance using three dimensions: current price versus all-time high, time span, and liquidity-to-market cap ratio. Projects are then categorized into five grades: S, A, B, C, and D. Summary generated by Mars AI This summary was generated by the Mars AI model, and the accuracy and completeness of its content are still being iteratively updated.

MarsBit2025/11/28 16:26
2025 TGE Survival Ranking: Who Will Rise to the Top and Who Will Fall? Complete Grading of 30+ New Tokens, AVICI Dominates S+

Mars Finance | "Machi" increases long positions, profits exceed 10 million dollars, whale shorts 1,000 BTC

Russian households have invested 3.7 billion rubles in cryptocurrency derivatives, mainly dominated by a few large players. INTERPOL has listed cryptocurrency fraud as a global threat. Malicious Chrome extensions are stealing Solana funds. The UK has proposed new tax regulations for DeFi. Bitcoin surpasses $91,000. Summary generated by Mars AI. The accuracy and completeness of this summary are still being iteratively updated by the Mars AI model.

MarsBit2025/11/28 16:26
Mars Finance | "Machi" increases long positions, profits exceed 10 million dollars, whale shorts 1,000 BTC

How much is ETH really worth? Hashed provides 10 different valuation methods in one go

After taking a weighted average, the fair price of ETH exceeds $4,700.

ForesightNews 速递2025/11/28 15:05
How much is ETH really worth? Hashed provides 10 different valuation methods in one go

Dragonfly partner: Crypto has fallen into financial cynicism, and those valuing public blockchains with PE ratios have already lost

People tend to overestimate what can happen in two years, but underestimate what can happen in ten years.

深潮2025/11/28 14:53
Dragonfly partner: Crypto has fallen into financial cynicism, and those valuing public blockchains with PE ratios have already lost