Virtue Quantifies Damage From IOTA Oracle Attack
Virtue has released a detailed recovery plan following the August 28 oracle manipulation attack that triggered 47 abnormal liquidations across 45 user positions. The IOTA-based lending protocol says its immediate priority is to make every affected user whole, while keeping the platform frozen during the recovery process.
The latest reconciliation puts the affected collateral at 23,215,117 IOTA-equivalent, while 455,102.94 VUSD of debt was cleared through the liquidations. Using the last untainted IOTA price of $0.0389806, Virtue estimates the historical value of the affected collateral at roughly $904,939.
The incident began after an attacker compromised the signing keys associated with all 14 oracles in Switchboard’s IOTA mainnet queue. The attacker manipulated the IOTA price feed in both directions, first pushing the reported price dramatically higher and later driving it close to zero. Virtue’s liquidation system acted on those prices, causing healthy positions to be liquidated.
Virtue previously said its price checks verified the source, feed identity, oracle count and freshness of the data. The problem was that those checks did not establish whether the reported price was economically plausible. The protocol has said that price-band and deviation controls will be added before any future reopening.
The latest update also identifies about 19.174 million IOTA held in locations linked to the attacker. Virtue says approximately 11.174 million IOTA is in restricted on-chain addresses, while another 5 million is at KuCoin and 3 million at StealthEX. The protocol stressed that restricted assets are not the same as recovered assets because they have not yet entered Virtue-controlled recovery custody.
Virtue Moves Toward User Restoration
The attack also affected the Stability Pool. Virtue estimates that roughly 6.32 million IOTA-equivalent in abnormal rewards was distributed to 53 other Stability Pool positions. Most of those rewards remain unclaimed, with around 6.307 million IOTA-equivalent associated with 49 addresses. Virtue plans to reverse or claw back those unclaimed amounts.
Four addresses reportedly claimed about 16,314 IOTA-equivalent. Virtue says recovery from those positions will be prioritized, with any shortfall covered by the protocol rather than passed on to affected users. This pool of restricted attacker assets and recovered Stability Pool rewards forms the proposed source of funds for restoring the liquidated positions.
Virtue’s preferred solution is called Plan A. Under that approach, each affected position would be reconstructed using the final clean state before the incident. The protocol would restore 23,215,117 IOTA of collateral and 455,102.94 VUSD of original debt, while excluding interest accumulated during the incident and yield generated through stIOTA or vIOTA after the attack.
Related: IOTA Validators Freeze Attacker Wallets Following Virtue Protocol Exploit
Plan A is not yet guaranteed. Virtue says several conditions must be satisfied before it can execute the restoration, including approval from IOTA community validators for the handling of restricted assets. The attacker-linked funds held at on-chain addresses, KuCoin and StealthEX must also legally enter recovery custody.
The protocol also needs to reverse eligible Stability Pool rewards, confirm that sufficient assets are available, verify the records of all 45 affected users and independently review the transactions used to rebuild the positions. Until those requirements are satisfied, the proposed restoration remains a recovery plan rather than completed compensation.
Virtue is also separating ordinary Stability Pool losses from the larger recovery process. It says regular Stability Pool depositors had approximately 113,416.78 VUSD consumed by the abnormal liquidations and that the protocol intends to replenish that amount by September 16. Attacker-consumed VUSD is excluded from that calculation.
The incident highlights a broader weakness in decentralized lending systems: smart contracts can execute correctly while still producing damaging results when trusted external data is compromised. Similar oracle-related liquidation events have affected other DeFi platforms recently, including Vesu on Starknet, where faulty upstream pricing triggered 47 abnormal liquidations involving roughly $3 million in collateral.
Related: IOTA v1.31.2: What Protocol 34 Changes for the Mainnet
For IOTA’s DeFi ecosystem, Virtue’s response will now be judged less by how quickly the platform can reopen and more by whether affected users are actually restored. The protocol has already said it will remain frozen while remediation continues. That gives the team time to test its recovery transactions and implement stronger price protections before taking on new lending activity.
Virtue’s recovery plan therefore marks an important next stage in the IOTA oracle incident. The damage has been quantified, attacker-linked assets have been traced and a mechanism for rebuilding the 45 affected positions has been outlined. The critical question now is whether those assets can be recovered and whether the proposed safeguards are strong enough to prevent another manipulated price feed from turning into a new wave of liquidations.















