OAK — OnChain Attack Knowledge

Worked example · 2025-03

Hyperliquid JELLY self-liquidation + cross-venue spot-pump cascade — Hyperliquid (HyperEVM L1) + Solana spot — 2025-03-26

Loss
approximately $13.5M unrealised peak loss to Hyperliquid's HLP (Hyperliquid Liquidity Provider) market-making vault during the manipulation window; net realised HLP outcome was approximately +$700K positive 24h-PnL after validator-side settlement. The attacker deposited approximately $7.17M into Hyperliquid across three accounts and withdrew approximately $6.26M before Hyperliquid froze the remaining ~$900K balance on two long accounts; per Arkham Intelligence's post-event reconstruction, the attacker's net economic outcome is in the range of approximately negative $1M (if the residual $900K is never withdrawn) or approximately negative $4K (if the $900K is recovered through any future channel) — the validator-set's settlement at JELLY=$0.0095 zeroed-out the long-side floating PnL on the attacker's two long-position accounts, defeating the realised-extraction outcome the attacker had engineered.
Recovery
all non-flagged long-side users were made whole from the Hyper Foundation in the days following the incident, per Hyperliquid's public communication.
OAK Techniques observed
OAK-T17.002 (Liquidation-Cascade Engineering) — primary; the attacker engineered a self-liquidation cascade by opening a ~$4.5M short position from one account and offsetting ~$4M long positions across two other accounts on JELLY perps, then withdrew margin from the short account to force its own liquidation into HLP's automated-counterparty inheritance pipeline. The HLP-side inheritance mechanism — Hyperliquid's standing design that the HLP vault becomes the counterparty-of-last-resort to liquidated positions when the order-book cannot absorb the liquidation — was the load-bearing surface. OAK-T17.001 (Cross-Venue Arbitrage-Driven Price-Discovery Distortion) — composing sub-pattern; the attacker (or a coordinating cohort) drove JELLY spot price up approximately 250%-429% on Solana DEX spot venues (where JELLY is a Pump.fun-launched memecoin with thin spot depth) while the inherited HLP short position remained open, propagating the spot-price excursion into Hyperliquid's perpetual mark-price computation and creating a forced-buy cascade pressure against the HLP vault's inherited short. The cross-venue (Solana spot → Hyperliquid perp) propagation of the price-discovery distortion is the load-bearing T17.001 framing and the cleanest 2025 anchor for that draft sub-Technique. Order-book spoofing (T17 spoof / cancel-flood class) is not load-bearing here — the manipulation primitive was forced own-liquidation plus cross-venue spot-pump, not order-book spoofing. OAK-T9.004 (Access-Control Misconfiguration — partial framing): the HLP vault's inheritance-of-liquidated-positions design did not have a per-position size cap or a per-token concentration cap that would have bounded the worst-case HLP exposure to a single thin-liquidity perpetual — the same structural anti-pattern as the Lido stETH / Aave queue-saturation case examples/2025-07-lido-steth-aave-cascade.md at the lending-pool layer, applied here at the HLP-vault layer.
Attribution
pseudonymous. Three Hyperliquid accounts — identified at the funder-graph-cluster level by Arkham Intelligence and corroborated by independent forensic write-ups (Halborn, OAK Research, Cointelegraph timeline) — coordinated the short and long legs. No real-world identification has been published. The Solana-side spot-pump leg was attributed to a separate Solana-address cohort by post-event analysis; whether the spot-cohort and the perp-cohort are funder-graph-clustered is not publicly settled in the v0.4 reference cutoff.
Key teaching point
JELLY is the canonical 2025 worked example of T17.002 + T17.001 composing in the perp-DEX / centralised-liquidity-vault setting. The case demonstrates four structural lessons. First, self-liquidation can be a manipulation primitive when the venue's worst-case-counterparty design inherits liquidated positions into a centralised liquidity vault — the attacker did not need to find an external victim; the HLP vault was the structural victim by design. Second, cross-venue propagation from a thin-liquidity spot venue (Solana DEX spot) into a perpetual mark-price computation is the cleanest T17.001 instantiation OAK has at v0.4, and the load-bearing surface is the cross-venue spread itself rather than the perp's oracle layer. Third, validator-set discretionary settlement (closing the JELLY market at $0.0095, ignoring the manipulated mark price) is a recovery channel that depends on operator centralisation — the Hyperliquid validator quorum's ability to settle positions at an off-mark price is a centralisation tradeoff in the same family as the Shibarium BONE-freeze recovery channel examples/2025-09-shibarium-bridge.md, and future T17.x contributions should track both the existence and the centralisation-cost of this recovery channel. Fourth, the attacker engineered the extraction logic correctly but lost the asset-disposal race — the validator settlement zeroed out the long-side floating PnL faster than the attacker could withdraw it, demonstrating that validator-side counter-action is a credible deterrent against the T17.002 + T17.001 composed shape if the venue retains operator-side authority over the settlement primitive.

Summary

Hyperliquid is a perpetual-futures DEX operating on its own L1 (HyperEVM, post-2024). Liquidations on Hyperliquid that exceed the order-book's ability to absorb them are inherited by the HLP (Hyperliquid Liquidity Provider) market-making vault — a community-funded liquidity vault with approximately $230M in assets at the time of the JELLY incident. The HLP serves as the counterparty-of-last-resort: when a leveraged position is liquidated and the available order-book depth is insufficient to clear the position at the trigger price, the HLP inherits the residual position. This design works under normal market conditions because liquidations are typically small relative to the order-book depth, and the HLP earns spread / funding-rate income across the population of inherited positions. Under adversarial conditions — an attacker who engineers a forced-liquidation on a thin-liquidity perp and coordinates a cross-venue price excursion against the resulting inherited position — the design becomes the load-bearing T17.002 attack surface.

JELLY (full ticker JELLYJELLY) is a Pump.fun-launched Solana memecoin associated with Venmo / Cashapp founder Iqram Magdon-Ismail's "JellyJelly" social-app project. JELLY has thin spot depth on Solana DEX venues (Raydium, Orca) and was listed as a perpetual on Hyperliquid in the weeks before the incident.

On 2025-03-26 at approximately 13:53 UTC, an attacker began the manipulation by opening a $4.1M-$4.5M short position on JELLY perps from one Hyperliquid account, and simultaneously opening $2.15M and $1.9M long positions on JELLY perps from two other Hyperliquid accounts. The aggregate position structure was net-flat — the long and short legs offset — but the leg distribution across three accounts was the load-bearing design choice: the short-leg account was deliberately positioned to be liquidated, while the long-leg accounts were positioned to capture the resulting markup if the JELLY mark-price could be pushed up while the short was being liquidated. The attacker withdrew margin from the short account, raising its liquidation price and forcing the position to be liquidated by the protocol's automatic-liquidation engine. Because the short-position size (~$4.5M) materially exceeded the JELLY perp's order-book depth, the HLP vault inherited the residual short — meaning HLP became forced-short JELLY against an attacker-controlled long-side cohort.

A Solana-side cohort then bought a large quantity of JELLY spot on Solana DEX venues, driving the JELLY spot price up by approximately 250%-429% over the next hour. The Hyperliquid perp's mark-price computation propagated the spot-price excursion into the HLP's inherited short position; the HLP's short position accumulated unrealised loss reaching ~$13.5M at peak. Simultaneously, the attacker's two long-position accounts (the inverse of the HLP's forced short) accumulated unrealised profit, and the attacker began withdrawing margin from the long accounts before the position could be unwound — a structurally identical "withdraw before settlement" pattern to the short-leg setup, but now operating to extract the profit accrued from the cross-venue spot-pump.

At approximately 15:15:46 UTC (~82 minutes after the initial position-opening), the Hyperliquid validator set convened, voted unanimously within ~2 minutes (per the operator-side announcement), and delisted JELLY perps with all positions settled at $0.0095 — the open price at which the manipulation had begun. The settlement at $0.0095 (rather than the manipulated ~$0.50 mark) zeroed out the long-side floating PnL on the attacker's accounts. The Hyper Foundation announced that all non-flagged users with long positions would be made whole from foundation funds. The attacker had withdrawn approximately $6.26M of the $7.17M deposited; ~$900K remained on the long accounts and was frozen / locked at the $0.0095 settlement reference.

Net realised outcomes: HLP's 24-hour PnL closed at approximately +$700K positive after the settlement (the inherited short was closed at the favourable $0.0095 settlement price); the attacker's net economic outcome is approximately negative $1M (per Arkham Intelligence) if the residual $900K is never recoverable. The 8-hour validator-discretion settlement primitive is the load-bearing operator-side recovery channel; the Hyper Foundation reimbursement is the load-bearing user-side recovery channel. HYPE token (Hyperliquid's governance / fee token) dropped approximately 20% during the manipulation window in market-confidence response.

Timeline (UTC)

When Event OAK ref
pre-2025-03-26 Hyperliquid HLP vault standing in production: ~$230M AUM, inherits liquidated positions when order-book depth insufficient at trigger price; no per-token concentration cap, no per-position size cap (standing T17.002 + T9.004 surface)
2025-03-26 ~13:53 UTC Attacker opens ~$4.1M-$4.5M short on JELLY perp from account A; opens ~$2.15M long from account B and ~$1.9M long from account C T17.002 setup (self-liquidation engineering)
2025-03-26 T+minutes Attacker withdraws margin from account A, raising its liquidation price; protocol's auto-liquidation engine triggers; HLP vault inherits the residual short of ~$4.5M (forced-short on JELLY) T17.002 ignition
2025-03-26 T+minutes-to-hour Solana-side cohort buys JELLY spot on Solana DEX venues; JELLY spot price rises ~250-429% T17.001 cross-venue propagation
2025-03-26 T+30-60min Hyperliquid perp mark-price tracks Solana spot upward; HLP's inherited short position accumulates floating loss reaching ~$13.5M peak; attacker accounts B and C accumulate floating profit and begin withdrawing margin T17.002 + T17.001 (composed extraction window)
2025-03-26 ~15:15:46 UTC Hyperliquid validator set convenes; unanimous vote within ~2 minutes to delist JELLY perps and settle all positions at $0.0095 (the open-price reference) (validator-side discretionary settlement — recovery channel)
2025-03-26 T+82min All JELLY perp positions closed at $0.0095; attacker's long-side floating PnL zeroed; HLP's forced-short closed at favourable $0.0095 reference; HLP 24h-PnL closes ~+$700K T17.002 + T17.001 (settlement-side defeat of extraction)
2025-03-26 (post) Attacker withdrew $6.26M of $7.17M deposited before settlement; ~$900K frozen on long-side accounts (operator response — partial freeze)
2025-03-26 to 2025-03-29 Hyper Foundation announces non-flagged-user reimbursement; HYPE token down ~20% on market-confidence response; Binance lists JELLY spot, JELLY spot price runs ~560% (operator response + market-side propagation)
2025-03-26 to 2025-04-15 Validator-set governance changes announced in response to JELLY-delist criticism; Hyperliquid wiki publishes incident page citing the 2/3-validator-quorum settlement primitive (governance response)

What defenders observed

  • Pre-event (HLP-vault inheritance design): Hyperliquid's design that the HLP vault inherits liquidated-position residuals when order-book depth is insufficient is the load-bearing T17.002 surface. The same structural anti-pattern recurs across centralised-liquidity-vault designs in DeFi: lending-protocol bad-debt absorption (Aave's safety module, Compound's reserves), perpetual-DEX insurance funds (dYdX, GMX), and AMM-vault designs (Uniswap V4 hooks-class). The class-level mitigation is per-token concentration caps + per-position size caps + thin-liquidity-perp listing-guards; Hyperliquid had none of these in the JELLY perp listing at the time. Cross-reference to GMX V1 GLP examples/2025-07-gmx-v1.md at the vault-side accounting layer: both cases demonstrate that centralised-liquidity vaults that act as counterparty-of-last-resort to a perp / lending product require explicit per-asset and per-position concentration limits or the worst-case extraction can exceed a meaningful fraction of total vault AUM.
  • Pre-event (cross-venue listing parity): JELLY had thin spot depth on Solana DEX venues (Pump.fun-bonded plus subsequent Raydium / Orca migration) but was listed as a perpetual on Hyperliquid with the same standard inheritance design used for thicker-liquidity assets. The cross-venue-depth-asymmetry is itself the T17.001 attack surface: a Hyperliquid perp whose mark-price computation references a thin-spot venue is structurally exposed to spot-side manipulation, regardless of how the HLP-inheritance design behaves. The mitigation is at the listing-guards layer: perp listings should require minimum spot-venue depth (multi-venue, minimum cross-venue depth ratio) before listing.
  • At-event (forced-self-liquidation signature): the attacker opened offsetting positions across multiple accounts, then withdrew margin from one account to force its own liquidation. A real-time anomaly detector that correlated margin-withdrawal events with liquidation events on the same account, combined with offsetting-position detection across funder-graph-clustered accounts, would have produced a high-confidence signature in the same minute. Hyperliquid's runtime risk-engine layer did not deploy this detector at v1; the validator-set discretionary settlement was the load-bearing defender response.
  • At-event (cross-venue spread excursion): the JELLY spot-price excursion from ~$0.0095 to ~$0.04-$0.05 over ~30 minutes on Solana DEX venues was visible to any Solana-side spot-price monitor in real time. A T17.001-class detector that correlated Solana-spot price excursions with Hyperliquid perp position-distribution anomalies would have flagged the cross-venue manipulation within minutes of the spot-pump initiation. No public detector at this granularity was deployed.
  • At-event (validator-set discretionary settlement): Hyperliquid's validator-set ability to convene, vote, and settle positions at an off-mark price within ~2 minutes is the load-bearing operator-side recovery channel. The mechanism worked as designed — the manipulation was detected, voted on, and settled fast enough to defeat the attacker's extraction. The centralisation tradeoff is real: the validator set has discretionary authority over settlement prices, and the JELLY-delist precedent has been criticised by Hyperliquid's community as a centralisation marker (HYPE-token ~20% drop in the manipulation window reflects this).
  • Post-event (Hyper Foundation reimbursement): the foundation reimbursed all non-flagged long-position users for losses incurred during the manipulation window. This is a discrete recovery-channel category: foundation-funded reimbursement to non-flagged users — distinct from negotiated recovery (Mango Markets 2022), bounty-back (Curio 2024, KiloEx 2025), protocol-funded reimbursement (Vee Finance 2021), or freeze-via-protocol-owner-authority (Shibarium 2025 BONE side). The recovery channel depends on (a) the foundation having sufficient treasury reserves and (b) the foundation choosing to absorb the loss rather than passing it to HLP depositors.

What this example tells contributors writing future Technique pages

  • T17.002 + T17.001 compose at the centralised-liquidity-vault inheritance layer. The canonical T17.002 anchor (Lido stETH cascades) is at the lending-protocol liquidation layer. JELLY demonstrates the same Technique class applied at the perp-DEX HLP-inheritance layer. T17.x contributions documenting perpetual-DEX cases should explicitly check whether the venue has a centralised-liquidity vault that inherits liquidated positions, and whether per-token concentration / per-position size caps are present at listing time; if absent, T17.002 is a standing surface and T17.001 cross-venue propagation can compose if a thin-spot listed asset exists.
  • Self-liquidation can be a manipulation primitive when the venue's worst-case-counterparty inherits. This is a structural lesson distinct from the canonical T17.002 "external-victim cascade" framing — the attacker does not need to find external victims; the venue's HLP vault is the structural victim by construction. Contributors writing T17.002 cases should distinguish the external-victim cascade sub-shape (Lido stETH) from the self-liquidation-into-vault-inheritance sub-shape (JELLY) and document both.
  • Cross-venue propagation from thin-spot to thicker-perp is the cleanest T17.001 anchor at v0.4. The OAK T17.001 page's draft status flagged the absence of a clean dollar-loss-quantified cross-venue case; JELLY at ~$13.5M peak HLP exposure, with the cross-venue propagation directly driving the manipulation, is the cleanest worked example for promoting T17.001 from draft to emerging in a future minor version. The load-bearing surface is the cross-venue spread (Solana spot vs. Hyperliquid perp mark) — closing T9.001 by adding TWAP windows on the Hyperliquid mark-price would not close T17.001, because the manipulation lives on the spot-side venue not on the oracle layer.
  • Validator-set discretionary settlement is a recovery-channel category with centralisation cost. The validator-quorum settlement is structurally analogous to Mango Markets' DAO-vote settlement (2022) and to Shibarium's BONE-freeze (2025), but operates faster (~2 minutes vs. days) and at a structurally lower decentralisation level (validator-set quorum vs. token-holder vote vs. multisig owner). T17.x and T16.x contributions documenting venue-side recovery should categorise this discrete recovery channel and track its centralisation tradeoff: faster recovery = lower decentralisation.

Public references

Citations

  • [hyperliquidjellyannouncement2025] — operator-side first-acknowledgement and reimbursement announcement.
  • [hyperliquidwikijelly2025] — operator-aligned wiki incident page.
  • [halbornhyperliquid2025jelly] — independent audit-firm forensic walkthrough.
  • [arkhamjelly2025] — forensic-firm post-event reconstruction; canonical for the deposit / withdrawal / net-PnL accounting.
  • [coindeskjelly2025] — contemporaneous press; ~$13.5M peak HLP exposure framing.
  • [cointelegraphjelly2025] — contemporaneous press; per-account position structure.
  • [oakresearchjelly2025] — independent analyst write-up; cross-venue propagation framing.
  • [theblockjelly2025] — contemporaneous press; market-confidence response.
  • [zhou2023sok] — academic taxonomy classifying cross-venue manipulation as a recurring class.
  • [chainalysis2025rug] — market-manipulation aggregate; cross-venue patterns referenced.

Discussion

JELLY March 2025 is the canonical 2025 worked example for T17.002 + T17.001 composing in the perp-DEX / centralised-liquidity-vault setting. It pairs with the Lido stETH / Aave queue-saturation cascade (examples/2025-07-lido-steth-aave-cascade.md — T17.002 at the lending-pool layer) and with the GMX V1 GLP global-short-tracking exploit (examples/2025-07-gmx-v1.md — T17.002 + T9.004 at the perp-DEX vault-accounting layer) as the three-incident 2025 set demonstrating that centralised-liquidity vaults acting as counterparty-of-last-resort require explicit per-asset and per-position concentration limits, or the worst-case extraction can exceed a meaningful fraction of total vault AUM. The cross-incident pattern is structurally identical: the venue / protocol designed a centralised-liquidity vault to absorb tail-risk under normal conditions, the design did not enforce per-asset / per-position concentration limits, and an adversary engineered an extraction that exploited the missing limit.

The cross-venue propagation framing (Solana spot → Hyperliquid perp) is the load-bearing T17.001 contribution from this case. T17.001 was introduced as draft at v0.4 with an honest documentation gap — no clean dollar-loss-quantified cross-venue manipulation case had been anchored in the OAK corpus. JELLY at ~$13.5M peak HLP exposure, with the cross-venue spot-pump directly driving the manipulation, fills the gap and enables a future promotion of T17.001 from draft to emerging. The structural distinction from T9.001 (which manipulates the oracle's input venue) is preserved: in JELLY, the load-bearing surface is the cross-venue spread itself — closing T9.001 by adding TWAP windows on Hyperliquid's mark-price would not close the T17.001 surface, because the manipulation lives on the spot-side venue, not on the oracle integration.

The validator-set discretionary settlement is a discrete recovery-channel category. The full T17.x recovery-channel taxonomy now reads: (a) negotiated recovery via DAO vote (Mango Markets 2022); (b) bounty-back via on-chain message (Curio 2024, KiloEx 2025); (c) foundation-funded reimbursement to non-flagged users (Hyperliquid JELLY 2025); (d) validator-set discretionary settlement at off-mark price (Hyperliquid JELLY 2025); (e) freeze-via-protocol-owner-authority (Shibarium 2025 BONE side); (f) zero recovery (most external-victim cascade cases). Future T17.x / T16.x contributions documenting venue-side recovery should map each case to one of these categories explicitly and document the centralisation-cost tradeoff.

Attribution-strength is pseudonymous-cluster at the funder-graph-cluster level. The three Hyperliquid accounts are clustered by deposit funding source and by coordination of the offsetting position structure; the Solana-side spot-pump cohort is a separate cluster whose funder-graph relationship to the perp-side cluster is not publicly settled. The combination of coordinated multi-account perp-side position structure and separate spot-side cohort is the same shape as the canonical T8.001 cluster-reuse signal (Common-Funder Cluster Reuse) but at the cross-venue level rather than at the same-venue level — future T17.x cases should track this cross-venue cluster shape as a discrete attribution sub-pattern.

False-positive considerations: legitimate market-making activity routinely produces offsetting positions across multiple accounts, and legitimate arbitrage activity routinely produces cross-venue spread-closing trades. The detection signal is not "offsetting positions exist" or "cross-venue arbitrage occurred" but specifically "offsetting positions were structured with one leg deliberately positioned for self-liquidation, combined with a coordinated cross-venue spot-pump that propagates against the inherited residual" — the cohort-attribution requirement (clustering across the perp and spot legs) is necessary to distinguish the load-bearing T17.002 + T17.001 surface from honest market-making and honest arbitrage.

Techniques demonstrated (3)