According to the monitoring of Beosin EagleEye, a subsidiary of Beosin, the Defrost Finance oracle machine was maliciously modified, and a fake mortgage token was added to liquidate current users, resulting in a loss of more than 13 million US dollars. The attacker modified the address of the oracle through the setOracleAddress function, then used the joinAndMint function to mint 100,000,000 H20 tokens to the address 0x6f31, and finally called the liquidate function to obtain a large amount of USDT through the fake price oracle. Subsequent attackers transferred the stolen funds to Ethereum’s 0x4e22 through cross-chain methods. Currently, there are 4.9 million USD in DAI at 0x4e22 address, 5 million USD in DAI at 0xfe71 address, and the remaining 3 million USD in ETH. Moved to address 0x3517.