Phemex Potential Manipulation of ETH Prices in $20M Papertrade Incident
Article Content
- •Two wallets reportedly manipulated ETH prices on Hyperliquid with $20 million trades.
- •The Papertrade protocol's pricing mechanism is vulnerable to manipulation via BBO.
- •A trader profited $1.28 million by exploiting the pricing mechanism within eight hours.
On October 11, 2026, two wallets allegedly manipulated Ether (ETH) prices on the Hyperliquid platform by executing $20 million in trades, potentially affecting Papertrade's synthetic pricing. The trades moved ETH prices by 0.1% to 0.2%, raising concerns about the vulnerability of Papertrade's pricing mechanism, which relies on Hyperliquid's best bid and offer (BBO). Reports indicate that a trader exploited this mechanism to earn approximately $1.28 million in profit within eight hours by manipulating prices through large trade volumes. Despite community accusations and the acknowledgment of risks in Papertrade's documentation, there is no confirmed proof of the wallets' identities or losses incurred. As of now, the situation remains unresolved, with no official response from Papertrade and no compensation plans announced. The incident has led to increased trading volume for ETH, surpassing Bitcoin's, indicating heightened market activity linked to the exploit.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Huo Xing Finance in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What is the nature of the exploit?
What are the implications for Papertrade users?
What actions are being taken by Papertrade?
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…