
Rocket has suspended deposits, withdrawals and trading after an attacker manipulated a dormant perpetual market and withdrew approximately $287,000 in positive PnL from the platform’s Bridge.
Summary
- An attacker manipulated a dormant Rocket perpetual market using inflated orders and self trades, creating artificial profits before withdrawing approximately $287,000.
- Rocket has paused deposits, withdrawals and trading while security firms and law enforcement investigate the Sept. 5 incident.
- The platform is working with exchanges, bridges and stablecoin issuers to trace and freeze the stolen funds.
- Rocket is preparing a recovery plan that will prioritize refunds for smaller affected accounts.
Rocket said in a Sept. 7 update on X that the security incident occurred at approximately 19:00 UTC on Sept. 5, when an attacker targeted an inactive perpetual market using a burner account.
The attacker placed orders at artificially inflated prices and traded against themselves, creating artificial profits in one account while pushing the burner account into bankruptcy. The profitable account subsequently withdrew around $287,000 from the Bridge, leaving the resulting loss to be socialized across the platform.
Rocket attack used self trading to create artificial profits
Instead of describing a smart contract vulnerability, Rocket’s initial account of the incident centered on the manipulation of a dormant perpetual market with limited activity.
Using a disposable account, the attacker was able to post orders at inflated prices before acting as both sides of the trades. Rocket said the transactions generated “fake profits” for one account while the burner account accumulated the corresponding losses and became insolvent.
The account showing positive PnL then withdrew approximately $287,000 through the Bridge before the activity was stopped.
Rocket has since paused all trading, deposits and withdrawals while its team investigates the incident. The project did not provide a timeline for restoring the affected services or disclose how many users were exposed to the socialized loss.
Blockchain security tracker SlowMist classified the incident as a price manipulation attack and recorded the loss at $287,000.
The method bears similarities to previous incidents in thin perpetual markets where traders have been able to manipulate prices or positions and transfer resulting losses to liquidity providers or other parts of a trading platform.
In March 2025, a trader targeted Hyperliquid’s thin JELLY market by opening a large short position while buying the token on decentralized exchanges. The activity drove JELLY’s price sharply higher and pushed the short toward liquidation, eventually transferring the position to Hyperliquid’s liquidity vault.
As crypto.news previously reported, Hyperliquid restricted the trader’s accounts to reduce-only mode before validators later voted to delist the JELLY perpetual market and settle outstanding positions.
A separate Hyperliquid incident in March 2025 saw its HLP vault absorb around $4 million in losses after a trader withdrew collateral from a highly leveraged Ether position before liquidation. Hyperliquid said at the time that the event was not a protocol exploit and subsequently changed leverage requirements for Bitcoin and Ether positions.
Rocket seeks to freeze the stolen $287,000
With platform operations suspended, Rocket said it is working with security firms and law enforcement agencies to investigate the attack and recover the funds.
The team is coordinating with cryptocurrency exchanges, cross-chain bridges and stablecoin issuers to trace the stolen assets and attempt to freeze them. Rocket has not disclosed the identities of the security companies or law enforcement agencies involved in the investigation.
Similar measures have been used after other recent DeFi incidents, particularly when attackers attempt to move funds through bridges or centralized trading venues.
AFX suffered a cross-chain bridge exploit in July that drained 24.15 million USDC. Security firm Blockaid worked with the Arbitrum team to investigate the incident as the attacker transferred the stolen USDC to Ethereum and converted the proceeds into 12,467.5 ETH.
Earlier in June, Axelar disabled bridge routes connected to Secret Network after an exploit resulted in roughly $4.7 million in losses. Axelar said the incident was limited to bridged assets on Secret Network and did not compromise its core protocol.
Rocket has not disclosed whether any portion of the $287,000 has been frozen or recovered so far.
Smaller Rocket accounts are first in line for refunds
The team is preparing a recovery plan for users affected by the incident, with smaller accounts expected to receive priority when refunds begin.
Rocket said it understands that compensation is the update affected users are waiting for but will provide specific details only when it can do so responsibly. The platform has not yet disclosed the size of its available recovery funds, eligibility requirements, payment method or a timetable for reimbursements.
Recovery programs have taken different forms following previous attacks on decentralized trading protocols.
GMX, for example, completed a roughly $44 million compensation plan in August 2025 for liquidity providers affected by an exploit of its V1 GLP pool. The protocol used GLV tokens for distributions, while its DAO treasury covered a $2 million shortfall.
The GMX attacker had previously returned approximately $37.5 million of the roughly $42 million stolen after the protocol offered a 10% white-hat bounty. The affected V1 system was paused after the attack, while GMX V2 remained operational.
Rocket has not announced a similar bounty or offered terms directly to the attacker. Its current recovery effort remains focused on tracing the withdrawn funds and developing a reimbursement plan.
The platform warned users to watch for impersonators attempting to take advantage of the incident. Rocket said recovery information will be published only through its official X account and Discord channels, adding that team members will not contact affected users first through direct messages.





Be the first to comment