
According to reports from Rocket, a security incident occurred at approximately 19:00 UTC on September 5 when an attacker targeted an inactive perpetual market using a burner account. The attacker placed orders at artificially inflated prices and traded against themselves, creating artificial profits in one account while pushing the burner account into bankruptcy. The profitable account subsequently withdrew approximately $287,000 from the Bridge, leaving the resulting loss to be socialized across the platform. Rocket has since paused all trading, deposits and withdrawals while its team investigates the incident. The platform described the target as a "dormant" market - a quiet corner of the trading platform that rarely attracts attention until something goes wrong, making it particularly vulnerable to manipulation.
As reported by Rocket, the platform is working with security firms and law enforcement agencies to investigate the attack and recover the funds. The team is coordinating with cryptocurrency exchanges, cross-chain bridges and stablecoin issuers to trace the stolen assets and attempt to freeze them. Blockchain security tracker SlowMist independently reviewed the incident and classified it as a price manipulation attack, confirming the $287,000 loss figure. Rocket has not disclosed the identities of the security companies or law enforcement agencies involved in the investigation. The platform is preparing a recovery plan for users affected by the incident, with smaller accounts expected to receive priority when refunds begin. The team understands that compensation is the update affected users are waiting for but will provide specific details only when it can do so responsibly.
According to Rocket's September 7 update on X, the attacker used a disposable account to post orders at inflated prices before acting as both sides of the trades. The transactions generated "fake profits" for one account while the burner account accumulated the corresponding losses and became insolvent. The method relied on a manual approach rather than exploiting smart contract bugs, with the attacker effectively trading against themselves to create artificial market conditions. Blockchain security tracker SlowMist classified the incident as a price manipulation attack and recorded the loss at $287,000. The method bears similarities to previous incidents in thin perpetual markets where traders have been able to manipulate prices or positions and transfer resulting losses to liquidity providers or other parts of a trading platform.
As reported by crypto.news, similar incidents have occurred in the DeFi space, including a March 2025 attack on Hyperliquid where a trader targeted the thin JELLY market by opening a large short position while buying the token on decentralized exchanges. In another Hyperliquid incident in March 2025, the HLP vault absorbed around $4 million in losses after a trader withdrew collateral from a highly leveraged Ether position before liquidation. AFX suffered a cross-chain bridge exploit in July that drained 24.15 million USDC, while Axelar disabled bridge routes connected to Secret Network after an exploit resulted in roughly $4.7 million in losses. GMX completed a roughly $44 million compensation plan in August 2025 for liquidity providers hit by an exploit, distributing funds using GLV tokens while its DAO treasury covered a $2 million shortfall.
According to Rocket, the platform has not disclosed whether any portion of the $287,000 has been frozen or recovered so far. The platform warned users to watch for impersonators attempting to take advantage of the incident and stated that recovery information will be published only through its official X account and Discord channels. Team members will not contact affected users first through direct messages. Rocket has not announced a similar bounty or offered terms directly to the attacker, with its current recovery effort remaining focused on tracing the withdrawn funds and developing a reimbursement plan. The platform has confirmed that any recovery plan will prioritize smaller accounts first once refunds begin, though no specific timeline, eligibility criteria, or payment method has been disclosed. The platform has not announced a similar bounty or opened negotiations directly with the attacker, with its recovery effort focused on tracing the stolen assets rather than negotiating with the perpetrator.