Decentralized finance platform Rocket officially suspended all deposit, withdrawal, and trading activities across its network on September 7, 2026. The shutdown follows a security exploit that resulted in the loss of $287,000 in assets from the platform. The attack took place two days prior, on September 5 at around 19:00 UTC.
According to blockchain security firm SlowMist, the incident affecting Rocket has been classified purely as a price manipulation attack. The perpetrator targeted a vulnerability within the decentralized exchange system: a dormant perpetual contract market.
Wash Trading Through a Burner Account
To carry out the attack, the perpetrator deployed a burner account. Through this intermediary entity, the hacker flooded the inactive perpetual market with orders at prices inflated far beyond the asset’s fair value. Once the orders were placed, the attacker repeatedly traded against themselves. This self-dealing manipulation was designed to generate artificial market activity without real user interaction.
The wash trading successfully manipulated the exchange’s valuation reporting system. This scheme generated artificial profits in the attacker’s primary account, while the paired burner account rapidly absorbed all bad positions and became insolvent. Once the platform registered a positive balance, the primary account withdrew $287,000 in funds. All stolen assets were bridged across the platform’s cross-chain facility.
The repercussions of the exploit extended beyond the hacker’s pocket. The net loss of $287,000 was not borne by the Rocket protocol alone, but was instead distributed across the platform’s entire user base through a loss socialization mechanism. Because the system evenly split the exchange’s deficit, the drained funds directly reduced the collective portfolio value of platform users who were not even involved in the trades.
Mirroring the Hyperliquid Incident
Exploiting illiquid markets is not new to the decentralized ecosystem. The perpetrator’s manipulation method mirrors an attack that hit the Hyperliquid platform in March 2025. In that incident, an attacker exploited the JELLY contract market, which had dried up of daily liquidity, to artificially pump the asset’s price and extract fake profits.
Rocket management is currently coordinating closely with centralized crypto exchanges, cross-chain bridge operators, and stablecoin issuers to trace the movement of the stolen funds. The primary objective is to block cash-out routes. However, Rocket has not yet reported the amount of assets successfully frozen, nor disclosed the specific security firm hired to handle the investigation.
An illiquid contract market is more than just a blank screen - it can sometimes serve as an open door for hackers. Reported by crypto.news.
Also read: What Is DeFi (Decentralized Finance)?
Also read: DefiLlama Releases Wall Street-Style Crypto Ratings - Out of 128 Tokens, Only Uniswap Earns AAA
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




