
A dormant trading pair that almost nobody was watching became the entry point for one of the more unusual DeFi exploits of the year. Rocket, a decentralized perpetual trading platform, has confirmed that a Rocket perpetual market hack drained roughly $287,000 from the protocol after an attacker manipulated prices on a market that had seen little to no activity, then walked away with the funds before anyone could stop it.
Key takeaways
- Rocket lost approximately $287,000 after an attacker manipulated a dormant perpetual market at around 19:00 UTC on Sept. 5, 2026.
- The attacker used a burner account to post artificially inflated orders and trade against themselves, creating fake profits before withdrawing funds through Rocket’s Bridge.
- Rocket has suspended all deposits, withdrawals, and trading while it works with security firms and law enforcement to trace and freeze the stolen assets.
- Blockchain security firm SlowMist classified the event as a price manipulation attack.
- Rocket says smaller accounts will be prioritized in any future refund plan, though no timeline or amount has been disclosed.
Price manipulation attack causes $287K loss on Rocket platform
The incident happened fast and quietly. According to a Sept. 7 update Rocket posted on X, the price manipulation attack unfolded at approximately 19:00 UTC on Sept. 5, when an attacker set their sights on an inactive perpetual market that had drawn little trading interest and, apparently, little scrutiny.
Rocket described the target as a “dormant” market — the kind of quiet corner of a trading platform that rarely attracts attention until something goes wrong. That lack of activity turned out to be exactly what made it vulnerable.
How the burner account scheme worked
Instead of exploiting a bug in smart contract code, the attacker relied on a more manual approach. Using a disposable burner account, they posted orders at artificially inflated prices, then effectively traded against themselves. That self-trading created what Rocket called “fake profits” in one account while simultaneously pushing the burner account itself into bankruptcy.
Once the profitable side of the trade showed a healthy balance, the attacker withdrew roughly $287,000 through Rocket’s Bridge before the platform’s team caught on and shut things down. The resulting loss was left to be absorbed across the platform, though Rocket has not said how many users were affected by that socialized hit.
Rocket suspends trading and launches investigation
Rocket’s first move was to freeze the platform entirely. Deposits, withdrawals, and trading were all paused while the team investigated what had happened and how far the damage extended. No timeline has been given yet for restoring those services.
Blockchain security tracker SlowMist independently reviewed the incident and classified it as a price manipulation attack, confirming the $287,000 loss figure that Rocket had already disclosed.
Tracing funds across exchanges and bridges
With the platform on lockdown, Rocket said it is now working alongside security firms and law enforcement agencies to investigate the breach and attempt to recover the stolen money. The team is reportedly coordinating with cryptocurrency exchanges, cross-chain bridges, and stablecoin issuers in hopes of tracing where the funds ended up and freezing them before they can be laundered further.
Rocket has not named the security firms or law enforcement bodies involved, and it has not confirmed whether any portion of the $287,000 has actually been frozen or recovered so far.
This kind of multi-party tracing effort has become fairly standard after recent DeFi breaches. A cross-chain bridge exploit at AFX in July drained 24.15 million USDC, prompting security firm Blockaid to work with the Arbitrum team after the attacker converted the stolen funds into 12,467.5 ETH. Similarly, Axelar disabled bridge routes tied to Secret Network in June after an exploit caused about $4.7 million in losses, saying the damage was limited to bridged assets rather than its core protocol.
Recovery plan prioritizes smaller accounts
Rocket says it understands that a compensation timeline is the update most affected users are actually waiting for, but the platform has stopped short of giving one. What it has confirmed is that any recovery plan will prioritize smaller accounts first once refunds begin.
Beyond that, the details remain thin. Rocket has not disclosed the size of any available recovery fund, who exactly qualifies for reimbursement, how payments would be issued, or when any of this might happen.
Warning against impersonators
As is common after high-profile security incidents, Rocket has also warned its community to be on guard against scammers posing as the platform or its staff. The team said all official updates on the recovery process will come exclusively through its verified X account and Discord channels, and that no team member will ever reach out to affected users first through direct messages.
Notably, Rocket has not announced any bounty offer or opened negotiations directly with the attacker — a route some other protocols have taken after similar breaches.
Rocket incident echoes past perpetual market manipulation cases
This isn’t the first time a thinly traded perpetual market has become a pressure point for an entire platform. The pattern of exploiting low liquidity to distort prices, then shifting the resulting losses onto liquidity providers, has shown up before in decentralized trading protocols.
In March 2025, a trader targeted Hyperliquid’s thin JELLY market by opening a large short position while simultaneously buying the token on decentralized exchanges. That combination drove JELLY’s price sharply higher, pushing the short position toward liquidation and eventually transferring it onto Hyperliquid’s liquidity vault. Hyperliquid responded by restricting the trader’s accounts to reduce-only mode, and validators later voted to delist the JELLY perpetual market entirely and settle the outstanding positions.
A separate Hyperliquid incident that same month saw its HLP vault absorb around $4 million in losses after a trader pulled collateral from a heavily leveraged Ether position right before liquidation. Hyperliquid maintained that event wasn’t a protocol exploit, but it still changed leverage requirements for Bitcoin and Ether positions afterward.
Recovery efforts across the industry have varied widely in scope and speed. GMX completed a roughly $44 million compensation plan in August 2025 for liquidity providers hit by an exploit of its V1 GLP pool, distributing funds using GLV tokens while its DAO treasury covered a $2 million shortfall. That case also involved the attacker voluntarily returning about $37.5 million of the roughly $42 million stolen after GMX offered a 10% white-hat bounty — a negotiation route Rocket has not pursued.
What links these cases together is a structural weakness that keeps resurfacing across decentralized trading platforms: markets with thin liquidity or little activity are far easier to manipulate, and the resulting losses tend to land on liquidity providers or the broader user base rather than staying contained to the attacker’s own risk. Whether Rocket’s eventual reimbursement plan closes that gap for affected users, or simply manages the fallout, remains an open question the platform has yet to answer.
FAQ
How did the attacker exploit Rocket’s perpetual market?
The attacker manipulated a dormant perpetual market by placing artificially inflated orders and trading against themselves using a burner account, creating fake profits.
What was Rocket’s response to the security incident?
Rocket suspended all deposits, withdrawals, and trading while investigating the attack, and is working with security firms and law enforcement.
Will all affected users be reimbursed for their losses?
Rocket plans to prioritize refunds for smaller accounts but has not provided a timeline, eligibility, or payment method yet.
Are there any security warnings for Rocket users?
Rocket warns users to avoid impersonators and rely only on official communication channels for updates regarding the incident.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

1 hour ago
13








English (US) ·