Meet the Top 101 in Crypto
Security
Complexity Icon Easy
9 min read

Was the Oct.10 Market Crash a Coordinated Crypto Attack? Here’s What the On-Chain Evidence Says

Published 13 October 2025
Giuseppe Ciccomascolo
Authors

Key Takeaways

  • The crypto market was shocked by $19.3 billion in liquidations within hours, the largest ever recorded.
  • It was triggered by what appeared to be a $60 million sell-off, which was later revealed to be part of a coordinated oracle manipulation attack.
  • A single “whale” reportedly held $1.1B in short positions, profiting over $80M in 24 hours.
  • The crash demonstrates that financial structure can be weaponized like code.

The crypto market event of Oct. 10-11, 2025, was an anomaly that shook the entire digital asset ecosystem, resulting in a staggering $19.3 billion in liquidations, the largest in history.

While initial reports quickly blamed a broader market panic following tariff announcements, a deeper, forensic analysis of the on-chain data and trading patterns reveals a far more precise and troubling story.

This was not a random market crash. The evidence strongly suggests a deliberate, carefully planned oracle manipulation attack, weaponizing a known vulnerability against a system scaled to institutional size.

The cost to the attacker was minimal, an estimated $60 million market dump. However, the destruction was amplified over 300 times, laying bare an industry-wide failure to learn from five years of repeated history.

Try Our Recommended Crypto Exchanges
Sponsored
Disclosure
Opened in 2011
Promotions
Get $10 in Bitcoin when you register through a referral link from an existing member.
Coins
Bitcoin Ethereum Tether Build'N'Build USD Coin +81
Promotions
Receive up to $100,000 worth of exclusive gifts for newcomers upon registration.
Coins
Bitcoin Ethereum Tether USD Coin Solana +76
Opened in 2017
Promotions
Experience a 1-minute swap on a non-custodial platform.
Coins
Bitcoin Ethereum Tether Build'N'Build USD Coin +217
Show More

First Warning Sign: Why USDe, wBETH, and BNSOL Crashed Only on One Exchange

The immediate red flag in the October event was its hyper-specific nature. While market panic typically affects all exchanges simultaneously, this event is discriminated by venue, concentrating the carnage on a single central platform.

The crash centered on three specific assets that experienced catastrophic price collapses, but only on this single exchange:

  1. USDe: Plummeted to $0.6567 on the target exchange while maintaining parity (or near-parity) on all other venues and on-chain liquidity pools.
  2. wBETH: Crashed to $430, an incredible 89% below the value of ETH, which it is supposed to track.
  3. BNSOL: Tumbled to $34.9, with minimal corresponding movement on other major exchanges.
Binance response to market crash
Binance response to market crash. | Credit: YQ X profile

This venue-specific destruction is highly inconsistent with genuine asset impairment. If USDe was truly impaired, its value would have dropped across all markets. Instead, its price moved dramatically on the source exchange for the oracle while remaining stable everywhere else. The system was liquidated based on prices that existed nowhere else in the broader market.

Crypto Market Manipulation Timeline: How the October 2025 Crash Exploited a Known Vulnerability Window

Here is where the hypothesis of coordination gains traction: the attack occurred within a predictable, announced vulnerability window.

On Oct. 6, Binance announced updates to the pricing mechanisms for these three assets. The scheduled implementation date was Oct. 14. The crash occurred on Oct. 10-11, precisely in the middle of this eight-day pre-announcement window.

Is it a coincidence that out of thousands of trading pairs, only those with announced, upcoming oracle updates experienced such extreme depegs? The probability is negligible.

Crypto exchange liquidations
Crypto exchange liquidations. | Credit: KobeissiLetter X profile

The attacker knew oracle dependencies, had predictable transition timing, and had eight days to position and prepare. The attack exploited the transition between Oracle methodologies, a vulnerability that only existed because the improvements were announced before implementation.

Oct. 10-11 Crypto Crash Timeline (UTC+8)

The event followed a highly synchronized, sequential execution, suggesting deliberate execution rather than random chaos:

Time Event Description
5:00 AM Initial market movement The Bitcoin decline from $119,000 begins. Trading volumes are within normal parameters.
5:20 AM First liquidation cascade Altcoin liquidations accelerate. Volume spikes 10x regular trading activity. This action is consistent with a targeted elimination of market maker positions, forcing them to withdraw liquidity from the system.
5:43 AM Critical depeg event A $60 million USDe dump hits the spot market. The oracle, relying on this single venue’s spot price, marks down collateral immediately. USDe crashes to $0.6567.
5:44 AM Simultaneous collapse wBETH and BNSOL follow immediately as the cascade triggers. The 23-minute gap between general liquidations (5:20 AM) and the specific asset crashes (5:43 AM) suggests sequential execution, first eliminating the market’s defense, then attacking the primary targets.
6:30 AM Market structure breakdown Total liquidations exceed $10 billion. Market makers are completely withdrawn. The $19.3 billion in total liquidations is set.

This timeline confirms the attack was initiated by a precise $60 million spot dump amplified into a $19.3 billion liquidation cascade.

The sequential pattern, eliminating liquidity first, then hitting the specific targets, is the hallmark of a sophisticated, coordinated action.

Was the 2025 Crypto Crash an Inside Job? Tracking the Whale Behind the $1.1B Short

The sheer scale of the profits made during this “black swan” event immediately raises the question: Was this a prediction or an inside job?

Yesterday, a black swan event struck the market, marking the largest margin call in crypto history. However, someone managed to short the market in advance, establishing over $1.1 billion in short positions and generating profits exceeding $80 million in 24 hours.

Garrett Bullish
Garrett Bullish reacted to allegations on his X profile. | Credit: GarrettBullish X profile

The true identity of this whale, who had the foresight to position such massive shorts, has drawn intense market scrutiny.

Identity Clues and Background

A thread by the online sleuth “Eye” revealed the suspected identity of this whale as Garrett Jin (also known as Garrett Bullish on social media). The investigation traced the transaction fees of the wallet that opened a massive $735 million Bitcoin short position to an address linked to the ENS name “garrettjin.eth.”

Eye conducted an investigation on Garrett Bullish
Eye conducted an investigation on the whale involved in Oct. 10 market crash. | Credit: Eye X profile

Garrett Jin’s background is highly relevant to the operation’s sophistication:

  • He served as Director of Operations at Huobi (HTX) until 2015.
  • From 2017 to 2020, he was CEO of BitForex, an exchange later embroiled in a trading volume scandal and a private key breach that resulted in a loss of approximately $57 million before its eventual shutdown.

Suspicious Capital Flows

The capital positioning of this whale was extraordinary and potentially suspicious:

  • Between August and September, the whale sold over 35,000 Bitcoin (BTC) for Ethereum (ETH) via Hyperliquid/Hyperunit spot and perpetual contracts.
  • Simultaneously, the whale placed $735 million in short Bitcoin orders on the same platform.
  • The whale holds over 100,000 Bitcoins in various addresses.

Furthermore, reports suggest that a wallet that transferred gas for the whale’s activity also moved 1.31 million USDC to a research firm’s Binance deposit address, suggesting potential advance knowledge or data exchange.

On-chain investigator Eye expressed caution regarding the cross-verification, highlighting the challenge in definitively linking all these BTC holdings to a single entity.

Despite the uncertainty surrounding the complete veracity of the “Eye” investigation, the highly organized, pre-positioned shorts and the principal’s background add a layer of deep suspicion to the operational planning of the crash.

DeFi’s Oracle Problem: How Design Oversight Turned $60M Into $19.3B in Liquidations

A $60 million dump could cause $19.3 billion in destruction, due to a systemic flaw in oracle design that the industry has failed to address for five years.

A leveraged system needs an oracle to price collateral. The fundamental challenge is balancing sensitivity to price changes (to react to real losses) with stability (to prevent manipulation). The target exchange’s oracle design chose high sensitivity, relying heavily on spot prices from its primary trading venue.

Oracle
How price feed deisgn turned $60 million into a $19 billion crash. | Credit: YQ X profile

This intuition is the exact flaw that has destroyed billions across previous oracle attacks. Volume concentration isn’t evidence of price accuracy; it’s evidence of manipulation opportunity.

The Five-Year Attack Blueprint

The October 2025 event was a 160x amplification of the largest previous oracle attack, but the blueprint was identical to those used since 2020:

Previous Attack Date Manipulation Damage amplification
bZx Feb 2020 Single-source oracle (Uniswap) flash loan manipulation $10 million borrowed to $350,000 extracted
Compound Nov 2020 Single-venue manipulation (Coinbase Pro DAI spike) $100,000 manipulation to $89 million liquidated
Mango Markets Oct 2022 Multi-venue token pump (MNGO) to inflate collateral $5 million initial capital to $117 million extracted
October 2025 Oct 2025 Single-venue spot dump (USDe/USDT) to trigger cascade $60 million manipulation to $19.3 billion destroyed

The common thread is the same: Identify oracle dependence on a manipulatable source, calculate the manipulation cost, execute, and profit.

The Amplification Factor

The system was vulnerable due to a combination of factors that amplified the initial $60 million dump:

  • Hidden leverage: Yield programs encouraged recursive borrowing, creating leveraged positions up to 10 times based on USDe collateral.
  • Concentration Risk: The oracle relied too heavily on the internal spot price of the target exchange.
  • Infrastructure Failure: The initial liquidation cascade caused a “server busy” state, leading to a liquidity vacuum as market makers (MMs) couldn’t place bids on time. This is the Harvest Finance (2020) pattern at the institutional scale: the attack overloaded the infrastructure, accelerating the cascade.

The $60 million manipulation destroyed $19.3 billion, equal to amplification of 322 times. This is not a failure of technical sophistication; it’s a failure to update fundamental system design to match the institutional scale.

Implications: Weaponizing Crypto Market Structure

If this were a coordinated attack (and the evidence strongly aligns with this hypothesis), it represents a dangerous new evolution in crypto market manipulation. 

Attackers didn’t need to hack systems or steal keys; they simply weaponized the market structure and the oracle’s design flaws.

The total potential profit extracted, through short profits, asset accumulation at distressed prices, and cross-exchange arbitrage, is estimated at $800 million to $1.2 billion. These are heist-level returns achieved not through a security breach, but through game theory and transparent system design.

Conclusion

The systemic lessons are clear:

  1. Transparency paradox: Announcing oracle improvements in advance paradoxically created an exploitable attack window.
  2. Oracle design is systemic risk: Over-reliance on manipulatable spot prices, the central design flaw in the 2020 attacks, remains the industry’s greatest systemic vulnerability.
  3. Infrastructure is a bottleneck: Systems must be designed for 100x normal capacity to handle the exponentially increasing load that a liquidation cascade generates.

The Oct. 10-11 event was many things, but one thing it was not was random. It was the Oracle Attack Theorem proven valid at unprecedented scale.

Until the industry universally adopts robust, multi-source, time-weighted oracles and designs infrastructure for stress, traders must assume that every transparent announcement and every high-volume exchange order book is a potential vector for attack.

FAQs

What exactly happened on Oct. 10-11?

A sudden, massive crash wiped out over $19.3 billion in leveraged crypto positions, the largest liquidation event in history. At first, it looked like a market panic triggered by global tariff news. However, on-chain data and trading analysis indicate it was likely a coordinated oracle manipulation attack, not a random crash.

What is an oracle attack?

An oracle is a system that feeds real-world prices into blockchain applications. An oracle attack occurs when a trader or group manipulates these price feeds to trigger liquidations or extract profits. In this case, the attacker dumped about $60 million worth of tokens to distort prices on a single exchange, enough to mislead automated systems and spark a massive chain reaction.

Who is suspected to be behind the attack?

On-chain analysts traced massive pre-positioned shorts worth over $1.1 billion to a wallet linked to Garrett Jin (aka Garrett Bullish), a former executive at Huobi and BitForex. While definitive proof is still under review, the timing, size, and sophistication of his positions make him a key person of interest in ongoing investigations.

What is the “Oracle Attack Theorem”?

It’s the idea that any system dependent on manipulatable price oracles can be attacked using predictable, legal market actions, with no hacking required. Attackers exploit transparency, timing, and structure to trigger profitable chaos. This event proved that theorem at institutional scale.

Disclaimer: The information provided in this article is for informational purposes only. It is not intended to be, nor should it be construed as, financial advice. We do not make any warranties regarding the completeness, reliability, or accuracy of this information. All investments involve risk, and past performance does not guarantee future results. We recommend consulting a financial advisor before making any investment decisions.
Giuseppe Ciccomascolo

Giuseppe Ciccomascolo began his career as an investigative journalist in Italy, where he contributed to both local and national newspapers, focusing on various financial sectors.

Upon relocating to London, he worked as an analyst for Fitch's CapitalStructure and later as a Senior Reporter for Alliance News. In 2017, Giuseppe transitioned to covering cryptocurrency-related news, producing documentaries and articles on Bitcoin and other emerging digital currencies. He also played a pivotal role in establishing the academy for a cryptocurrency exchange website. Crypto remained his primary area of interest throughout his tenure as a writer for ThirdFloor.

Survey Icon
Help us improve
1 of 4
Is this your first time here?
What brought you here today?
What are you most interested in?
Would you be interested in:
Thank you icon
Thank you for your feedback!
DMCA.com Protection Status