{"investigation":{"slug":"0vix","entity_name":"0VIX","trust_score":28,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"0VIX was a DeFi lending protocol built on Polygon PoS and Polygon zkEVM, forked from the Compound v2 codebase, that launched as one of Polygon zkEVM's inaugural partners. On April 28, 2023, an attacker exploited a price oracle vulnerability in the protocol's vGHST market using a flash loan, draining approximately $2 million in user funds from a total TVL of $6.4 million. Stolen funds were bridged to Ethereum via Stargate Finance and deposited into Tornado Cash; the attacker did not respond to a $125,000 bounty offer. The protocol subsequently rebranded as Keom in August 2023.","sections":[{"content":"0VIX was a decentralized lending and borrowing protocol operating on Polygon PoS and Polygon zkEVM, forked from Compound v2. It allowed users to supply collateral and borrow assets against it. The protocol was audited by WatchPug in May 2022 and served as an early launch partner for Polygon's zkEVM rollout. At its peak, the protocol held approximately $6.4 million in total value locked (TVL). Following a significant exploit in April 2023, the protocol rebranded as Keom in August 2023 and has since migrated operations to that identity.","heading":"Overview","sources":[{"url":"https://www.coindesk.com/business/2023/04/28/defi-protocol-0vix-loses-nearly-2m-in-flash-loan-exploit","name":"coindesk.com","type":"other","credibility":3},{"url":"https://defillama.com/protocol/0vix","name":"defillama.com","type":"other","credibility":3},{"url":"https://assets.website-files.com/622a09bc809cd190f58b7b15/627a5d6eea14146296b3261b_0VIX_Audit_Report_by_WatchPug.pdf","name":"assets.website-files.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On April 28, 2023, an attacker executed a multi-step exploit against the 0VIX protocol using three attacker-controlled addresses (0x407, 0x49c, and 0x702). The attack unfolded as follows: the attacker obtained flash loans totaling approximately 24.5 million USDC, 6.15 million USDT, and 1.95 million GHST from AAVE and Balancer. The attacker used these borrowed funds to open large lending positions on 0VIX and artificially inflate demand for the vGHST token, manipulating the protocol's price oracle. The GHST token price surged approximately 24.7% from $1.13 to $1.41 within 30 minutes, rendering the vGHST lending pool insolvent. The attacker then liquidated positions and extracted collateral, making off with approximately 1.45 million USDC and 58,400 USDT, among other assets. The net liquidity loss to the protocol is reported at approximately $4.33 million when accounting for the full liquidity impact, with direct theft estimated at around $2 million. The vulnerability exploited was a weak oracle design introduced when vGHST was listed as a market on March 17, 2023.","heading":"April 2023 Flash Loan and Oracle Manipulation Exploit","sources":[{"url":"https://www.coindesk.com/business/2023/04/28/defi-protocol-0vix-loses-nearly-2m-in-flash-loan-exploit","name":"coindesk.com","type":"other","credibility":3},{"url":"https://decrypt.co/138262/polygon-lending-protocol-0vix-pauses-protocol-exploit","name":"decrypt.co","type":"other","credibility":3},{"url":"https://cryptodaily.co.uk/2023/04/0vix-protocol-drained-for-2m-in-oracle-manipulation-exploit-update","name":"cryptodaily.co.uk","type":"other","credibility":3},{"url":"https://quillaudits.medium.com/decoding-ovix-protocols-2-million-exploit-quillaudits-92befc250e7c","name":"quillaudits.medium.com","type":"other","credibility":3},{"url":"https://cryptoslate.com/polygon-based-protocol-0vix-exploited-for-2m/","name":"cryptoslate.com","type":"other","credibility":3}],"severity":"medium"},{"content":"After extracting funds from the 0VIX protocol, the attacker moved stolen assets through a chain of obfuscation steps. Approximately $1.4 million in USDC and $600,000 in USDT were transferred via the Stargate Finance cross-chain bridge from Polygon to Ethereum mainnet, where the assets were converted to ETH. Approximately 1,069 ETH in total was reported moved through this path. The attacker subsequently deposited funds into Tornado Cash, with reports indicating approximately 520 ETH deposited initially and another 239 ETH transferred on the following day. The use of Tornado Cash effectively obfuscated on-chain traceability. As of reporting, no stolen funds were recovered.","heading":"Fund Movement and Laundering","sources":[{"url":"https://decrypt.co/138262/polygon-lending-protocol-0vix-pauses-protocol-exploit","name":"decrypt.co","type":"other","credibility":3},{"url":"https://medium.com/coinmonks/ovix-protocol-hack-wtf-happened-f8d9da0219a3","name":"medium.com","type":"other","credibility":3},{"url":"https://cryptodaily.co.uk/2023/04/0vix-protocol-drained-for-2m-in-oracle-manipulation-exploit-update","name":"cryptodaily.co.uk","type":"other","credibility":3}],"severity":"medium"},{"content":"Immediately following the exploit, the 0VIX team paused all markets on both Polygon PoS and Polygon zkEVM, halting oToken transfers, minting, and liquidations. The team published an on-chain message to the attacker offering $125,000 as a bug bounty if the remainder of the stolen funds were returned, and set a deadline of 8:00 AM UTC on May 1, 2023. The team stated that if funds were not returned by the deadline, they would initiate a formal law enforcement process and share investigative leads with authorities. The attacker did not respond to this offer. The protocol subsequently worked with security partners to assess the damage and develop a recovery plan, which included governance proposals (including 0IP-26 and 0IP-30) to recapitalize markets, refund users who had repaid loans post-pause, and slash protocol reserves.","heading":"Team Response and Bounty Negotiation","sources":[{"url":"https://www.binance.com/en/square/post/475417","name":"binance.com","type":"other","credibility":3},{"url":"https://cryptodaily.co.uk/2023/04/0vix-protocol-drained-for-2m-in-oracle-manipulation-exploit-update","name":"cryptodaily.co.uk","type":"other","credibility":3},{"url":"https://keomprotocol.medium.com/0vix-on-polygon-pos-has-resumed-operations-1229b8b53b1e","name":"keomprotocol.medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"In August 2023, 0VIX announced a full rebranding to Keom. The team cited two reasons: a request to avoid using the 0VIX name due to proximity to a pre-existing trademark, and a strategic shift in product direction following lessons learned from the Beta phase exploit. As part of the transition, a governance vote was held to merge the legacy 0VIX lending DApp with the new Keom protocol. By October 2023, 0VIX resumed full operations on Polygon PoS, with repayments and withdrawals restored. Keom announced plans to build AI-enhanced trading products leveraging zero-knowledge technology and to incorporate updated risk management practices. The domain 0vix.com was migrated to redirect to Keom.","heading":"Protocol Rebranding to Keom","sources":[{"url":"https://www.binance.com/en/square/post/2023-08-31-hacked-0vix-protocol-rebrands-as-keom-announces-governance-vote-on-dapp-merger-1063044","name":"binance.com","type":"other","credibility":3},{"url":"https://keomprotocol.medium.com/introducing-keom-the-rebrand-76845784c1fa","name":"keomprotocol.medium.com","type":"other","credibility":3},{"url":"https://keomprotocol.medium.com/0vix-on-polygon-pos-has-resumed-operations-1229b8b53b1e","name":"keomprotocol.medium.com","type":"other","credibility":3},{"url":"https://www.0vix.com/","name":"0vix.com","type":"other","credibility":3}],"severity":"medium"},{"content":"0VIX was audited by WatchPug in May 2022 prior to its mainnet launch. However, the critical vulnerability exploited in April 2023 was introduced later, when the vGHST market was listed on March 17, 2023, approximately six weeks before the exploit. The oracle design for that market was insufficiently hardened against price manipulation. This reflects a gap between initial audit coverage and subsequent protocol upgrades. The protocol's reliance on spot price oracles for newly listed tokens, rather than time-weighted average price (TWAP) oracles or multi-source aggregated oracles, is identified in post-mortems as the root cause. The exploit is classified as an oracle manipulation attack facilitated by flash loans, a well-documented attack vector in DeFi.","heading":"Security Audit History and Risk Factors","sources":[{"url":"https://assets.website-files.com/622a09bc809cd190f58b7b15/627a5d6eea14146296b3261b_0VIX_Audit_Report_by_WatchPug.pdf","name":"assets.website-files.com","type":"other","credibility":3},{"url":"https://quillaudits.medium.com/decoding-ovix-protocols-2-million-exploit-quillaudits-92befc250e7c","name":"quillaudits.medium.com","type":"other","credibility":3},{"url":"https://bitcoinist.com/ovix-protocol-suffers2-m-exploit/","name":"bitcoinist.com","type":"other","credibility":3}],"severity":"medium"},{"content":"At the time of the exploit, the protocol's TVL stood at approximately $6.4 million. Immediately following the attack, TVL dropped to approximately $1.4 million as users withdrew remaining assets. An additional approximately $280,000 in withdrawals occurred before the protocol was fully paused. Users whose funds were impacted were subject to governance-directed recovery measures. Those who repaid loans after the soft pause were refunded under 0IP-26. Protocol reserves were partially redistributed to affected users. Full repayment of all user losses was not reported; the recovery approach involved sharing remaining liquidity proportionally among affected depositors. ZachXBT, a prominent on-chain investigator, flagged the entity as part of broader coverage of DeFi exploits.","heading":"User Impact and Recovery","sources":[{"url":"https://decrypt.co/138262/polygon-lending-protocol-0vix-pauses-protocol-exploit","name":"decrypt.co","type":"other","credibility":3},{"url":"https://keomprotocol.medium.com/0vix-on-polygon-pos-has-resumed-operations-1229b8b53b1e","name":"keomprotocol.medium.com","type":"other","credibility":3},{"url":"https://www.web3isgoinggreat.com/?id=0vix-protocol-exploited-for-2-million","name":"web3isgoinggreat.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2022-05-09","event":"0VIX protocol smart contracts audited by WatchPug prior to mainnet launch.","source":""},{"date":"2023-03-17","event":"vGHST market listed on 0VIX with a price oracle that was later found vulnerable to manipulation.","source":""},{"date":"2023-04-28","event":"Flash loan oracle manipulation exploit executed against the vGHST market. Approximately $2 million in user funds stolen; net protocol liquidity impact reported at $4.33 million. 0VIX pauses all markets on Polygon PoS and zkEVM.","source":""},{"date":"2023-04-29","event":"Attacker bridges stolen funds from Polygon to Ethereum via Stargate Finance, converting assets to ETH and depositing approximately 520 ETH into Tornado Cash. An additional 239 ETH reportedly moved the following day.","source":""},{"date":"2023-04-29","event":"0VIX team issues on-chain message to attacker offering $125,000 bounty for return of remaining funds, with a May 1 deadline before law enforcement engagement.","source":""},{"date":"2023-05","event":"Bounty deadline passes with no response from attacker. 0VIX indicates intent to initiate law enforcement process.","source":"","date_original":"2023-05-01"},{"date":"2023-08-31","event":"0VIX Protocol announces rebrand to Keom and initiates governance vote on merging the 0VIX lending DApp with Keom.","source":""},{"date":"2023-10-27","event":"0VIX on Polygon PoS resumes full operations including repayments and withdrawals following governance-directed recapitalization measures.","source":""}],"sources_used":[{"url":"https://www.coindesk.com/business/2023/04/28/defi-protocol-0vix-loses-nearly-2m-in-flash-loan-exploit","name":"DeFi Protocol 0VIX Loses Nearly $2M in Flash-Loan Exploit — CoinDesk","type":"news_article","archive_url":"http://web.archive.org/web/20260720154127/https://www.coindesk.com/business/2023/04/28/defi-protocol-0vix-loses-nearly-2m-in-flash-loan-exploit","credibility":1,"archive_timestamp":"2026-07-20T15:41:27+00:00"},{"url":"https://decrypt.co/138262/polygon-lending-protocol-0vix-pauses-protocol-exploit","name":"Polygon Lending Protocol 0VIX Pauses Protocol After $2M Exploit — Decrypt","type":"news_article","archive_url":"http://web.archive.org/web/20260415070918/https://decrypt.co/138262/polygon-lending-protocol-0vix-pauses-protocol-exploit","credibility":2,"archive_timestamp":"2026-04-15T07:09:18+00:00"},{"url":"https://cryptodaily.co.uk/2023/04/0vix-protocol-drained-for-2m-in-oracle-manipulation-exploit-update","name":"0VIX Protocol Drained For $2m In Oracle Manipulation Exploit — Crypto Daily","type":"news_article","archive_url":"https://web.archive.org/web/20260725123332/https://cryptodaily.co.uk/2023/04/0vix-protocol-drained-for-2m-in-oracle-manipulation-exploit-update","credibility":2,"archive_timestamp":"2026-07-25T12:33:32+00:00"},{"url":"https://quillaudits.medium.com/decoding-ovix-protocols-2-million-exploit-quillaudits-92befc250e7c","name":"Decoding Ovix Protocol's $2 Million Exploit — QuillAudits","type":"research","archive_url":"http://web.archive.org/web/20251017174002/https://quillaudits.medium.com/decoding-ovix-protocols-2-million-exploit-quillaudits-92befc250e7c","credibility":2,"archive_timestamp":"2025-10-17T17:40:02+00:00"},{"url":"https://cryptoslate.com/polygon-based-protocol-0vix-exploited-for-2m/","name":"Polygon-based protocol 0vix exploited for $2M — CryptoSlate","type":"news_article","archive_url":"http://web.archive.org/web/20260210173711/https://cryptoslate.com/polygon-based-protocol-0vix-exploited-for-2m/","credibility":2,"archive_timestamp":"2026-02-10T17:37:11+00:00"},{"url":"https://www.web3isgoinggreat.com/?id=0vix-protocol-exploited-for-2-million","name":"0VIX Protocol exploited for $2 million — Web3 Is Going Great","type":"community_report","archive_url":"http://web.archive.org/web/20260414220644/https://www.web3isgoinggreat.com/?id=0vix-protocol-exploited-for-2-million","credibility":2,"archive_timestamp":"2026-04-14T22:06:44+00:00"},{"url":"https://medium.com/coinmonks/ovix-protocol-hack-wtf-happened-f8d9da0219a3","name":"Ovix Protocol Hack — WTF happened? — Coinmonks/Medium","type":"research","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://keomprotocol.medium.com/0vix-exploit-post-mortem-15c882dcf479","name":"0VIX Exploit Post-Mortem & Steps to Recovery — Keom/Medium","type":"official","archive_url":"http://web.archive.org/web/20251112014719/https://keomprotocol.medium.com/0vix-exploit-post-mortem-15c882dcf479","credibility":2,"archive_timestamp":"2025-11-12T01:47:19+00:00"},{"url":"https://www.binance.com/en/square/post/475417","name":"0VIX Will Enforce Legal Process for Hackers After May 1 — CoinCu/Binance Square","type":"news_article","archive_url":"https://web.archive.org/web/20260725123827/https://www.binance.com/en/square/post/475417","credibility":3,"archive_timestamp":"2026-07-25T12:38:27+00:00"},{"url":"https://www.binance.com/en/square/post/2023-08-31-hacked-0vix-protocol-rebrands-as-keom-announces-governance-vote-on-dapp-merger-1063044","name":"Hacked 0VIX Protocol Rebrands as Keom — Binance News","type":"news_article","archive_url":"https://web.archive.org/web/20260725123924/https://www.binance.com/en/square","credibility":2,"archive_timestamp":"2026-07-25T12:39:24+00:00"},{"url":"https://keomprotocol.medium.com/introducing-keom-the-rebrand-76845784c1fa","name":"Introducing Keom: The Rebrand — Keom/Medium","type":"official","archive_url":"http://web.archive.org/web/20251112023152/https://keomprotocol.medium.com/introducing-keom-the-rebrand-76845784c1fa","credibility":2,"archive_timestamp":"2025-11-12T02:31:52+00:00"},{"url":"https://keomprotocol.medium.com/0vix-on-polygon-pos-has-resumed-operations-1229b8b53b1e","name":"0VIX on Polygon PoS has Resumed Operations — Keom/Medium","type":"official","archive_url":"http://web.archive.org/web/20251112015556/https://keomprotocol.medium.com/0vix-on-polygon-pos-has-resumed-operations-1229b8b53b1e","credibility":2,"archive_timestamp":"2025-11-12T01:55:56+00:00"},{"url":"https://bitcoinist.com/ovix-protocol-suffers2-m-exploit/","name":"OVIX Protocol Falls Victim To $2 Million Oracle Exploit — Bitcoinist","type":"news_article","archive_url":"http://web.archive.org/web/20260316155158/https://bitcoinist.com/ovix-protocol-suffers2-m-exploit/","credibility":2,"archive_timestamp":"2026-03-16T15:51:58+00:00"},{"url":"https://assets.website-files.com/622a09bc809cd190f58b7b15/627a5d6eea14146296b3261b_0VIX_Audit_Report_by_WatchPug.pdf","name":"0VIX Protocol Audit Report by WatchPug (May 2022)","type":"research","archive_url":"http://web.archive.org/web/20260528021839/https://assets.website-files.com/622a09bc809cd190f58b7b15/627a5d6eea14146296b3261b_0VIX_Audit_Report_by_WatchPug.pdf","credibility":1,"archive_timestamp":"2026-05-28T02:18:39+00:00"},{"url":"https://defillama.com/protocol/0vix","name":"0vix TVL, Fees & Revenue — DefiLlama","type":"on_chain","archive_url":"http://web.archive.org/web/20250916232544/https://defillama.com/protocol/0vix","credibility":1,"archive_timestamp":"2025-09-16T23:25:44+00:00"},{"url":"https://www.0vix.com/","name":"KEOM Migrated — 0vix.com","type":"official","archive_url":"http://web.archive.org/web/20260513002906/http://www.0vix.com/","credibility":2,"archive_timestamp":"2026-05-13T00:29:06+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:42.410583+00:00","updated_at":"2026-08-29T01:34:40.333+00:00"}}