{"investigation":{"slug":"astrid-finance","entity_name":"Astrid Finance","trust_score":38,"severity_base":null,"score_modifier":0,"confidence":0.72,"status":"published","content_type":"investigation","summary":"Astrid Finance is an Ethereum-based liquid restaking protocol built on EigenLayer, allowing users to deposit liquid staking tokens (stETH, rETH, cbETH) in exchange for liquid restaked tokens. On October 28, 2023, the protocol suffered a smart contract exploit due to a missing input validation check in its withdraw function, resulting in the theft of approximately $228,000 in assets. The attacker eventually returned 80% of stolen funds after an on-chain negotiation and legal threat by the team; all affected users received refunds, and the vulnerable contracts remain paused pending re-audit.","sections":[{"content":"Astrid Finance is an Ethereum Mainnet liquid restaking protocol that operates on top of EigenLayer. Users deposit liquid staking tokens — specifically stETH (Lido), rETH (Rocket Pool), and cbETH (Coinbase) — and receive corresponding liquid restaked tokens (rstETH, rrETH, rcbETH) in return. The pooled LSTs are restaked on EigenLayer and delegated across multiple node operators selected through Astrid DAO governance. Rewards earned through restaking are automatically compounded and distributed via a balance rebase mechanism, meaning holders of liquid restaked tokens see their balances adjust proportionally over time. The protocol is distinct from AstridDAO, a separate Polkadot-ecosystem project with no known affiliation. Astrid Finance's testnet and mainnet were launched in 2023, with mainnet activity beginning shortly before the October 2023 exploit. Following the exploit the main contracts were paused; as of available reporting the protocol has not relaunched on mainnet.","heading":"Protocol Overview","sources":[{"url":"https://medium.com/neptune-mutual/understanding-the-astrid-finance-exploit-d8001a65b4f6","name":"medium.com","type":"other","credibility":3},{"url":"https://astridfinancial.wixsite.com/mysite","name":"astridfinancial.wixsite.com","type":"other","credibility":3},{"url":"https://testnet.astrid.finance/","name":"testnet.astrid.finance","type":"other","credibility":3}],"severity":"medium"},{"content":"On October 28, 2023, Astrid Finance was exploited on Ethereum Mainnet, resulting in the theft of approximately $228,000 in liquid staking tokens. The attacker address identified in post-mortem analysis is 0x792ec27874e1f614e757a1ae49d00ef5b2c73959, and the primary attack transaction hash is 0x8af9b5fb3e2e3df8659ffb2e0f0c1f4c90d5a80f4f6fccef143b823ce673fb60. Assets drained comprised approximately 64.17 stETH (worth roughly $114,757), 39.16 rETH (roughly $76,328), and 20.0004 cbETH (roughly $37,637), which the attacker subsequently converted into approximately 127.797 ETH with a combined value near $228,591 at the time. The root cause was a missing input validation check in the protocol's withdraw function. The function's parameters — specifically `_restakedTokenAddress` and `amount` — were left unvalidated, allowing the attacker to pass an arbitrary token contract address. The attacker deployed a fake ERC-20 token, minted it in large quantities, and supplied it to the withdraw function to drain the pool's allowances of legitimate LSTs. No flash loan or price oracle manipulation was involved; the attack was a straightforward input validation bypass.","heading":"October 2023 Smart Contract Exploit","sources":[{"url":"https://medium.com/neptune-mutual/understanding-the-astrid-finance-exploit-d8001a65b4f6","name":"medium.com","type":"other","credibility":3},{"url":"https://www.binance.com/en/square/post/2023-10-29-astrid-finance-suffers-exploit-after-auditors-recommended-fix-smart-contract-paused-and-full-refunds-promised-1541672","name":"binance.com","type":"other","credibility":3},{"url":"https://www.fxstreet.com/cryptocurrencies/news/what-happened-in-crypto-this-weekend-202310300652","name":"fxstreet.com","type":"other","credibility":3}],"severity":"medium"},{"content":"A significant aspect of the incident is the question of audit accountability. Shortly after the exploit was detected, Astrid Finance's initial public communications alleged that the vulnerability originated from a fix recommended by one of its auditing partners — implying the audit firm bore responsibility for introducing the flaw. Approximately one hour later, the team retracted that characterization and stated instead that the vulnerability had been 'missed' by both Astrid and its auditing team, framing it as a shared oversight rather than an auditor-introduced bug. The reversal raised questions about the team's crisis communication practices and the thoroughness of pre-deployment security review. Post-exploit, the team committed to requiring multiple independent audits before any future mainnet relaunch. The names of the specific auditing firms involved were not prominently disclosed in available public reporting at the time of this investigation.","heading":"Audit Accountability and Conflicting Statements","sources":[{"url":"https://www.binance.com/en/square/post/2023-10-29-astrid-finance-suffers-exploit-after-auditors-recommended-fix-smart-contract-paused-and-full-refunds-promised-1541672","name":"binance.com","type":"other","credibility":3},{"url":"https://www.fxstreet.com/cryptocurrencies/news/what-happened-in-crypto-this-weekend-202310300652","name":"fxstreet.com","type":"other","credibility":3},{"url":"https://medium.com/neptune-mutual/understanding-the-astrid-finance-exploit-d8001a65b4f6","name":"medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On October 29, 2023 — one day after the exploit — the Astrid Finance team sent an on-chain message to the attacker's wallet offering a 20% bounty in exchange for the return of the remaining 80% of stolen funds. The team set a deadline of October 31, 2023, at 8:00 am UTC, threatening to pursue legal action if funds were not returned by that time. The attacker complied ahead of the deadline, returning approximately 102 ETH (worth approximately $182,000 at the time) of the roughly 127 ETH stolen. The 20% retained by the attacker — approximately 25.6 ETH — constituted the informal white-hat bounty. Following fund recovery, the Astrid Finance team stated: 'As such we consider this as settled amicably.' The team then published a snapshot of all token holders at the time of the exploit to facilitate proportional user refunds, and subsequently confirmed that all user refunds had been processed. Remaining recovered funds were directed to a multisignature wallet designated for protocol re-auditing and smart contract redevelopment.","heading":"Hacker Negotiation and Fund Recovery","sources":[{"url":"https://www.fxstreet.com/cryptocurrencies/news/what-happened-in-crypto-this-weekend-202310300652","name":"fxstreet.com","type":"other","credibility":3},{"url":"https://business.outlookindia.com/cryptocurrency/standard-chartered-owned-crypto-platform-zodia-launched-in-hong-kong-astrid-finance-exploiter-returns-182k","name":"business.outlookindia.com","type":"other","credibility":3},{"url":"https://www.binance.com/en/square/post/2023-10-29-astrid-finance-suffers-exploit-after-auditors-recommended-fix-smart-contract-paused-and-full-refunds-promised-1541672","name":"binance.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Astrid Finance has been flagged by ZachXBT, the pseudonymous blockchain investigator known for documenting DeFi exploits and fund-flow tracing across the crypto ecosystem. The specific nature and content of ZachXBT's flag on Astrid Finance could not be independently verified through available public sources at the time of this investigation. ZachXBT's broader track record includes flagging projects post-exploit for ongoing risk, fund misuse, or incomplete remediation. The exploit itself — verified through multiple media reports and on-chain data — is consistent with the category of incidents ZachXBT routinely investigates and flags. Community discussion on social media platforms and forums has noted the audit failure as a reputational concern. These social-media-sourced signals are classified as low-confidence (Tier 3) absent further corroboration from primary sources. The protocol's contracts remain paused as of available reporting, which some community members interpret as an indicator the team has not fully committed to relaunching.","heading":"ZachXBT Flag and Community Risk Signals","sources":[{"url":"https://twitter.com/AstridFinance","name":"twitter.com","type":"other","credibility":3},{"url":"https://medium.com/neptune-mutual/understanding-the-astrid-finance-exploit-d8001a65b4f6","name":"medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the October 2023 exploit, Astrid Finance paused all vulnerable smart contracts and directed remaining recovered funds to a multisig wallet earmarked for auditing and redevelopment. The team publicly committed to obtaining multiple independent security audits before any future mainnet relaunch. As of available reporting through mid-2025, there is no confirmed evidence of a mainnet relaunch or public disclosure of new audit reports. The protocol's testnet (testnet.astrid.finance) remains accessible, but mainnet activity has been suspended. The absence of public updates from the team following the incident resolution — including no disclosed new audit engagements, no updated documentation, and no governance activity — represents an ongoing operational risk signal. Users seeking to interact with the protocol should exercise caution, as the mainnet contracts are paused and the path to relaunch remains unclear from publicly available information.","heading":"Protocol Status and Operational Risk","sources":[{"url":"https://testnet.astrid.finance/","name":"testnet.astrid.finance","type":"other","credibility":3},{"url":"https://www.fxstreet.com/cryptocurrencies/news/what-happened-in-crypto-this-weekend-202310300652","name":"fxstreet.com","type":"other","credibility":3},{"url":"https://github.com/astridfinance","name":"github.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The Astrid Finance exploit exemplifies a class of smart contract vulnerability categorized as missing input validation or improper access control. By failing to whitelist or otherwise constrain the token address parameter accepted by the withdraw function, the protocol allowed any caller to substitute a maliciously crafted ERC-20 contract for a legitimate LST. This type of vulnerability — while conceptually elementary — is frequently missed in audit processes when auditors assess business logic rather than rigorously enumerating all permissible parameter states. The exploit did not require external price data manipulation, flash loans, or governance attacks, making it low-complexity to execute once the vulnerability was identified. DeFi security researchers have noted that EigenLayer-adjacent protocols, particularly early liquid restaking implementations, face elevated smart contract risk due to the novelty of the restaking primitive and the compounded complexity of managing multiple LST types. The Astrid Finance incident is cited in post-mortem analyses as a case study in insufficient parameter validation in restaking pool contracts.","heading":"Technical Risk Profile","sources":[{"url":"https://medium.com/neptune-mutual/understanding-the-astrid-finance-exploit-d8001a65b4f6","name":"medium.com","type":"other","credibility":3},{"url":"https://www.binance.com/en/square/post/2023-10-29-astrid-finance-suffers-exploit-after-auditors-recommended-fix-smart-contract-paused-and-full-refunds-promised-1541672","name":"binance.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2023-10-28","event":"Astrid Finance exploited on Ethereum Mainnet via missing input validation in withdraw function; approximately $228,000 in stETH, rETH, and cbETH drained by attacker at address 0x792ec27874e1f614e757a1ae49d00ef5b2c73959.","source":""},{"date":"2023-10-28","event":"Astrid Finance team detects exploit, pauses vulnerable contracts, and takes a snapshot of all token holders to facilitate future refunds.","source":""},{"date":"2023-10-28","event":"Team initially states the vulnerability originated from an auditor-recommended fix; retracts the statement approximately one hour later, attributing the flaw to a mutual oversight by both the team and the auditing firm.","source":""},{"date":"2023-10-29","event":"Team sends on-chain message to attacker offering a 20% bounty (approximately 25.6 ETH) to return the remaining 80% of stolen funds; deadline set for October 31, 2023 at 8:00 am UTC with threat of legal action.","source":""},{"date":"2023-10-30","event":"Attacker returns approximately 102 ETH (roughly $182,000) — the 80% share — ahead of the deadline. Team states the matter is 'settled amicably.'","source":""},{"date":"2023-10-31","event":"Team publishes full list of affected depositors and their refund amounts; confirms all user refunds processed. Remaining recovered funds moved to multisig wallet for re-audit and redevelopment.","source":""},{"date":"2023-11","event":"Astrid Finance announces plan to undergo multiple independent smart contract audits before any future mainnet relaunch; contracts remain paused.","source":"","date_original":"2023-11-01"}],"sources_used":[{"url":"https://medium.com/neptune-mutual/understanding-the-astrid-finance-exploit-d8001a65b4f6","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://astridfinancial.wixsite.com/mysite","name":"astridfinancial.wixsite.com","type":"other","archive_url":"https://web.archive.org/web/20260830035556/https://astridfinancial.wixsite.com/mysite","credibility":3,"archive_timestamp":"2026-08-30T03:55:56+00:00"},{"url":"https://testnet.astrid.finance/","name":"testnet.astrid.finance","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://www.binance.com/en/square/post/2023-10-29-astrid-finance-suffers-exploit-after-auditors-recommended-fix-smart-contract-paused-and-full-refunds-promised-1541672","name":"binance.com","type":"other","archive_url":"https://web.archive.org/web/20260829144038/https://www.binance.com/en/square/post/2023-10-29-astrid-finance-suffers-exploit-after-auditors-recommended-fix-smart-contract-paused-and-full-refunds-promised-1541672","credibility":3,"archive_timestamp":"2026-08-29T14:40:38+00:00"},{"url":"https://www.fxstreet.com/cryptocurrencies/news/what-happened-in-crypto-this-weekend-202310300652","name":"fxstreet.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://business.outlookindia.com/cryptocurrency/standard-chartered-owned-crypto-platform-zodia-launched-in-hong-kong-astrid-finance-exploiter-returns-182k","name":"business.outlookindia.com","type":"other","archive_url":"https://web.archive.org/web/20260829233317/https://www.outlookmoney.com/invest/standard-chartered-owned-crypto-platform-zodia-launched-in-hong-kong-astrid-finance-exploiter-returns-182k","credibility":3,"archive_timestamp":"2026-08-29T23:33:17+00:00"},{"url":"https://twitter.com/AstridFinance","name":"twitter.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://github.com/astridfinance","name":"github.com","type":"other","archive_url":"https://web.archive.org/web/20260829134121/https://github.com/astridfinance","credibility":3,"archive_timestamp":"2026-08-29T13:41:21+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:37.636149+00:00","updated_at":"2026-08-30T05:14:09.388471+00:00"}}