{"investigation":{"slug":"atlantis-loans","entity_name":"Atlantis Loans","trust_score":12,"severity_base":null,"score_modifier":0,"confidence":0.88,"status":"published","content_type":"investigation","summary":"Atlantis Loans was a decentralized lending and borrowing protocol built on BNB Chain (BSC) that was abandoned by its development team in April 2023 due to financial distress. Despite the abandonment, active smart contracts and unrevoked user approvals remained on-chain, which an attacker exploited in June 2023 through a malicious governance proposal, ultimately draining an estimated $2.5 million from users. The protocol is now defunct, its website is down, and its TVL has collapsed to near zero.","sections":[{"content":"Atlantis Loans operated as a decentralized money market protocol on BNB Smart Chain (BSC), enabling users to supply and borrow digital assets in a non-custodial environment. The protocol was algorithmically governed via the ATL utility token using a GovernorBravo-style governance system, which allowed token holders to submit and vote on proposals that could modify protocol parameters and upgrade contract implementations. The platform also deployed on Polygon and Avalanche. At its peak, the protocol held meaningful TVL across its supported chains. Atlantis Loans was functionally a fork of Compound Finance, using ABep20Delegator proxy contracts for each supported token market — a design pattern that later became central to the exploit. A PeckShield audit of the protocol was conducted and is on record, though the audit did not prevent the governance-layer attack that later occurred.","heading":"Protocol Overview","sources":[{"url":"https://defillama.com/protocol/atlantis-loans","name":"defillama.com","type":"other","credibility":3},{"url":"https://github.com/peckshield/publications/blob/master/audit_reports/PeckShield-Audit-Report-Atlantis-v1.0.pdf","name":"github.com","type":"other","credibility":3},{"url":"https://medium.com/@atlantisfinance/atlantis-official-ido-rush-rewards-40b6e4682269","name":"medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On April 1, 2023, the Atlantis Loans team published a message to their community on Medium announcing that the project would cease active development. The team cited approximately six to eight months of financial difficulties, describing pressure from the competitive DeFi landscape, the ongoing cost of asset security management, and the continuous need for protocol improvements. The announcement stated: 'The competitive landscape, continuous asset security management and the ongoing need for improvements have put a strain on our resources.' Because Atlantis Loans operated as a fully decentralized protocol, the team noted that any modifications or shutdowns would require passage through governance. The team promised to burn approximately 450,000 ATL tokens before July 2023 to relinquish control, and pledged to cover UI hosting costs through 2025 and open-source the front end. Notably, the team did not deactivate the smart contracts, pause the protocol, or urge users to revoke their token approvals — a critical oversight. Users experiencing withdrawal difficulties were directed to contact support@atlantis.loans.","heading":"Project Abandonment (April 2023)","sources":[{"url":"https://medium.com/@atlantisfinance/dear-atlantis-community-712307f91a7","name":"medium.com","type":"other","credibility":3},{"url":"https://www.web3isgoinggreat.com/?id=abandoned-atlantis-loans-project-exploited-for-1-1-million","name":"web3isgoinggreat.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On June 7, 2023, an unknown attacker submitted a malicious governance proposal (Proposal ID 52) through the GovernorBravo contract. The proposal was designed to set the admin of multiple ABep20Delegator contracts to attacker-controlled malicious contracts. Because the project had been abandoned and the community was no longer actively monitoring governance, the proposal passed without opposition after the mandatory 172,800-second (48-hour) timelock elapsed. On June 10, 2023, the attacker executed the proposal, granting themselves administrative control over the proxy contracts for all listed token markets. The attacker then replaced the ABep20Delegate implementation address with a backdoored contract, which included a function allowing the transfer of any user's tokens to an arbitrary address. Since there were no user deposits remaining in the protocol at the time, the attacker targeted users who had previously granted token approvals to Atlantis Loans contracts but had never revoked them. Security researchers identified the primary attacker address as 0xEADe071FF23bceF312deC938eCE29f7da62CF45b, the malicious governance contract as 0x027383c520c289cb5c4b66f8e0c8ca65d0769094, the backdoor implementation as 0x613cc544053812ab026d60361212cdb67b46f42f, and a funds-holding address as 0xd8e918824a560cd83a90d8e97ca19a54314d6f9f. The attacker was initially funded from Binance on Ethereum. An earlier attempt with Proposal ID 49, submitted on April 12, 2023, had failed to reach quorum. The June attack succeeded because community engagement had completely collapsed following the abandonment announcement.","heading":"Governance Attack and Exploit (June 2023)","sources":[{"url":"https://rekt.news/atlantis-loans-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-atlantis-loans-hack-june-2023","name":"halborn.com","type":"other","credibility":3},{"url":"https://medium.com/neptune-mutual/understanding-atlantis-loans-exploit-3716f7e765b4","name":"medium.com","type":"other","credibility":3},{"url":"https://blog.solidityscan.com/atlantis-loans-hack-analysis-7f3fb2e295e0","name":"blog.solidityscan.com","type":"other","credibility":3},{"url":"https://www.immunebytes.com/blog/atlantis-loans-hack-june-10-2023-detailed-hack-analysis/","name":"immunebytes.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Initial reports placed losses from the June 10, 2023 governance attack at approximately $1.1 million. Security firm PeckShield subsequently reported that the attacker continued operating the same method against users who had still not revoked their approvals in the days following the initial breach, pushing total losses above $2.5 million according to later estimates cited by Nefture Security and Revoke.cash. No user funds were held within the protocol itself at the time of the attack; all losses were extracted directly from the external wallets of users who had previously approved the Atlantis Loans contracts and failed to revoke those approvals after the project was abandoned. The attacker drained BEP-20 tokens across multiple markets. As of 2026, the protocol's total value locked stands at approximately $2,902 spread across residual Avalanche and Dogechain deployments, with zero TVL on BSC. DeFiLlama labels the protocol as having conducted a rug pull with the website down.","heading":"Financial Losses","sources":[{"url":"https://www.web3isgoinggreat.com/?id=abandoned-atlantis-loans-project-exploited-for-1-1-million","name":"web3isgoinggreat.com","type":"other","credibility":3},{"url":"https://medium.com/nefture/2-5m-lost-in-atlantis-loan-crypto-hack-an-avoidable-tragedy-c926d72fee8b","name":"medium.com","type":"other","credibility":3},{"url":"https://revoke.cash/exploits/atlantis-loans","name":"revoke.cash","type":"other","credibility":3},{"url":"https://defillama.com/protocol/atlantis-loans","name":"defillama.com","type":"other","credibility":3},{"url":"https://rekt.news/atlantis-loans-rekt","name":"rekt.news","type":"other","credibility":3}],"severity":"medium"},{"content":"Security researchers identified two compounding vulnerabilities. First, the GovernorBravo contract only verified the ETA (unlock time) parameter when queuing a proposal, lacking sufficient validation of the proposal's downstream effects on privileged contract roles. This permitted the attacker to queue a proposal that reassigned the admin role of every ABep20Delegator proxy to attacker-controlled contracts. Second, the ABep20Delegator pattern used by Atlantis Loans allowed the proxy admin to swap the underlying implementation contract, meaning that once the admin role was captured, the attacker could inject arbitrary logic into every token market simultaneously. The combination of an unmonitored governance system, an inattentive (effectively non-existent) community, no emergency pause mechanism, and millions of unrevoked ERC-20 approvals created conditions in which the attacker faced no practical resistance. Halborn's post-mortem noted that the hack was avoidable had users revoked approvals to the defunct contracts. The protocol's own abandonment announcement, which stated changes could only be made through governance, inadvertently served as a public roadmap for the attack vector.","heading":"Technical Root Cause Analysis","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-atlantis-loans-hack-june-2023","name":"halborn.com","type":"other","credibility":3},{"url":"https://medium.com/neptune-mutual/understanding-atlantis-loans-exploit-3716f7e765b4","name":"medium.com","type":"other","credibility":3},{"url":"https://blog.solidityscan.com/atlantis-loans-hack-analysis-7f3fb2e295e0","name":"blog.solidityscan.com","type":"other","credibility":3},{"url":"https://medium.com/@AMLBot/defi-vulnerabilities-atlantis-loans-hack-1545dfac22ae","name":"medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"During post-exploit on-chain analysis, researchers alleged a connection between the founder of Atlantis Loans and the original Venus Protocol deployer address on BSC. This alleged link was noted in an investigation published on Medium by d3ploy/Ron MH Ventures and raised questions about the relationship between the two protocols and their shared deployer history. Venus Protocol is one of the largest lending protocols on BNB Chain. The nature and significance of the alleged on-chain connection has not been publicly confirmed by Venus Protocol, and no formal regulatory action has been taken on this basis. The connection is treated as an allegation requiring further corroboration and is classified as low-to-medium confidence given that the primary source is a Tier 2 Medium publication rather than a court filing or regulatory document.","heading":"Venus Protocol Connection","sources":[{"url":"https://medium.com/d3ploy/atlantis-loans-exploit-defi-governance-vulnerabilities-the-connection-w-venus-protocol-af39721d9b1f","name":"medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Users who interacted with Atlantis Loans contracts at any point and did not revoke their token approvals remain exposed to further exploitation as long as those approvals persist on-chain. Revoke.cash published a dedicated exploit checker for Atlantis Loans allowing users to verify whether their addresses were affected and to revoke outstanding approvals. BeosinAlert and PeckShieldAlert both issued public warnings via social media following the initial attack. Security researchers broadly recommended that users of any DeFi protocol proactively revoke approvals when ceasing use of a platform, particularly when a project announces discontinuation. The Atlantis Loans incident has been cited as a canonical example of the risks posed by abandoned DeFi protocols with live governance systems.","heading":"User Risk and Remediation","sources":[{"url":"https://revoke.cash/exploits/atlantis-loans","name":"revoke.cash","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-atlantis-loans-hack-june-2023","name":"halborn.com","type":"other","credibility":3},{"url":"https://medium.com/neptune-mutual/understanding-atlantis-loans-exploit-3716f7e765b4","name":"medium.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2021","event":"Atlantis Loans launches as a decentralized lending protocol on BNB Smart Chain, modeled after Compound Finance.","source":"","date_original":"2021-01-01"},{"date":"2023-04","event":"Development team publishes abandonment announcement on Medium, citing 6-8 months of financial difficulty. Protocol smart contracts remain live and governance remains active.","source":"","date_original":"2023-04-01"},{"date":"2023-04-12","event":"First malicious governance proposal (Proposal ID 49) submitted by attacker. Proposal fails to reach quorum due to insufficient votes.","source":""},{"date":"2023-06-07","event":"Attacker submits second malicious governance proposal (Proposal ID 52) via GovernorBravo contract, targeting admin roles of all ABep20Delegator token contracts.","source":""},{"date":"2023-06-10","event":"Governance proposal executes after 48-hour timelock. Attacker takes admin control of proxy contracts, inserts backdoored implementation, and begins draining token approvals from user wallets. Initial losses estimated at approximately $1.1 million.","source":""},{"date":"2023-06-11","event":"Exploit discovered and reported publicly. BeosinAlert and PeckShieldAlert issue warnings. Revoke.cash deploys dedicated exploit checker for affected users.","source":""},{"date":"2023-06-12","event":"Attacker continues draining unrevoked approvals. PeckShield reports total losses exceeding $2.5 million. Web3 Is Going Great documents the incident.","source":""},{"date":"2023-06-13","event":"Rekt.news publishes post-mortem. Multiple security firms including Halborn, Neptune Mutual, Nefture Security, and SolidityScan publish detailed analyses.","source":""},{"date":"2023-07","event":"Team's deadline for burning 450,000 ATL tokens passes. Protocol website subsequently goes offline.","source":"","date_original":"2023-07-01"},{"date":"2026-05","event":"Protocol TVL stands at approximately $2,902. DeFiLlama marks the protocol as having rug pulled user funds with website down. No recovery or remediation has been undertaken.","source":"","date_original":"2026-05-01"}],"sources_used":[{"url":"https://defillama.com/protocol/atlantis-loans","name":"defillama.com","type":"other","archive_url":"http://web.archive.org/web/20250913011403/https://defillama.com/protocol/atlantis-loans","credibility":3,"archive_timestamp":"2025-09-13T01:14:03+00:00"},{"url":"https://github.com/peckshield/publications/blob/master/audit_reports/PeckShield-Audit-Report-Atlantis-v1.0.pdf","name":"github.com","type":"other","archive_url":"https://web.archive.org/web/20260829134217/https://github.com/peckshield/publications/blob/master/audit_reports/PeckShield-Audit-Report-Atlantis-v1.0.pdf","credibility":3,"archive_timestamp":"2026-08-29T13:42:17+00:00"},{"url":"https://medium.com/@atlantisfinance/atlantis-official-ido-rush-rewards-40b6e4682269","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://medium.com/@atlantisfinance/dear-atlantis-community-712307f91a7","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.web3isgoinggreat.com/?id=abandoned-atlantis-loans-project-exploited-for-1-1-million","name":"web3isgoinggreat.com","type":"other","archive_url":"http://web.archive.org/web/20251214143517/https://www.web3isgoinggreat.com/?id=abandoned-atlantis-loans-project-exploited-for-1-1-million","credibility":3,"archive_timestamp":"2025-12-14T14:35:17+00:00"},{"url":"https://rekt.news/atlantis-loans-rekt","name":"rekt.news","type":"other","archive_url":"http://web.archive.org/web/20260608202844/https://rekt.news/atlantis-loans-rekt","credibility":3,"archive_timestamp":"2026-06-08T20:28:44+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-atlantis-loans-hack-june-2023","name":"halborn.com","type":"other","archive_url":"http://web.archive.org/web/20260517001118/https://www.halborn.com/blog/post/explained-the-atlantis-loans-hack-june-2023","credibility":3,"archive_timestamp":"2026-05-17T00:11:18+00:00"},{"url":"https://medium.com/neptune-mutual/understanding-atlantis-loans-exploit-3716f7e765b4","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://blog.solidityscan.com/atlantis-loans-hack-analysis-7f3fb2e295e0","name":"blog.solidityscan.com","type":"other","archive_url":"https://web.archive.org/web/20260830040510/https://blog.solidityscan.com/atlantis-loans-hack-analysis-7f3fb2e295e0/","credibility":3,"archive_timestamp":"2026-08-30T04:05:10+00:00"},{"url":"https://www.immunebytes.com/blog/atlantis-loans-hack-june-10-2023-detailed-hack-analysis/","name":"immunebytes.com","type":"other","archive_url":"http://web.archive.org/web/20251215225654/https://immunebytes.com/blog/atlantis-loans-hack-june-10-2023-detailed-hack-analysis/","credibility":3,"archive_timestamp":"2025-12-15T22:56:54+00:00"},{"url":"https://medium.com/nefture/2-5m-lost-in-atlantis-loan-crypto-hack-an-avoidable-tragedy-c926d72fee8b","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://revoke.cash/exploits/atlantis-loans","name":"revoke.cash","type":"other","archive_url":"http://web.archive.org/web/20260314133346/https://revoke.cash/exploits/atlantis-loans","credibility":3,"archive_timestamp":"2026-03-14T13:33:46+00:00"},{"url":"https://medium.com/@AMLBot/defi-vulnerabilities-atlantis-loans-hack-1545dfac22ae","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://medium.com/d3ploy/atlantis-loans-exploit-defi-governance-vulnerabilities-the-connection-w-venus-protocol-af39721d9b1f","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:41.673667+00:00","updated_at":"2026-08-30T05:14:10.956837+00:00"}}