{"investigation":{"slug":"cashio","entity_name":"Cashio","trust_score":5,"severity_base":null,"score_modifier":0,"confidence":1,"status":"published","content_type":"investigation","summary":"Cashio was a Solana-based algorithmic stablecoin protocol that issued the CASH token, collateralized by Saber LP tokens. On March 23, 2022, an attacker exploited a critical missing validation flaw in the smart contract to mint approximately 2 billion CASH tokens backed by worthless fake collateral, draining roughly $52 million in real assets and permanently destroying the token's USD peg. The protocol was unaudited, never compensated victims in full, and its pseudonymous creator later admitted the code was rushed and insecure.","sections":[{"content":"Cashio was a decentralized stablecoin application built on the Solana blockchain, developed under the pseudonym '0xGhostchain.' The protocol allowed users to deposit Saber USD liquidity provider (LP) tokens as collateral in exchange for minting $CASH, a US dollar-pegged stablecoin. Collateral was routed through the Arrow Protocol, a Solana-based yield-bearing token wrapper, and held in Saber liquidity pools containing stablecoin pairs such as USDC-USDT. The design was intended to maintain the $CASH peg through the value of the underlying LP token collateral. Cashio launched on Solana mainnet and, prior to the March 2022 exploit, held approximately $28–52 million in total value locked (TVL). The protocol was never subjected to a third-party smart contract security audit.","heading":"Protocol Overview","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-cashio-hack-march-2022","name":"Explained: The Cashio Hack (March 2022) - Halborn","type":"research","credibility":2},{"url":"https://ackee.xyz/blog/2022-solana-hacks-explained-cashio/","name":"2022 Solana Hacks Explained: Cashio - Ackee Blockchain","type":"research","credibility":2},{"url":"https://www.certik.com/resources/blog/3bHgCDnWaqUeQJn6695bea-cashio-app-incident-analysis","name":"Cashio App Incident Analysis - CertiK","type":"research","credibility":2}],"severity":"high"},{"content":"At approximately 08:15 UTC on March 23, 2022, an unknown attacker began exploiting Cashio's minter contract. The exploit was made possible by two missing validation checks in the collateral deposit logic. First, the contract validated that the token type matched the saber_swap.arrow account, but critically did not validate the .mint field within that account. Second, the depositor_source parameter was never verified to ensure consistency with collateral requirements. These two omissions allowed the attacker to construct a chain of entirely fake accounts — a counterfeit Arrow protocol account, a fake Saber LP token, and a fraudulent collateral vault — that passed all existing checks because each fraudulent account was only compared against the other fraudulent accounts in the chain rather than any legitimate contract reference. The attacker interacted with the Arrow program's deposit_vendor() function to deposit 2,000,000,000 counterfeit LP tokens and used these to mint an equal quantity of $CASH tokens. These unbacked tokens were then swapped for legitimate stablecoins across Cashio's liquidity pools: the attacker obtained approximately $16.4 million in USDC and $10.8 million in USDT via LP token redemptions, and an additional $17 million in USDC and $8.6 million in UST through secondary swaps — totaling approximately $52 million in stolen assets. The $CASH token's price collapsed from $1.00 to $0.00005 within hours, effectively wiping out all liquidity providers. Cashio developer 0xGhostchain issued a public warning on Twitter at 09:59 UTC — roughly 1 hour and 44 minutes after the attack began — urging users not to mint $CASH and to withdraw funds from pools.","heading":"The Exploit (March 23, 2022)","sources":[{"url":"https://www.coindesk.com/tech/2022/03/23/stablecoin-cashio-suffers-infinite-glitch-exploit-tvl-drops-by-28m","name":"Stablecoin Cashio Suffers 'Infinite Glitch' Exploit - CoinDesk","type":"news_article","credibility":1},{"url":"https://www.theblock.co/post/138934/stablecoin-cashio-on-solana-exploited-for-28-million-in-infinite-mint-glitch","name":"Stablecoin Cashio on Solana exploited for $52.8 million - The Block","type":"news_article","credibility":1},{"url":"https://rekt.news/cashio-rekt","name":"Cashio - REKT","type":"research","credibility":2},{"url":"https://www.halborn.com/blog/post/explained-the-cashio-hack-march-2022","name":"Explained: The Cashio Hack (March 2022) - Halborn","type":"research","credibility":2}],"severity":"critical"},{"content":"The attack exploited Solana's account-based programming model, in which programs must explicitly validate the legitimacy of accounts passed as input. Cashio's minter contract performed numerous validation checks but was missing two critical ones. The contract's crate_collateral_tokens function confirmed that token types matched the saber_swap.arrow account, but omitted any check on the .mint field of that account. This meant an attacker could supply a self-referential chain of counterfeit accounts: (1) a fake bank initialized with a worthless token mint; (2) a fake Arrow protocol account (saber_swap.arrow) pointing to the fake bank; (3) a fake Saber LP token; and (4) a counterfeit Sunny/Saber vault. Because each fake account only needed to be internally consistent with the other fake accounts — not with any on-chain program-derived address or legitimate reference — all validation checks passed. The attacker called deposit_vendor() on the Arrow program with 2 billion fake LP tokens, receiving 2 billion fake collateral tokens in return. These fake collateral tokens were then passed to the print_cash instruction, which minted 2 billion real $CASH tokens. The attacker then used those real $CASH tokens to drain the genuine USDC and USDT in Cashio's Saber liquidity pools. The root cause was the absence of a verification that the bank's token and the ultimately minted CASH token were related to a legitimate, program-derived collateral chain — a check that an independent security audit would likely have identified.","heading":"Technical Breakdown: Fake Account Chain","sources":[{"url":"https://www.certik.com/resources/blog/3bHgCDnWaqUeQJn6695bea-cashio-app-incident-analysis","name":"Cashio App Incident Analysis - CertiK","type":"research","credibility":2},{"url":"https://ackee.xyz/blog/2022-solana-hacks-explained-cashio/","name":"2022 Solana Hacks Explained: Cashio - Ackee Blockchain","type":"research","credibility":2},{"url":"https://www.halborn.com/blog/post/explained-the-cashio-hack-march-2022","name":"Explained: The Cashio Hack (March 2022) - Halborn","type":"research","credibility":2},{"url":"https://www.quadrigainitiative.com/casestudy/cashioappsolanafakeaccountexploit.php","name":"Mar 2022 - Cashio App Solana Fake Account Exploit - Quadriga Initiative","type":"research","credibility":2}],"severity":"critical"},{"content":"The exploit resulted in the theft of approximately $52 million in stablecoins. The attacker obtained roughly $16.4 million in USDC and $10.8 million in USDT from LP token swaps on Saber, and an additional $17 million in USDC and $8.6 million in UST from secondary swaps. The $CASH token depegged instantly, falling from $1.00 to $0.00005 — a near-total loss for all holders. Cashio's total value locked (TVL) dropped from approximately $28–29 million to under $600,000 within hours of the attack. All liquidity providers who had deposited stablecoins into Cashio's Saber pools were effectively wiped out. Roughly $25 million of the stolen funds remained unrecovered as of mid-2022, per CertiK's incident analysis. The protocol never resumed operations after the exploit.","heading":"Scale of Damage","sources":[{"url":"https://decrypt.co/95772/solana-stablecoin-project-cashio-plummets-zero-multi-million-dollar-hack","name":"Solana Stablecoin Project Cashio Plummets to Zero After Hack - Decrypt","type":"news_article","credibility":2},{"url":"https://www.certik.com/resources/blog/3bHgCDnWaqUeQJn6695bea-cashio-app-incident-analysis","name":"Cashio App Incident Analysis - CertiK","type":"research","credibility":2},{"url":"https://www.vidma.io/blog/the-cashio-hack-lessons-from-a-48-million-defi-exploit","name":"The Cashio Hack: Lessons from a $48 Million DeFi Exploit - Vidma","type":"research","credibility":2}],"severity":"critical"},{"content":"After draining the Cashio liquidity pools on Solana, the attacker bridged the stolen stablecoins to Ethereum using Jupiter (a Solana liquidity aggregator) and the Wormhole cross-chain bridge. Approximately $15.3 million in USDC and USDT were moved from Solana to Ethereum in three transactions. Once on Ethereum, the attacker converted the stablecoins to Ether (ETH), ultimately accumulating over 16,000 ETH. According to on-chain data from Etherscan, the attacker subsequently transferred 1,610 ETH to an Ethereum mixer service across 17 transactions — all but one consisting of 100 ETH each — in an alleged effort to obscure the funds' origin and destination. The majority of the approximately $52 million in stolen funds was never returned or recovered.","heading":"Fund Movement and Alleged Laundering","sources":[{"url":"https://rekt.news/cashio-rekt","name":"Cashio - REKT","type":"research","credibility":2},{"url":"https://finance.yahoo.com/news/solana-cashio-hack-loots-52-165359406.html","name":"Solana Cashio Hack Loots $52.8M - Yahoo Finance","type":"news_article","credibility":2},{"url":"https://ambcrypto.com/decoding-the-if-but-and-so-of-cashio-hack/","name":"Decoding the if, but, and so of Cashio Hack - AMBCrypto","type":"news_article","credibility":2}],"severity":"critical"},{"content":"Approximately three hours after the exploit began, the attacker embedded a message in the input data of an Ethereum transaction stating: 'Account with less 100k have been returned. all other money will be donated to charity.' On-chain records showed hundreds of small USDC transactions distributed to addresses that had lost less than $100,000 in the attack, consistent with the attacker's stated intention. In a subsequent message sent on approximately March 28, 2022, the attacker announced a further change of stance: victims who had lost more than $100,000 would also have the opportunity to receive a refund by submitting an application. The message stated: 'The inntention [sic] was only to take money from those who do not need it, not from those who do.' It is unclear from available sources how much was actually returned to larger claimants or whether any charitable donations were made. The attacker was never publicly identified, and no arrests or criminal charges related to the Cashio hack have been reported as of the time of this investigation.","heading":"The Attacker's On-Chain Messages and Alleged Partial Returns","sources":[{"url":"https://www.web3isgoinggreat.com/?id=robin-hood-esque-attacker-steals-52-million-from-cashio-then-returns-smaller-amounts-and-pledges-to-donate-the-rest-to-charity","name":"Robin Hood-esque attacker steals $52M from Cashio - Web3 Is Going Great","type":"news_article","credibility":2},{"url":"https://fortune.com/2022/03/25/crypto-robin-hood-stole-50-million-hacker-heist-cashio/","name":"Crypto Robin Hood stole $50 million and says he'll donate to charity - Fortune","type":"news_article","credibility":2},{"url":"https://beincrypto.com/cashio-hacker-asks-affected-users-to-state-their-case-if-they-want-their-funds-returned/","name":"Cashio Hacker Asks Affected Users to State Their Case - BeInCrypto","type":"news_article","credibility":2},{"url":"https://fortune.com/2022/03/31/crypto-robin-hood-50-million-theft-apply-and-get-a-refund-hacker-cashio/","name":"Crypto hacker says victims can get their money back if they plead their case - Fortune","type":"news_article","credibility":2}],"severity":"high"},{"content":"The Cashio protocol was developed pseudonymously under the handle '0xGhostchain.' Following the exploit, 0xGhostchain posted on Twitter warning users not to mint any $CASH, stating that the team was investigating the root cause and urging liquidity providers to withdraw their funds from pools. The developer indicated that a postmortem would be published. A post-incident statement regarding the impact on Saber and its users was published on or around March 28, 2022. The Cashio protocol did not resume normal operations following the exploit. No formal recovery or relaunch plan was executed, and the protocol is considered permanently collapsed.","heading":"Developer Response","sources":[{"url":"https://solananewstoday.com/2022/03/28/the-cashio-vulnerability-against-saber-and-our-users-what-happened-and-what-we-are-doing-about-it/","name":"The Cashio Vulnerability Against Saber and Our Users - Solana News Today","type":"other","credibility":3},{"url":"https://decrypt.co/95772/solana-stablecoin-project-cashio-plummets-zero-multi-million-dollar-hack","name":"Solana Stablecoin Project Cashio Plummets to Zero After Hack - Decrypt","type":"news_article","credibility":2},{"url":"https://www.theblock.co/post/138934/stablecoin-cashio-on-solana-exploited-for-28-million-in-infinite-mint-glitch","name":"Stablecoin Cashio on Solana exploited for $52.8 million - The Block","type":"news_article","credibility":1}],"severity":"high"},{"content":"Cashio was deeply integrated with Saber, a Solana-based stablecoin automated market maker (AMM), and Sunny Aggregator, a yield optimization layer built on top of Saber. $CASH was minted against Saber USD LP tokens, meaning the exploit directly drained Saber's USDC-USDT and other liquidity pools. Both Saber and Sunny Aggregator were built by Ian Macalinao (also known as 'iMac' or 'Surya Khosla') and his brother Dylan Macalinao of Saber Labs. A CoinDesk investigation published in August 2022 revealed that Ian Macalinao had secretly built Cashio, along with more than a dozen other protocols in the Saber ecosystem, using 11 different pseudonymous developer identities — including 'kiwipepper' (Crate), 'oliver_code' (Arrow), and 'Larry Jarry' (Quarry). These interlocking protocols were designed so that a single dollar of collateral would be counted multiple times across each protocol layer, artificially inflating Solana's reported TVL. At peak, Saber and Sunny together accounted for approximately $7.5 billion of Solana's $10.5 billion TVL, much of which was the result of this double- and triple-counting scheme.","heading":"Saber and Sunny Aggregator Connection","sources":[{"url":"https://www.coindesk.com/layer2/2022/08/04/master-of-anons-how-a-crypto-developer-faked-a-defi-ecosystem","name":"Master of Anons: How a Crypto Developer Faked a DeFi Ecosystem - CoinDesk","type":"news_article","credibility":1},{"url":"https://cryptoslate.com/defi-sybil-attack-created-7-5b-fake-tvl-on-solana-from-anon-developers/","name":"DeFi Sybil attack created $7.5B fake TVL on Solana - CryptoSlate","type":"news_article","credibility":2},{"url":"https://www.business2community.com/crypto-news/ian-macalinao-inflates-solana-tvl-by-creating-11-fake-developer-personas-02532693","name":"Ian Macalinao Inflates Solana TVL by Creating 11 Fake Developer Personas - Business2Community","type":"news_article","credibility":2}],"severity":"high"},{"content":"CoinDesk's August 2022 investigation revealed that Ian Macalinao operated at least 11 pseudonymous developer identities to build an interlocking web of Solana DeFi protocols that each used the outputs of the prior one as inputs — inflating TVL metrics by counting the same underlying dollar multiple times. Ian wrote in a then-unpublished blog post: 'I devised a scheme to maximize Solana's TVL: I would build protocols that stack on top of each other, such that a dollar could be counted several times.' Among the projects secretly attributed to Ian were Cashio (via pseudonymous contributions), Arrow Protocol, Crate, and Quarry, in addition to Saber and Sunny. In January 2023, CoinDesk reported that the U.S. Department of Justice had opened an investigation into Ian and Dylan Macalinao in connection with these Solana-based DeFi and stablecoin projects, including Cashio. The DOJ was reported to be seeking information on the web of projects that orbited Saber. The Macalinao brothers subsequently withdrew from Protagonist VC, the crypto venture-capital firm they had co-founded, and transferred control of some pseudonymously built protocols to Marinade, another Solana DeFi protocol. No charges had been publicly filed as of the time of this investigation.","heading":"Ian Macalinao Pseudonym Scandal and DOJ Investigation","sources":[{"url":"https://www.coindesk.com/business/2023/01/11/doj-said-to-probe-saber-labs-founders-over-solana-based-defi-stablecoin-projects","name":"Justice Department Probing Saber Labs Founders Over Solana-Based Projects - CoinDesk","type":"regulatory","credibility":1},{"url":"https://www.coindesk.com/layer2/2022/08/04/master-of-anons-how-a-crypto-developer-faked-a-defi-ecosystem","name":"Master of Anons: How a Crypto Developer Faked a DeFi Ecosystem - CoinDesk","type":"news_article","credibility":1},{"url":"https://www.web3isgoinggreat.com/?id=ian-macalinao-pseudonyms","name":"Ian Macalinao Revealed to Have Pumped Solana TVL - Web3 Is Going Great","type":"news_article","credibility":2},{"url":"https://www.tronweekly.com/brothers-behind-solana-saber-doj-investigation/","name":"Brothers Behind Solana Saber Labs Under DOJ Investigation - Tron Weekly","type":"news_article","credibility":2}],"severity":"high"},{"content":"The Cashio exploit occurred during a period of broader stress for Solana's DeFi ecosystem, and contributed to eroding confidence in Solana-native protocols. The revelation that Saber's TVL had been artificially inflated through double-counting across Ian Macalinao's pseudonymous protocol stack — with Cashio itself being one node in that stack — raised systemic concerns about the reliability of Solana TVL figures and the ecosystem's apparent depth. The exploit also highlighted the specific risks of unaudited smart contracts on Solana, where account validation must be performed manually by developers rather than enforced at the runtime level. Multiple security researchers cited the Cashio hack as a reference case for the importance of input account validation in Solana programs. The incident contributed to a broader reassessment of Solana DeFi's actual health during 2022, a year that also saw FTX's collapse further damage confidence in the Solana ecosystem.","heading":"Impact on Solana DeFi","sources":[{"url":"https://ackee.xyz/blog/2022-solana-hacks-explained-cashio/","name":"2022 Solana Hacks Explained: Cashio - Ackee Blockchain","type":"research","credibility":2},{"url":"https://www.vidma.io/blog/the-cashio-hack-lessons-from-a-48-million-defi-exploit","name":"The Cashio Hack: Lessons from a $48 Million DeFi Exploit - Vidma","type":"research","credibility":2},{"url":"https://beincrypto.com/top-ten-defi-hacks-2022-hackers-daring/","name":"Top Ten DeFi Hacks of 2022 - BeInCrypto","type":"news_article","credibility":2}],"severity":"medium"},{"content":"Several pre-existing red flags were present before the Cashio exploit occurred. The protocol was never independently audited — a critical omission for a stablecoin protocol holding tens of millions of dollars. The protocol's collateral validation logic was incomplete, failing to verify the .mint field of Arrow accounts or to confirm that the depositor_source was consistent with legitimate collateral. The protocol was pseudonymously developed with no public team identity beyond '0xGhostchain.' After the exploit, the broader context revealed that Cashio was embedded in an ecosystem of interlocking protocols built by a single developer using multiple false identities — a fact not publicly known at the time of the exploit. The lack of transparency about the protocol's authorship, the absence of an audit, and the reliance on a complex multi-protocol collateral chain (Saber LP tokens routed through Arrow) all represented material risks that users could not fully assess. The exploit is widely cited in Solana security literature as a canonical example of account validation failures in Anchor-based Solana programs.","heading":"Red Flags and Security Lessons","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-cashio-hack-march-2022","name":"Explained: The Cashio Hack (March 2022) - Halborn","type":"research","credibility":2},{"url":"https://www.certik.com/resources/blog/3bHgCDnWaqUeQJn6695bea-cashio-app-incident-analysis","name":"Cashio App Incident Analysis - CertiK","type":"research","credibility":2},{"url":"https://ackee.xyz/blog/2022-solana-hacks-explained-cashio/","name":"2022 Solana Hacks Explained: Cashio - Ackee Blockchain","type":"research","credibility":2}],"severity":"high"}],"timeline":[{"date":"2021-11-23","event":"Ian Macalinao, operating as 0xGhostchain, tells the Cashio Discord community 'I personally audited it,' a claim he later contradicts.","source":""},{"date":"2021-11","event":"Cashio is launched on Solana, built by Ian Macalinao under the pseudonym 0xGhostchain, as part of an ecosystem of protocols around the Saber DEX. The code was reportedly rushed to meet a Breakpoint conference deadline.","source":"","date_original":"2021-11-01"},{"date":"2022-03-23","event":"Attacker exploits a missing collateral validation flaw in Cashio's smart contract at approximately 8:23 AM UTC, minting ~2 billion CASH tokens backed by worthless fake collateral and draining approximately $52 million in real assets. CASH token collapses to near zero.","source":""},{"date":"2022-03-23","event":"Attacker embeds on-chain message: 'Account with less 100k have been returned. all other money will be donated to charity.' Saber pauses withdrawals to Cashio pools and freezes smart contracts.","source":""},{"date":"2022-03-23","event":"Ian Macalinao publicly acknowledges 'I did not audit Cashio as carefully as I should have,' contradicting prior claims.","source":""},{"date":"2022-03-26","event":"Ian Macalinao writes (in an unpublished blog post) that Cashio's code was insecure because it was 'rushed for this deadline' and pledges to repay affected users from personal token holdings — a promise he does not fulfill.","source":""},{"date":"2022-03-28","event":"Attacker posts second message stating intention was to redistribute wealth and invites victims with over $100,000 in losses to apply for refunds. Saber team states they cannot compensate depositors.","source":""},{"date":"2022-03-31","event":"Attacker opens a refund application process requiring victims to explain why they need their money back; large accounts held by wealthy individuals are excluded from consideration.","source":""},{"date":"2022-06","event":"Cashio announces plans on Medium for a new protocol to help victims; approximately $25 million in stolen funds remain unrecovered. Team goes silent on social media.","source":"","date_original":"2022-06-01"},{"date":"2022-08-04","event":"CoinDesk publishes 'Master of Anons,' revealing that Ian and Dylan Macalinao operated 11 fake developer identities to inflate Solana DeFi TVL, with Cashio (via 0xGhostchain) being one of those projects.","source":""}],"sources_used":[{"url":"https://www.halborn.com/blog/post/explained-the-cashio-hack-march-2022","name":"Explained: The Cashio Hack (March 2022) - Halborn","type":"research","archive_url":"http://web.archive.org/web/20251216063128/https://www.halborn.com/blog/post/explained-the-cashio-hack-march-2022","credibility":2,"archive_timestamp":"2025-12-16T06:31:28+00:00"},{"url":"https://ackee.xyz/blog/2022-solana-hacks-explained-cashio/","name":"2022 Solana Hacks Explained: Cashio - Ackee Blockchain","type":"research","archive_url":"https://web.archive.org/web/20260829001352/https://ackee.xyz/blog/2022-solana-hacks-explained-cashio/","credibility":2,"archive_timestamp":"2026-08-29T00:13:52+00:00"},{"url":"https://www.certik.com/resources/blog/3bHgCDnWaqUeQJn6695bea-cashio-app-incident-analysis","name":"Cashio App Incident Analysis - CertiK","type":"research","archive_url":"https://web.archive.org/web/20260829001722/https://www.certik.com/blog/3bHgCDnWaqUeQJn6695bea-cashio-app-incident-analysis","credibility":2,"archive_timestamp":"2026-08-29T00:17:22+00:00"},{"url":"https://www.coindesk.com/tech/2022/03/23/stablecoin-cashio-suffers-infinite-glitch-exploit-tvl-drops-by-28m","name":"Stablecoin Cashio Suffers 'Infinite Glitch' Exploit - CoinDesk","type":"news_article","archive_url":"http://web.archive.org/web/20251118193956/https://www.coindesk.com/tech/2022/03/23/stablecoin-cashio-suffers-infinite-glitch-exploit-tvl-drops-by-28m","credibility":1,"archive_timestamp":"2025-11-18T19:39:56+00:00"},{"url":"https://www.theblock.co/post/138934/stablecoin-cashio-on-solana-exploited-for-28-million-in-infinite-mint-glitch","name":"Stablecoin Cashio on Solana exploited for $52.8 million - The Block","type":"news_article","archive_url":null,"credibility":1,"archive_timestamp":null},{"url":"https://rekt.news/cashio-rekt","name":"Cashio - REKT","type":"research","archive_url":"http://web.archive.org/web/20260608205756/https://rekt.news/cashio-rekt","credibility":2,"archive_timestamp":"2026-06-08T20:57:56+00:00"},{"url":"https://www.quadrigainitiative.com/casestudy/cashioappsolanafakeaccountexploit.php","name":"Mar 2022 - Cashio App Solana Fake Account Exploit - Quadriga Initiative","type":"research","archive_url":"https://web.archive.org/web/20260830010114/https://www.quadrigainitiative.com/casestudy/cashioappsolanafakeaccountexploit.php","credibility":2,"archive_timestamp":"2026-08-30T01:01:14+00:00"},{"url":"https://decrypt.co/95772/solana-stablecoin-project-cashio-plummets-zero-multi-million-dollar-hack","name":"Solana Stablecoin Project Cashio Plummets to Zero After Hack - Decrypt","type":"news_article","archive_url":"http://web.archive.org/web/20260414033634/https://decrypt.co/95772/solana-stablecoin-project-cashio-plummets-zero-multi-million-dollar-hack","credibility":2,"archive_timestamp":"2026-04-14T03:36:34+00:00"},{"url":"https://www.vidma.io/blog/the-cashio-hack-lessons-from-a-48-million-defi-exploit","name":"The Cashio Hack: Lessons from a $48 Million DeFi Exploit - Vidma","type":"research","archive_url":"http://web.archive.org/web/20260211063124/https://www.vidma.io/blog/the-cashio-hack-lessons-from-a-48-million-defi-exploit","credibility":2,"archive_timestamp":"2026-02-11T06:31:24+00:00"},{"url":"https://finance.yahoo.com/news/solana-cashio-hack-loots-52-165359406.html","name":"Solana Cashio Hack Loots $52.8M - Yahoo Finance","type":"news_article","archive_url":"http://web.archive.org/web/20260227014314/https://finance.yahoo.com/news/solana-cashio-hack-loots-52-165359406.html","credibility":2,"archive_timestamp":"2026-02-27T01:43:14+00:00"},{"url":"https://ambcrypto.com/decoding-the-if-but-and-so-of-cashio-hack/","name":"Decoding the if, but, and so of Cashio Hack - AMBCrypto","type":"news_article","archive_url":"http://web.archive.org/web/20260829001443/https://ambcrypto.com/decoding-the-if-but-and-so-of-cashio-hack/","credibility":2,"archive_timestamp":"2026-08-29T00:14:43+00:00"},{"url":"https://www.web3isgoinggreat.com/?id=robin-hood-esque-attacker-steals-52-million-from-cashio-then-returns-smaller-amounts-and-pledges-to-donate-the-rest-to-charity","name":"Robin Hood-esque attacker steals $52M from Cashio - Web3 Is Going Great","type":"news_article","archive_url":"http://web.archive.org/web/20251210150619/https://www.web3isgoinggreat.com/?id=robin-hood-esque-attacker-steals-52-million-from-cashio-then-returns-smaller-amounts-and-pledges-to-donate-the-rest-to-charity","credibility":2,"archive_timestamp":"2025-12-10T15:06:19+00:00"},{"url":"https://fortune.com/2022/03/25/crypto-robin-hood-stole-50-million-hacker-heist-cashio/","name":"Crypto Robin Hood stole $50 million and says he'll donate to charity - Fortune","type":"news_article","archive_url":"https://web.archive.org/web/20260829001427/https://fortune.com/2022/03/25/crypto-robin-hood-stole-50-million-hacker-heist-cashio/","credibility":2,"archive_timestamp":"2026-08-29T00:14:27+00:00"},{"url":"https://beincrypto.com/cashio-hacker-asks-affected-users-to-state-their-case-if-they-want-their-funds-returned/","name":"Cashio Hacker Asks Affected Users to State Their Case - BeInCrypto","type":"news_article","archive_url":null,"credibility":2,"archive_timestamp":null},{"url":"https://fortune.com/2022/03/31/crypto-robin-hood-50-million-theft-apply-and-get-a-refund-hacker-cashio/","name":"Crypto hacker says victims can get their money back if they plead their case - Fortune","type":"news_article","archive_url":"https://web.archive.org/web/20260829133553/https://fortune.com/2022/03/31/crypto-robin-hood-50-million-theft-apply-and-get-a-refund-hacker-cashio/","credibility":2,"archive_timestamp":"2026-08-29T13:35:53+00:00"},{"url":"https://solananewstoday.com/2022/03/28/the-cashio-vulnerability-against-saber-and-our-users-what-happened-and-what-we-are-doing-about-it/","name":"The Cashio Vulnerability Against Saber and Our Users - Solana News Today","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-job","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.coindesk.com/layer2/2022/08/04/master-of-anons-how-a-crypto-developer-faked-a-defi-ecosystem","name":"Master of Anons: How a Crypto Developer Faked a DeFi Ecosystem - CoinDesk","type":"news_article","archive_url":"http://web.archive.org/web/20251113151511/https://www.coindesk.com/layer2/2022/08/04/master-of-anons-how-a-crypto-developer-faked-a-defi-ecosystem","credibility":1,"archive_timestamp":"2025-11-13T15:15:11+00:00"},{"url":"https://cryptoslate.com/defi-sybil-attack-created-7-5b-fake-tvl-on-solana-from-anon-developers/","name":"DeFi Sybil attack created $7.5B fake TVL on Solana - CryptoSlate","type":"news_article","archive_url":"http://web.archive.org/web/20260227105350/https://cryptoslate.com/defi-sybil-attack-created-7-5b-fake-tvl-on-solana-from-anon-developers/","credibility":2,"archive_timestamp":"2026-02-27T10:53:50+00:00"},{"url":"https://www.business2community.com/crypto-news/ian-macalinao-inflates-solana-tvl-by-creating-11-fake-developer-personas-02532693","name":"Ian Macalinao Inflates Solana TVL by Creating 11 Fake Developer Personas - Business2Community","type":"news_article","archive_url":null,"credibility":2,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.coindesk.com/business/2023/01/11/doj-said-to-probe-saber-labs-founders-over-solana-based-defi-stablecoin-projects","name":"Justice Department Probing Saber Labs Founders Over Solana-Based Projects - CoinDesk","type":"regulatory","archive_url":"http://web.archive.org/web/20250424143304/https://www.coindesk.com/business/2023/01/11/doj-said-to-probe-saber-labs-founders-over-solana-based-defi-stablecoin-projects","credibility":1,"archive_timestamp":"2025-04-24T14:33:04+00:00"},{"url":"https://www.web3isgoinggreat.com/?id=ian-macalinao-pseudonyms","name":"Ian Macalinao Revealed to Have Pumped Solana TVL - Web3 Is Going Great","type":"news_article","archive_url":"http://web.archive.org/web/20260307053247/https://www.web3isgoinggreat.com/?id=ian-macalinao-pseudonyms","credibility":2,"archive_timestamp":"2026-03-07T05:32:47+00:00"},{"url":"https://www.tronweekly.com/brothers-behind-solana-saber-doj-investigation/","name":"Brothers Behind Solana Saber Labs Under DOJ Investigation - Tron Weekly","type":"news_article","archive_url":"https://web.archive.org/web/20260830051017/https://www.tronweekly.com/brothers-behind-solana-saber-doj-investigation/","credibility":2,"archive_timestamp":"2026-08-30T05:10:17+00:00"},{"url":"https://beincrypto.com/top-ten-defi-hacks-2022-hackers-daring/","name":"Top Ten DeFi Hacks of 2022 - BeInCrypto","type":"news_article","archive_url":null,"credibility":2,"archive_error":"forbiddenaccess","archive_status":"unarchivable","archive_timestamp":null}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:50.610527+00:00","updated_at":"2026-08-30T05:14:13.659629+00:00"}}