{"investigation":{"slug":"cozy-v2","entity_name":"Cozy V2","trust_score":42,"severity_base":null,"score_modifier":0,"confidence":0.72,"status":"published","content_type":"investigation","summary":"Cozy V2 is a DeFi protection marketplace deployed on Optimism that allows users to buy or provide protection against smart contract hacks, depegs, and other on-chain risks. On August 29, 2025, the protocol suffered a $427,000 exploit caused by a missing caller verification check in its withdrawal logic, with funds subsequently bridged to Ethereum mainnet and deposited into Tornado Cash. The incident is notable for its irony: a protocol designed to insure against DeFi hacks was itself hacked through a preventable authorization flaw.","sections":[{"content":"Cozy V2 is the second major version of Cozy Finance, a DeFi protection protocol founded in 2020 by Tony Sheng (formerly of Multicoin Capital and Decentraland) and Payom Dousti (co-founder of Rare Bits), along with Zach Krasner. The protocol is deployed on Optimism (OP Mainnet) and operates as a permissionless protection marketplace. In V2, participants fall into three categories: Protection Creators who define trigger conditions and publish on-chain Trigger Contracts; Protection Providers who supply capital and earn yield when their market does not trigger; and Protection Buyers who pay premiums to hedge against predefined risk events such as smart contract hacks or stablecoin depegs. When a trigger condition is met, protection markets freeze automatically and Protection Buyers are released from repayment obligations, allowing them to retain borrowed assets as a payout. V2 replaced V1, which launched on Ethereum mainnet and was subsequently sunset. V2 relocated to Optimism and introduced a revamped cost model allowing permissionless market creation. As of mid-2025, the protocol's total value locked stood at approximately $184,931 on OP Mainnet, according to DeFiLlama.","heading":"Protocol Overview","sources":[{"url":"https://mirror.xyz/cozy.eth/w24TU4ksefu7-jF1AGBrIbfeNKuZAH9v41aJw_VAr4g","name":"mirror.xyz","type":"other","credibility":3},{"url":"https://defillama.com/protocol/cozy-v2","name":"defillama.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2020/09/03/defi-risk-management-startup-cozy-finance-debuts-with-2m-funding-round","name":"coindesk.com","type":"other","credibility":3},{"url":"https://medium.com/@cozyfinance/introducing-cozy-protection-markets-fc8f75636085","name":"medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On August 29, 2025, Cozy V2 was exploited on OP Mainnet through a critical authorization flaw in its withdrawal system, resulting in losses of approximately $427,000. The vulnerability involved two compounding oversights. First, the `completeWithdraw` function did not verify that the caller completing a redemption was the same address that originally initiated it. An attacker could supply any victim's redemption ID and execute the withdrawal on their behalf. Second, the `unwrapWrappedAssetViaConnectorForWithdraw` function did not validate the `receiver_` parameter, allowing the attacker to redirect converted yield-bearing tokens (such as aOptUSDC) to a wallet they controlled rather than the intended recipient. The attack sequence began on August 28, 2025, when a victim initiated a redemption of approximately $376,661 with redemption ID 6. The attacker then used a separate account to call `completeWithdraw` with the same ID, converting the victim's stataOptUSDC into USDC and routing the funds to the attacker's address. The total loss across the incident reached approximately $427,000. Following the exploit, the attacker bridged the stolen funds to an Ethereum mainnet address and subsequently deposited them into Tornado Cash, a transaction mixing service, in an apparent attempt to obscure the on-chain trail. Security firm Decurity first publicly flagged the hack via social media. Verichains published a technical post-mortem analyzing the vulnerability in detail.","heading":"August 2025 Exploit — Protocol Logic Vulnerability","sources":[{"url":"https://blog.verichains.io/p/cozy-protocol-incident","name":"blog.verichains.io","type":"other","credibility":3},{"url":"https://x.com/DecurityHQ/status/1961810726164533602","name":"x.com","type":"other","credibility":3},{"url":"https://defillama.com/protocol/cozy-v2","name":"defillama.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Blockchain investigator ZachXBT is recorded as having flagged Cozy V2 in connection with the August 2025 exploit. The specific context of the flag — whether it pertained to the attacker's on-chain movement of funds, the Tornado Cash deposit, or a broader security alert — is not independently verified by a publicly available primary source at the time of this investigation. The exploit was corroborated by independent security monitoring firm Decurity, which reported on the hack via X (formerly Twitter) and noted that stolen funds were bridged to mainnet and deposited into Tornado Cash. Verichains independently analyzed and published a detailed incident report. No public statement from the Cozy Finance team addressing the exploit, announcing a post-mortem, or outlining a remediation plan has been identified in available sources. The protocol's use of Tornado Cash by the attacker to launder proceeds is a standard pattern in DeFi exploits and does not by itself imply protocol complicity.","heading":"ZachXBT Flag and Community Response","sources":[{"url":"https://x.com/DecurityHQ/status/1961810726164533602","name":"x.com","type":"other","credibility":3},{"url":"https://blog.verichains.io/p/cozy-protocol-incident","name":"blog.verichains.io","type":"other","credibility":3}],"severity":"medium"},{"content":"DeFiLlama categorizes Cozy V2 as \"Audited,\" though a specific named audit firm and corresponding audit report for the V2 codebase were not identified in available public sources at the time of this investigation. The Cozy Finance GitHub organization (github.com/Cozy-Finance) hosts developer guides and integration code but had not, as of available records, published a SECURITY.md file. The August 2025 exploit was classified as a Protocol Logic vulnerability with an Insufficient Sender Verification root cause — a class of bug that standard access-control reviews are expected to catch. The absence of caller verification on a withdrawal completion function in a financial protocol represents a material security oversight. Cozy V2's V2 codebase is open-source and available on GitHub. The protocol previously demonstrated its trigger mechanism worked correctly: in March 2023, when Euler Finance was hacked for approximately $200 million, an active Cozy V2 early-access market covering Euler Finance triggered and paid out to Protection Buyers, indicating the core trigger logic functioned as intended in that instance.","heading":"Security Posture and Audit History","sources":[{"url":"https://blog.verichains.io/p/cozy-protocol-incident","name":"blog.verichains.io","type":"other","credibility":3},{"url":"https://defillama.com/protocol/cozy-v2","name":"defillama.com","type":"other","credibility":3},{"url":"https://github.com/Cozy-Finance","name":"github.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Cozy Finance raised a $2 million seed round announced on September 3, 2020, led by Electric Capital. Additional investors included Variant Fund, Dragonfly Capital, Robot Ventures, Slow Ventures, Volt Capital, Spencer Noon, and Ed Moncada (founder of Blockfolio). Co-founder Tony Sheng previously worked at Multicoin Capital and served as Product Lead at Decentraland. Co-founder Payom Dousti previously co-founded Rare Bits, a peer-to-peer crypto goods marketplace, and was Director of Product at FanDuel; he serves as CEO of Cozy Finance. Zach Krasner is listed as a third co-founder. The company was incorporated and operates out of Seattle, Washington. No additional disclosed funding rounds beyond the 2020 seed have been identified. The protocol's V2 deployment on Optimism operates with a restriction against US persons, as noted in the protocol's terms. No governance token has been identified for Cozy V2. The protocol appears to operate without decentralized governance.","heading":"Funding, Team, and Background","sources":[{"url":"https://www.coindesk.com/business/2020/09/03/defi-risk-management-startup-cozy-finance-debuts-with-2m-funding-round","name":"coindesk.com","type":"other","credibility":3},{"url":"https://www.crunchbase.com/organization/cozy-finance","name":"crunchbase.com","type":"other","credibility":3},{"url":"https://www.crunchbase.com/person/payom-dousti","name":"crunchbase.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Several risk factors are relevant for users evaluating Cozy V2. First, the August 2025 exploit demonstrated that a missing access-control check in core withdrawal logic led to a $427,000 loss, and no public remediation announcement has been identified. Second, the protocol's total value locked is small (approximately $185,000 as of mid-2025), which limits liquidity available for payout in large trigger events and may indicate reduced user confidence post-exploit. Third, the attacker's use of Tornado Cash to launder funds means on-chain recovery of stolen assets is unlikely. Fourth, the protocol explicitly excludes US persons from participation, which may reflect legal uncertainty around the classification of protection markets as insurance products subject to regulation. Fifth, the protocol operates without a public governance token or decentralized governance mechanism, concentrating protocol upgrade authority in the founding team. The protocol is restricted to Optimism and has not expanded to additional chains. No regulatory actions against Cozy Finance or its founders have been identified.","heading":"Protocol Risk Factors","sources":[{"url":"https://blog.verichains.io/p/cozy-protocol-incident","name":"blog.verichains.io","type":"other","credibility":3},{"url":"https://defillama.com/protocol/cozy-v2","name":"defillama.com","type":"other","credibility":3},{"url":"https://v2.cozy.finance/","name":"v2.cozy.finance","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2020-09-03","event":"Cozy Finance announces $2M seed round led by Electric Capital; founders Tony Sheng and Payom Dousti publicly named.","source":""},{"date":"2021-09","event":"Cozy Finance V1 launches on Ethereum mainnet as an open-source protection market protocol.","source":"","date_original":"2021-09-01"},{"date":"2023-03-13","event":"Euler Finance hacked for approximately $200M. Cozy V2 early-access Euler Finance market triggers and pays out to Protection Buyers, validating core trigger logic.","source":""},{"date":"2023","event":"Cozy V2 launches on Optimism (OP Mainnet) with redesigned permissionless protection marketplace architecture; V1 subsequently sunset.","source":"","date_original":"2023-01-01"},{"date":"2025-08-28","event":"Victim initiates redemption of approximately $376,661 (redemption ID 6) on Cozy V2 on Optimism.","source":""},{"date":"2025-08-29","event":"Attacker exploits missing caller verification in `completeWithdraw` function, redirecting victim's redemption proceeds to attacker's address. Total loss reaches approximately $427,000.","source":""},{"date":"2025-08-30","event":"Decurity publicly reports the exploit on X, noting attacker bridged funds from Optimism to Ethereum mainnet and deposited into Tornado Cash.","source":""},{"date":"2025-08-30","event":"Verichains publishes detailed technical post-mortem of the Cozy Protocol incident, classifying the root cause as insufficient sender verification.","source":""}],"sources_used":[{"url":"https://mirror.xyz/cozy.eth/w24TU4ksefu7-jF1AGBrIbfeNKuZAH9v41aJw_VAr4g","name":"mirror.xyz","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://defillama.com/protocol/cozy-v2","name":"defillama.com","type":"other","archive_url":"http://web.archive.org/web/20250911025539/https://defillama.com/protocol/cozy-v2","credibility":3,"archive_timestamp":"2025-09-11T02:55:39+00:00"},{"url":"https://www.coindesk.com/business/2020/09/03/defi-risk-management-startup-cozy-finance-debuts-with-2m-funding-round","name":"coindesk.com","type":"other","archive_url":"https://web.archive.org/web/20260915164021/https://www.coindesk.com/business/2020/09/03/defi-risk-management-startup-cozy-finance-debuts-with-2m-funding-round","credibility":3,"archive_timestamp":"2026-09-15T16:40:21+00:00"},{"url":"https://medium.com/@cozyfinance/introducing-cozy-protection-markets-fc8f75636085","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://blog.verichains.io/p/cozy-protocol-incident","name":"blog.verichains.io","type":"other","archive_url":"http://web.archive.org/web/20260515173259/https://blog.verichains.io/p/cozy-protocol-incident","credibility":3,"archive_timestamp":"2026-05-15T17:32:59+00:00"},{"url":"https://x.com/DecurityHQ/status/1961810726164533602","name":"x.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://github.com/Cozy-Finance","name":"github.com","type":"other","archive_url":"https://web.archive.org/web/20260830115518/https://github.com/Cozy-Finance","credibility":3,"archive_timestamp":"2026-08-30T11:55:18+00:00"},{"url":"https://www.crunchbase.com/organization/cozy-finance","name":"crunchbase.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.crunchbase.com/person/payom-dousti","name":"crunchbase.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://v2.cozy.finance/","name":"v2.cozy.finance","type":"other","archive_url":"https://web.archive.org/web/20260829120519/https://v2.cozy.finance/","credibility":3,"archive_timestamp":"2026-08-29T12:05:19+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:21.561699+00:00","updated_at":"2026-09-15T17:10:50.585783+00:00"}}