{"investigation":{"slug":"defrost","entity_name":"Defrost Finance","trust_score":18,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"Defrost Finance was an Avalanche-based CDP (Collateralized Debt Position) DeFi protocol that allowed users to collateralize yield-bearing tokens to mint an H2O USD-pegged stablecoin. In December 2022 the protocol suffered a two-stage exploit resulting in approximately $12 million in losses; multiple blockchain security firms — including CertiK, PeckShield, and De.Fi Security — alleged the attack constituted an insider rug pull enabled by admin key access, a conclusion the team denied. Funds were subsequently returned and a refund contract was deployed in January 2023, but the protocol has since effectively ceased meaningful operations with under $100,000 in TVL, and the MELT governance token has lost nearly all of its value.","sections":[{"content":"Defrost Finance was a decentralized CDP protocol deployed on the Avalanche blockchain. It enabled users to deposit yield-bearing tokens as collateral to borrow H2O, a USD-pegged stablecoin, and also featured a leveraged trading product. The protocol launched in late 2021. Its native governance token, MELT, reached an all-time high of approximately $23.00 in December 2021. Total value locked peaked at around $95 million in February 2022 before declining to approximately $13 million by December 2022. Following a December 2022 security incident, TVL collapsed to under $93,000. As of 2024–2025, DefiLlama reports TVL at approximately $81,000, and the protocol has not resumed active development.","heading":"Overview","sources":[{"url":"https://www.coindesk.com/business/2022/12/25/defrost-finance-hacked-in-attack-some-say-may-have-been-a-rug-pull","name":"coindesk.com","type":"other","credibility":3},{"url":"https://defillama.com/protocol/defrost","name":"defillama.com","type":"other","credibility":3},{"url":"https://www.coingecko.com/en/coins/defrost-finance","name":"coingecko.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On December 23, 2022 (Christmas Eve), Defrost Finance suffered a two-stage attack. The first attack targeted the V2 protocol using a flash loan exploit: the attacker exploited a lack of reentrancy protection on the flashloan/deposit functions to manipulate the share price of LSWUSDC, draining approximately $173,000. The second — and far larger — attack targeted V1: the attacker used an owner (admin) private key to add a fake collateral token and a malicious price oracle, then minted 100 million H2O stablecoins and used the manipulated oracle to liquidate existing user positions, resulting in a total loss estimated at approximately $12 million. The critical technical distinction in the V1 attack is that it required access to the project's owner key or multisig — a form of privileged access not available to external attackers without an insider component or compromised operational security.","heading":"December 2022 Exploit — Attack Mechanics","sources":[{"url":"https://www.coindesk.com/business/2022/12/25/defrost-finance-hacked-in-attack-some-say-may-have-been-a-rug-pull","name":"coindesk.com","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-defrost-hack-december-2022","name":"halborn.com","type":"other","credibility":3},{"url":"https://medium.com/@DeDotFiSecurity/exclusive-the-defrost-team-rugpulled-12m-7m-999b24c13f47","name":"medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Multiple blockchain security firms concluded or strongly suggested that the V1 attack was an insider rug pull rather than an external hack. CertiK, in a December 26, 2022 public statement, declared Defrost Finance an 'exit scam,' citing the team's failure to respond to attempted contact. PeckShield stated that the attack appeared to have been a rug pull. De.Fi Security published on-chain analysis showing that the wallet address which created the project's multisig was the same address that requested and approved the malicious oracle replacement transaction (on-chain transaction hash: 0x21fb9837044464cfa5db531e7ad07cbed9f60f57315d4a76291dbd2f3803e38d). DeFiYield similarly identified overlapping wallet provenance. The alleged multisig creator address is 0x7f08ba62fadaf3b4b70a8ddc22b3c63669bddeb2, and the address that initiated the oracle replacement is 0x3cd5854fe3a13707b7882d8290d3cae793a7751a. These are alleged findings by third-party security researchers; no court has made a formal determination.","heading":"Rug Pull Allegations and Security Firm Findings","sources":[{"url":"https://cointelegraph.com/news/defrost-finance-offers-20-payment-to-hackers-as-certik-claims-project-is-an-exit-scam","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://medium.com/@DeDotFiSecurity/exclusive-the-defrost-team-rugpulled-12m-7m-999b24c13f47","name":"medium.com","type":"other","credibility":3},{"url":"https://dailycoin.com/defrost-finance-hacked-for-12-million-security-firms-call-it-a-rug-pull/","name":"dailycoin.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2022/12/25/defrost-finance-hacked-in-attack-some-say-may-have-been-a-rug-pull","name":"coindesk.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The Defrost Finance team broke its silence on December 28, 2022, in a statement to CoinTelegraph, denying that they had orchestrated a rug pull. The team characterized the V1 attack as having involved hackers who 'appropriated the private key' and used it to insert malicious contracts. The team labeled rug-pull claims as 'slanderous and inaccurate,' and argued that if they had planned an exit scam, they would have executed it months earlier when TVL was near $200 million rather than at $13 million. The team also stated that the speed with which they announced fund recovery was evidence of good faith. No team members were identified by name in official statements. The team did not publicly address the alleged wallet overlap identified by De.Fi Security.","heading":"Team Denial and Response","sources":[{"url":"https://www.coindesk.com/business/2022/12/30/defrost-finance-denies-rug-pull-allegations-amid-12m-exploit","name":"coindesk.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/defrost-finance-breaks-silence-on-exit-scam-accusations-denies-rug-pull","name":"cointelegraph.com","type":"other","credibility":3}],"severity":"medium"},{"content":"De.Fi Security and other researchers have alleged that the developers behind Defrost Finance are the same individuals who operated Phoenix Finance (FinNexus), a DeFi options protocol that suffered a $7.6 million exploit in May 2021. In that incident, an unknown actor obtained the private key to the FNX token contract, minted over 323 million FNX tokens, and dumped them on the market. FinNexus officially attributed the loss to a stolen private key. De.Fi Security alleged that on-chain patterns — including GitHub account naming conventions (shared 'jqg' suffix) and wallet funding paths — link the same development team to both projects. It further alleged that funds used to deploy Defrost Finance originated in part from the 2021 FinNexus losses routed through Tornado Cash on Avalanche (deployer funding address: 0xbbb2229ed5d1ca3501f8c4ef31741b6800e12d3b). The individuals named in De.Fi Security's investigation are 'Boris Yang,' 'Jacky Wang,' and 'Lu Jianqiang'; De.Fi Security alleged their LinkedIn profiles were fabricated. These are alleged findings by a third-party research firm and have not been independently verified by law enforcement or a court. The combined alleged losses across both incidents are approximately $19 million.","heading":"Alleged Connection to FinNexus / Phoenix Finance 2021 Exploit","sources":[{"url":"https://medium.com/@DeDotFiSecurity/exclusive-the-defrost-team-rugpulled-12m-7m-999b24c13f47","name":"medium.com","type":"other","credibility":3},{"url":"https://medium.com/@DeDotFiSecurity/the-most-evil-crypto-scam-defrost-finance-was-funded-with-criminal-money-cb08c99fb6d9","name":"medium.com","type":"other","credibility":3},{"url":"https://finance.yahoo.com/news/latest-defi-hack-drains-7-050841516.html","name":"finance.yahoo.com","type":"other","credibility":3},{"url":"https://medium.com/phoenix-finance/finnexus-statement-regarding-the-may-2021-hack-d69e1b7617dc","name":"medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On December 26, 2022, Defrost Finance announced that the funds from the V1 attack had been returned to an address controlled by the project. The team stated it had offered a bounty to the hacker and received the funds back. The team announced a plan to convert recovered ETH into DAI and bridge it to Avalanche, with 12,850,277 DAI.e prepared for distribution. A refund smart contract was deployed and made claimable from January 11, 2023 at 00:01 UTC. The contract included a 100-day lock period. Users were reimbursed based on their vault positions and H2O holdings at the time of the exploit. The circumstances of the fund return — specifically why an external hacker would return funds after a successful exploit — were noted by security researchers as consistent with the insider rug pull theory rather than a conventional external hack.","heading":"Fund Return and Refund Process","sources":[{"url":"https://www.coindesk.com/business/2022/12/26/defrost-finance-says-hacked-funds-have-been-returned","name":"coindesk.com","type":"other","credibility":3},{"url":"https://medium.com/@Defrost_Finance/the-refund-contract-has-been-deployed-here-is-how-to-claim-your-refund-6632c53f6c5c","name":"medium.com","type":"other","credibility":3},{"url":"https://medium.com/@Defrost_Finance/details-of-the-defrost-finance-refund-plan-ba574236158d","name":"medium.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/here-s-how-defrost-finance-plans-to-refund-users-following-12m-hack/amp","name":"cointelegraph.com","type":"other","credibility":3}],"severity":"medium"},{"content":"As of 2024–2025, Defrost Finance retains a nominal TVL of approximately $81,000 on Avalanche according to DefiLlama — a reduction of over 99.9% from its February 2022 peak. The MELT governance token trades at approximately $0.0003–$0.0008, representing a decline of over 99.9% from its all-time high of approximately $23.00 in December 2021. The protocol's website listed 'Coming Soon' messaging after the exploit, suggesting it has not returned to active operation. No regulatory enforcement actions against Defrost Finance or its alleged team members have been identified in public records as of this investigation.","heading":"Current Protocol Status","sources":[{"url":"https://defillama.com/protocol/defrost","name":"defillama.com","type":"other","credibility":3},{"url":"https://www.coingecko.com/en/coins/defrost-finance","name":"coingecko.com","type":"other","credibility":3},{"url":"https://coinmarketcap.com/currencies/defrost-finance/","name":"coinmarketcap.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2021-05-17","event":"FinNexus (Phoenix Finance), a DeFi options protocol allegedly operated by the same team, is exploited for approximately $7.6 million via a private key compromise and token minting attack.","source":""},{"date":"2021-09","event":"Defrost Finance launches on Avalanche. De.Fi Security later alleged that project deployment was partially funded by proceeds from the 2021 FinNexus exploit.","source":"","date_original":"2021-09-01"},{"date":"2022-02","event":"Defrost Finance TVL peaks at approximately $95 million.","source":"","date_original":"2022-02-01"},{"date":"2022-12-23","event":"First attack: Flash loan exploit on Defrost V2 drains approximately $173,000 by exploiting a reentrancy vulnerability in the flashloan/deposit functions.","source":""},{"date":"2022-12-24","event":"Second attack: Defrost V1 is exploited via admin owner key access; attacker inserts a fake collateral token and malicious price oracle, mints 100 million H2O, and liquidates user positions. Total losses reach approximately $12 million.","source":""},{"date":"2022-12-25","event":"CoinDesk and PeckShield report on the exploit. PeckShield states the attack 'may have been a rug pull.' Defrost TVL drops from $13 million to under $93,000.","source":""},{"date":"2022-12-26","event":"CertiK publicly labels Defrost Finance an 'exit scam,' citing inability to contact team members. Defrost Finance announces funds from V1 attack have been returned.","source":""},{"date":"2022-12-28","event":"Defrost Finance team breaks silence with a statement denying rug pull allegations, characterizing the event as an external private key compromise.","source":""},{"date":"2022-12-30","event":"De.Fi Security publishes on-chain analysis alleging the multisig wallet creator is the same address that initiated the malicious oracle replacement, and connecting Defrost team to the 2021 FinNexus exploit.","source":""},{"date":"2023-01-11","event":"Defrost Finance deploys refund smart contract. Affected V1 vault depositors and H2O holders become eligible to claim stablecoin reimbursements based on pre-exploit positions.","source":""}],"sources_used":[{"url":"https://www.coindesk.com/business/2022/12/25/defrost-finance-hacked-in-attack-some-say-may-have-been-a-rug-pull","name":"coindesk.com","type":"other","archive_url":"http://web.archive.org/web/20251115185634/https://www.coindesk.com/business/2022/12/25/defrost-finance-hacked-in-attack-some-say-may-have-been-a-rug-pull","credibility":3,"archive_timestamp":"2025-11-15T18:56:34+00:00"},{"url":"https://defillama.com/protocol/defrost","name":"defillama.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.coingecko.com/en/coins/defrost-finance","name":"coingecko.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://www.halborn.com/blog/post/explained-the-defrost-hack-december-2022","name":"halborn.com","type":"other","archive_url":"http://web.archive.org/web/20260513002234/https://www.halborn.com/blog/post/explained-the-defrost-hack-december-2022","credibility":3,"archive_timestamp":"2026-05-13T00:22:34+00:00"},{"url":"https://medium.com/@DeDotFiSecurity/exclusive-the-defrost-team-rugpulled-12m-7m-999b24c13f47","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://cointelegraph.com/news/defrost-finance-offers-20-payment-to-hackers-as-certik-claims-project-is-an-exit-scam","name":"cointelegraph.com","type":"other","archive_url":"https://web.archive.org/web/20260829130514/https://cointelegraph.com/news/defrost-finance-offers-20-payment-to-hackers-as-certik-claims-project-is-an-exit-scam","credibility":3,"archive_timestamp":"2026-08-29T13:05:14+00:00"},{"url":"https://dailycoin.com/defrost-finance-hacked-for-12-million-security-firms-call-it-a-rug-pull/","name":"dailycoin.com","type":"other","archive_url":"https://web.archive.org/web/20260829132433/https://dailycoin.com/defrost-finance-hacked-for-12-million-security-firms-call-it-a-rug-pull/","credibility":3,"archive_timestamp":"2026-08-29T13:24:33+00:00"},{"url":"https://www.coindesk.com/business/2022/12/30/defrost-finance-denies-rug-pull-allegations-amid-12m-exploit","name":"coindesk.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://cointelegraph.com/news/defrost-finance-breaks-silence-on-exit-scam-accusations-denies-rug-pull","name":"cointelegraph.com","type":"other","archive_url":"http://web.archive.org/web/20260310065235/https://cointelegraph.com/news/defrost-finance-breaks-silence-on-exit-scam-accusations-denies-rug-pull","credibility":3,"archive_timestamp":"2026-03-10T06:52:35+00:00"},{"url":"https://medium.com/@DeDotFiSecurity/the-most-evil-crypto-scam-defrost-finance-was-funded-with-criminal-money-cb08c99fb6d9","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://finance.yahoo.com/news/latest-defi-hack-drains-7-050841516.html","name":"finance.yahoo.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://medium.com/phoenix-finance/finnexus-statement-regarding-the-may-2021-hack-d69e1b7617dc","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.coindesk.com/business/2022/12/26/defrost-finance-says-hacked-funds-have-been-returned","name":"coindesk.com","type":"other","archive_url":"http://web.archive.org/web/20251116021857/https://www.coindesk.com/business/2022/12/26/defrost-finance-says-hacked-funds-have-been-returned","credibility":3,"archive_timestamp":"2025-11-16T02:18:57+00:00"},{"url":"https://medium.com/@Defrost_Finance/the-refund-contract-has-been-deployed-here-is-how-to-claim-your-refund-6632c53f6c5c","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://medium.com/@Defrost_Finance/details-of-the-defrost-finance-refund-plan-ba574236158d","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://cointelegraph.com/news/here-s-how-defrost-finance-plans-to-refund-users-following-12m-hack/amp","name":"cointelegraph.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://coinmarketcap.com/currencies/defrost-finance/","name":"coinmarketcap.com","type":"other","archive_url":"https://web.archive.org/web/20260829234029/https://coinmarketcap.com/currencies/defrost-finance/","credibility":3,"archive_timestamp":"2026-08-29T23:40:29+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:45.717084+00:00","updated_at":"2026-08-30T01:16:32.08068+00:00"}}