{"investigation":{"slug":"dforce-lending","entity_name":"dForce Lending","trust_score":28,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"dForce Lending (operating as Lendf.Me) is a Chinese-founded DeFi lending protocol that suffered a landmark ~$25 million ERC-777 reentrancy exploit in April 2020 — one of the largest DeFi hacks of that year — and a second reentrancy attack in February 2023 that drained $3.65 million. In both incidents, stolen funds were ultimately returned after the attackers were identified or negotiated with. The protocol has also faced persistent allegations of plagiarizing Compound Finance's open-source smart contract code without attribution, and a 2021 ConsenSys Diligence audit flagged centralised owner controls capable of draining user funds. ZachXBT has flagged dForce as a high-risk entity.","sections":[{"content":"On April 19, 2020, an attacker exploited a reentrancy vulnerability in Lendf.Me, dForce's lending market, draining approximately $25 million in mixed assets — including roughly 55,159 WETH (~$10 million) and over $7 million in USDT — in what was at the time one of the largest DeFi exploits ever recorded. The root cause was dForce's decision to accept imBTC, a synthetic Bitcoin token that implements the ERC-777 callback standard, as collateral. ERC-777's tokensToSend and tokensReceived hooks allow the token contract to notify senders and recipients during transfers. When Lendf.Me failed to follow the checks-effects-interactions pattern, the attacker was able to re-enter the contract during an imBTC deposit, repeatedly doubling their recorded collateral balance before the contract updated its internal state. The inflated, fraudulent balance was then used to borrow virtually every asset available on the platform. A near-identical ERC-777 reentrancy attack had been publicly documented against Uniswap's imBTC pool only days earlier, and security researchers had widely flagged this attack vector; dForce's failure to remediate the known vulnerability before it affected Lendf.Me drew substantial criticism. dForce's monitoring systems detected the attack at approximately 09:15 CST on April 19, at which point the Lendf.Me and USDx contracts were paused and the website was taken down. The 1inch exchange team identified that the attacker had exposed their IP address by accessing 1inch's CDN-hosted frontend from a single Chinese IP — rather than IPFS or Tor — revealing their device fingerprint (Mac OS, Chinese system language). The attacker subsequently attempted negotiation: three symbolic PAX stablecoin transactions summing ~$250,000 were sent to 1inch, ParaSwap, and a Lendf.Me admin address — 'pax' meaning peace in Latin. Huobi-issued assets worth approximately $2.6 million were returned first. By April 25, 2020, the full $25 million had been returned; by May 4, 2020, dForce confirmed that 100% of recovered funds had been redistributed to affected Lendf.Me users.","heading":"April 2020 ERC-777 Reentrancy Exploit (~$25 Million)","sources":[{"url":"https://medium.com/dforcenet/a-summary-of-the-attack-on-lendf-me-on-april-19-2020-e2f1c5d96640","name":"medium.com","type":"other","credibility":3},{"url":"https://quantstamp.com/blog/how-the-dforce-hacker-used-reentrancy-to-steal-25-million","name":"quantstamp.com","type":"other","credibility":3},{"url":"https://rekt.news/dforce-network-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://decrypt.co/26033/dforce-lendfme-defi-hack-25m","name":"decrypt.co","type":"other","credibility":3},{"url":"https://www.theblock.co/linked/62346/multicoin-capital-backed-defi-protocol-dforce-loses-25m-total-locked-value-in-an-exploit","name":"theblock.co","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2020/04/28/defi-project-dforce-refunds-all-affected-users-after-25m-hack","name":"coindesk.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/dforce-hacker-attempts-to-negotiate-after-allegedly-leaking-his-identity","name":"cointelegraph.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On February 9, 2023 at approximately 23:00 UTC, dForce's lending protocol was exploited a second time via a read-only reentrancy vector, resulting in losses of approximately $3.65 million — $1.9 million on Arbitrum and $1.7 million on Optimism. The attacker targeted dForce's Curve Finance vault, which relied on Curve's wstETH/ETH pool virtual price as a price oracle. By depositing flash-loaned funds into the Curve pool and then calling remove_liquidity, the attacker triggered a reentrancy that allowed them to manipulate the perceived virtual price of the wstETH collateral during the mid-state of the transaction, enabling forced liquidation of other users' positions. This class of read-only reentrancy vulnerability had been publicly documented and Curve had published mitigation guidance months before the attack; similar exploits had been used against Midas Capital and Market.xyz. The vulnerability fell outside the explicit scope of dForce's existing audit. dForce paused all vaults shortly after community members raised the alarm. The protocol subsequently contacted the exploiter via on-chain message, and the attacker — who described themselves as a 'whitehat' — returned all $3.65 million to dForce's multi-sig wallets in exchange for a negotiated bug bounty, with dForce agreeing to drop any law enforcement actions.","heading":"February 2023 Read-Only Reentrancy Exploit ($3.65 Million)","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-dforce-hack-february-2023","name":"halborn.com","type":"other","credibility":3},{"url":"https://www.theblock.co/post/210518/dforce-protocol-drained-of-3-6-million-in-reentrancy-attack","name":"theblock.co","type":"other","credibility":3},{"url":"https://www.certik.com/resources/blog/1oDd0j4Kx9dfym2vRwvf5Y-curve-conundrum-the-dforce-attack-via-a-read-only-reentrancy-vector-exploit","name":"certik.com","type":"other","credibility":3},{"url":"https://crypto.news/dforce-confirms-the-return-of-exploited-3-65m-to-their-vaults","name":"crypto.news","type":"other","credibility":3},{"url":"https://www.web3isgoinggreat.com/?id=dforce-network-exploited-for-3-65-million-funds-returned","name":"web3isgoinggreat.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the April 2020 exploit, dForce faced significant allegations that its Lendf.Me smart contracts were copied from Compound Finance's open-source codebase without proper attribution or licensing compliance. Robert Leshner, founder and CEO of Compound, stated publicly that Lendf.Me had appropriated Compound's code. A report by The Block noted that the term 'Compound' appeared four times within dForce's deployed smart contract bytecode, and that the Lendf.Me team added attribution to Compound only after The Block sought comment. Brian Kerr, CEO of Kava Labs, stated: 'The dForce team copied code they did not understand from Compound, illegally deployed it as their own while changing a few parts without realizing the security issues, and then they heavily marketed it to the world without first running very basic audits.' Leshner further commented: 'If a project doesn't have the expertise to develop its own smart contracts, and instead steals and redeploys somebody else's copyrighted code, it's a sign that they don't have the capacity or intention to consider security.' These allegations remain disputed by dForce but were not publicly rebutted by the dForce team with substantive counter-evidence at the time. The broader DeFi community used the incident as a cautionary example of forking complex financial code without understanding its security assumptions.","heading":"Alleged Code Plagiarism from Compound Finance","sources":[{"url":"https://cointelegraph.com/news/dforce-hacker-returns-stolen-money-as-criticism-of-the-project-continues","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://decrypt.co/26033/dforce-lendfme-defi-hack-25m","name":"decrypt.co","type":"other","credibility":3},{"url":"https://www.theblock.co/linked/62346/multicoin-capital-backed-defi-protocol-dforce-loses-25m-total-locked-value-in-an-exploit","name":"theblock.co","type":"other","credibility":3}],"severity":"medium"},{"content":"In March–April 2021, ConsenSys Diligence conducted an eight-person-week security review of the dForce Lending Protocol. The audit identified several material concerns. Most notably, the Owner role was flagged as a single point of failure: it held permissions to execute a wide variety of privileged actions across virtually every component of the system, including the ability to drain user funds if the role were compromised by a malicious insider or external attacker. The audit also noted that Owner-initiated changes took effect without any time delay, meaning upgrades could be applied without warning and could be used to front-run incoming user transactions. The audit further noted that the oracle implementation (PriceOracle.sol) was explicitly excluded from the audit scope, leaving a critical attack surface unreviewed — a gap that later proved consequential in the February 2023 exploit. Plans to transition the Owner role to a smart contract-governed multisig were described as insufficiently planned and wholly untested.","heading":"2021 ConsenSys Diligence Audit: Centralized Control Risks","sources":[{"url":"https://consensys.net/diligence/audits/2021/03/dforce-lending-protocol-review/","name":"consensys.net","type":"other","credibility":3},{"url":"https://diligence.consensys.io/audits/2021/03/dforce-lending-protocol-review/","name":"diligence.consensys.io","type":"other","credibility":3}],"severity":"medium"},{"content":"dForce was founded in late 2018 by Mindao Yang, a Chinese financier with a background in private equity and investment banking. Yang previously held Investment Director roles at Hony Capital — described as China's largest private equity firm — and at Standard Chartered Principal Finance. He has been involved in Bitcoin since 2013 and participated in the Ethereum ICO in 2014. Prior to dForce, he founded Blockpower and Hashingbot. The dForce Foundation was established in 2019. In April 2020, shortly before the exploit, Multicoin Capital announced a $1.5 million seed round in dForce, with co-investors including China Merchants Bank International (CMBI) and Huobi Capital. The timing of the Multicoin announcement — made five days before the exploit — attracted scrutiny, though no evidence of foreknowledge has been established.","heading":"Founding Team and Background","sources":[{"url":"https://decrypt.co/26069/exclusive-an-interview-with-dforce-founder-mindao-yang","name":"decrypt.co","type":"other","credibility":3},{"url":"https://multicoin.capital/2020/04/14/our-investment-in-dforce-the-defi-super-network/","name":"multicoin.capital","type":"other","credibility":3},{"url":"https://www.fxstreet.com/cryptocurrencies/news/chinese-decentralized-finance-platform-dforce-raises-15m-in-funding-led-by-multicoin-capital-202004160232","name":"fxstreet.com","type":"other","credibility":3}],"severity":"medium"},{"content":"A notable risk pattern for dForce is that both of its major exploits (April 2020 and February 2023) involved reentrancy attack vectors that were publicly documented before they were exploited against dForce. In 2020, the ERC-777 reentrancy risk had been explicitly demonstrated against the Uniswap/imBTC pool days before the Lendf.Me attack; dForce had not applied mitigations. In 2023, Curve's read-only reentrancy risk had been published by Curve's own team with mitigation guidance, and other protocols had already been exploited using the same vector. Security researchers have characterized dForce's repeated exposure to known vulnerabilities as evidence of inadequate ongoing security review processes, particularly the practice of scoping out oracle implementations from audits despite their direct integration with external price-sensitive code paths.","heading":"Repeated Reentrancy Failures and Pattern of Known Vulnerabilities","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-dforce-hack-february-2023","name":"halborn.com","type":"other","credibility":3},{"url":"https://www.certik.com/resources/blog/1oDd0j4Kx9dfym2vRwvf5Y-curve-conundrum-the-dforce-attack-via-a-read-only-reentrancy-vector-exploit","name":"certik.com","type":"other","credibility":3},{"url":"https://quantstamp.com/blog/how-the-dforce-hacker-used-reentrancy-to-steal-25-million","name":"quantstamp.com","type":"other","credibility":3},{"url":"https://medium.com/pnetwork/is-a-new-token-standard-really-to-blame-for-the-imbtc-uniswap-and-dforce-attacks-31c62e2bc799","name":"medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"As of 2025, dForce continues to operate as a multi-chain DeFi platform spanning Ethereum, Arbitrum, Optimism, BSC, Polygon, Avalanche, zkSync, Base, and other networks. The protocol has evolved beyond lending to include its USX decentralized stablecoin, yield tokens, and RWA (real-world asset) vaults, with reported total assets of approximately $200 million. The USX stablecoin maintains a price close to $1.00 with a market cap of approximately $15 million as of mid-2025. The protocol remains active but carries a documented history of two major exploits, allegations of code plagiarism, and centralized governance risks identified by third-party auditors.","heading":"Current Status and USX Stablecoin","sources":[{"url":"https://dforce.network/","name":"dforce.network","type":"other","credibility":3},{"url":"https://defillama.com/stablecoin/dforce-usd","name":"defillama.com","type":"other","credibility":3},{"url":"https://coinmarketcap.com/currencies/dforce/","name":"coinmarketcap.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2018","event":"dForce founded by Mindao Yang in China as an integrated open finance protocol.","source":"","date_original":"2018-01-01"},{"date":"2019","event":"dForce Foundation established; Lendf.Me lending market launched.","source":"","date_original":"2019-01-01"},{"date":"2020","event":"The Block reports that dForce's Lendf.Me contracts contain unattributed references to Compound Finance code; attribution later added after press inquiry.","source":"","date_original":"2020-01-01"},{"date":"2020-04-14","event":"Multicoin Capital announces $1.5M seed investment in dForce, with Huobi Capital and CMBI as co-investors.","source":""},{"date":"2020-04-19","event":"Lendf.Me exploited via ERC-777 reentrancy attack; approximately $25 million in assets drained. dForce pauses contracts and takes website offline.","source":""},{"date":"2020-04-20","event":"1inch exchange reports the attacker exposed their Chinese IP address and device fingerprint. Attacker begins symbolic PAX token peace transactions totaling ~$250,000 to dForce, 1inch, and ParaSwap.","source":""},{"date":"2020-04-22","event":"Compound's Robert Leshner and Kava Labs' Brian Kerr publicly allege dForce copied Compound's code without authorization or understanding.","source":""},{"date":"2020-04-25","event":"Attacker returns full ~$25 million to dForce. Huobi-issued assets worth ~$2.6M were the first to be returned.","source":""},{"date":"2020-05-04","event":"dForce confirms 100% of recovered funds redistributed to affected Lendf.Me users.","source":""},{"date":"2021-04-09","event":"ConsenSys Diligence publishes dForce Lending Protocol audit, flagging Owner role as single point of failure with unchecked power to drain user funds, and governance transition as untested.","source":""},{"date":"2023-02-09","event":"dForce Lending exploited via read-only reentrancy on Curve wstETH/ETH vault on Arbitrum and Optimism; $3.65 million drained.","source":""},{"date":"2023-02-13","event":"Attacker self-identifies as a whitehat, returns all $3.65 million to dForce multi-sig wallets in exchange for a bug bounty; dForce drops threatened law enforcement action.","source":""}],"sources_used":[{"url":"https://medium.com/dforcenet/a-summary-of-the-attack-on-lendf-me-on-april-19-2020-e2f1c5d96640","name":"medium.com","type":"other","archive_url":"http://web.archive.org/web/20250927013347/https://medium.com/dforcenet/a-summary-of-the-attack-on-lendf-me-on-april-19-2020-e2f1c5d96640","credibility":3,"archive_timestamp":"2025-09-27T01:33:47+00:00"},{"url":"https://quantstamp.com/blog/how-the-dforce-hacker-used-reentrancy-to-steal-25-million","name":"quantstamp.com","type":"other","archive_url":"https://web.archive.org/web/20260911161207/https://quantstamp.com/blog/how-the-dforce-hacker-used-reentrancy-to-steal-25-million","credibility":3,"archive_timestamp":"2026-09-11T16:12:07+00:00"},{"url":"https://rekt.news/dforce-network-rekt","name":"rekt.news","type":"other","archive_url":"http://web.archive.org/web/20260626190342/https://rekt.news/dforce-network-rekt","credibility":3,"archive_timestamp":"2026-06-26T19:03:42+00:00"},{"url":"https://decrypt.co/26033/dforce-lendfme-defi-hack-25m","name":"decrypt.co","type":"other","archive_url":"http://web.archive.org/web/20260610094119/https://decrypt.co/26033/dforce-lendfme-defi-hack-25m","credibility":3,"archive_timestamp":"2026-06-10T09:41:19+00:00"},{"url":"https://www.theblock.co/linked/62346/multicoin-capital-backed-defi-protocol-dforce-loses-25m-total-locked-value-in-an-exploit","name":"theblock.co","type":"other","archive_url":"https://web.archive.org/web/20260830133149/https://www.theblock.co/news/defi/2020-04-19-multicoin-capital-backed-defi-protocol-dforce-loses-25m-total-locked-value-in-an-exploit-62346","credibility":3,"archive_timestamp":"2026-08-30T13:31:49+00:00"},{"url":"https://www.coindesk.com/business/2020/04/28/defi-project-dforce-refunds-all-affected-users-after-25m-hack","name":"coindesk.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://cointelegraph.com/news/dforce-hacker-attempts-to-negotiate-after-allegedly-leaking-his-identity","name":"cointelegraph.com","type":"other","archive_url":"http://web.archive.org/web/20260112161440/https://cointelegraph.com/news/dforce-hacker-attempts-to-negotiate-after-allegedly-leaking-his-identity","credibility":3,"archive_timestamp":"2026-01-12T16:14:40+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-dforce-hack-february-2023","name":"halborn.com","type":"other","archive_url":"http://web.archive.org/web/20260215113214/https://www.halborn.com/blog/post/explained-the-dforce-hack-february-2023","credibility":3,"archive_timestamp":"2026-02-15T11:32:14+00:00"},{"url":"https://www.theblock.co/post/210518/dforce-protocol-drained-of-3-6-million-in-reentrancy-attack","name":"theblock.co","type":"other","archive_url":"http://web.archive.org/web/20260725164937/https://www.theblock.co/post/210518/dforce-protocol-drained-of-3-6-million-in-reentrancy-attack","credibility":3,"archive_timestamp":"2026-07-25T16:49:37+00:00"},{"url":"https://www.certik.com/resources/blog/1oDd0j4Kx9dfym2vRwvf5Y-curve-conundrum-the-dforce-attack-via-a-read-only-reentrancy-vector-exploit","name":"certik.com","type":"other","archive_url":"https://web.archive.org/web/20260830131930/https://www.certik.com/blog/1oDd0j4Kx9dfym2vRwvf5Y-curve-conundrum-the-dforce-attack-via-a-read-only-reentrancy-vector-exploit","credibility":3,"archive_timestamp":"2026-08-30T13:19:30+00:00"},{"url":"https://crypto.news/dforce-confirms-the-return-of-exploited-3-65m-to-their-vaults","name":"crypto.news","type":"other","archive_url":"http://web.archive.org/web/20260520225612/https://crypto.news/dforce-confirms-the-return-of-exploited-3-65m-to-their-vaults/","credibility":3,"archive_timestamp":"2026-05-20T22:56:12+00:00"},{"url":"https://www.web3isgoinggreat.com/?id=dforce-network-exploited-for-3-65-million-funds-returned","name":"web3isgoinggreat.com","type":"other","archive_url":"http://web.archive.org/web/20260521071641/https://www.web3isgoinggreat.com/?id=dforce-network-exploited-for-3-65-million-funds-returned","credibility":3,"archive_timestamp":"2026-05-21T07:16:41+00:00"},{"url":"https://cointelegraph.com/news/dforce-hacker-returns-stolen-money-as-criticism-of-the-project-continues","name":"cointelegraph.com","type":"other","archive_url":"http://web.archive.org/web/20260417053329/https://cointelegraph.com/news/dforce-hacker-returns-stolen-money-as-criticism-of-the-project-continues","credibility":3,"archive_timestamp":"2026-04-17T05:33:29+00:00"},{"url":"https://consensys.net/diligence/audits/2021/03/dforce-lending-protocol-review/","name":"consensys.net","type":"other","archive_url":null,"credibility":3,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://diligence.consensys.io/audits/2021/03/dforce-lending-protocol-review/","name":"diligence.consensys.io","type":"other","archive_url":"http://web.archive.org/web/20250911060907/https://diligence.consensys.io/audits/2021/03/dforce-lending-protocol-review/","credibility":3,"archive_timestamp":"2025-09-11T06:09:07+00:00"},{"url":"https://decrypt.co/26069/exclusive-an-interview-with-dforce-founder-mindao-yang","name":"decrypt.co","type":"other","archive_url":"http://web.archive.org/web/20260125035304/https://decrypt.co/26069/exclusive-an-interview-with-dforce-founder-mindao-yang","credibility":3,"archive_timestamp":"2026-01-25T03:53:04+00:00"},{"url":"https://multicoin.capital/2020/04/14/our-investment-in-dforce-the-defi-super-network/","name":"multicoin.capital","type":"other","archive_url":"http://web.archive.org/web/20251027031404/https://multicoin.capital/2020/04/14/our-investment-in-dforce-the-defi-super-network/","credibility":3,"archive_timestamp":"2025-10-27T03:14:04+00:00"},{"url":"https://www.fxstreet.com/cryptocurrencies/news/chinese-decentralized-finance-platform-dforce-raises-15m-in-funding-led-by-multicoin-capital-202004160232","name":"fxstreet.com","type":"other","archive_url":"https://web.archive.org/web/20260829202514/https://www.fxstreet.com/cryptocurrencies/news/chinese-decentralized-finance-platform-dforce-raises-15m-in-funding-led-by-multicoin-capital-202004160232","credibility":3,"archive_timestamp":"2026-08-29T20:25:14+00:00"},{"url":"https://medium.com/pnetwork/is-a-new-token-standard-really-to-blame-for-the-imbtc-uniswap-and-dforce-attacks-31c62e2bc799","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://dforce.network/","name":"dforce.network","type":"other","archive_url":"http://web.archive.org/web/20260423002005/https://dforce.network/","credibility":3,"archive_timestamp":"2026-04-23T00:20:05+00:00"},{"url":"https://defillama.com/stablecoin/dforce-usd","name":"defillama.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://coinmarketcap.com/currencies/dforce/","name":"coinmarketcap.com","type":"other","archive_url":"http://web.archive.org/web/20260814095820/https://coinmarketcap.com/currencies/dforce/","credibility":3,"archive_timestamp":"2026-08-14T09:58:20+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:55:01.07256+00:00","updated_at":"2026-09-11T16:14:52.800531+00:00"}}