{"investigation":{"slug":"eleven-finance","entity_name":"Eleven Finance","trust_score":32,"severity_base":null,"score_modifier":0,"confidence":0.72,"status":"published","content_type":"investigation","summary":"Eleven Finance is a yield optimizer and leveraged yield farming protocol deployed on Binance Smart Chain (BSC) and Polygon. On June 22, 2021, attackers exploited a critical smart contract vulnerability in the protocol's Nerve-partnership vaults, draining approximately $4.5–4.8 million. The team published a recovery plan, repaid an initial 25% tranche from personal debt, and later announced full principal recovery; however, the ELE token has since lost over 99% of its value from its all-time high, and the protocol appears largely inactive.","sections":[{"content":"On June 22–23, 2021, an attacker exploited the ElevenNeverSellVault contracts on Binance Smart Chain to drain approximately $4.5–4.8 million across six Nerve-partnership vaults. The vulnerability resided in the `emergencyBurn()` function, which was designed to allow users to withdraw deposited funds while burning their corresponding share tokens. Due to a developer oversight, the function transferred assets to users without actually burning their shares. This enabled a double-withdrawal attack: the attacker could call `emergencyBurn()` to extract vault liquidity, and then invoke `withdrawAll()` again using the unburned shares to drain additional funds. The attacker first used a flash loan of approximately 953,869 BUSD via PancakeSwap to acquire Nerve Finance LP tokens, deposited them into Eleven Finance vaults, and then executed the bug repeatedly across multiple pools. Drained vaults included nrvBTC (~$1.05M), nrvETH (~$561K), 3nrv (~$2.24M), nrvUST, nrvfUSDT, and bfUSD. The stolen proceeds were bridged via the Nerve bridge to an external Ethereum address. PeckShield confirmed in a root cause analysis that the code had been present since the inception of these vaults and was missed during both internal code review and external audits. The attacker's primary address was identified as 0x8b29.","heading":"The June 2021 Exploit","sources":[{"url":"https://rekt.news/11-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://elevenfinance.medium.com/eleven-finance-nrv-vault-exploit-and-loss-of-funds-a-post-mortem-437a79ded743","name":"elevenfinance.medium.com","type":"other","credibility":3},{"url":"https://peckshield.medium.com/eleven-finance-incident-root-cause-analysis-123b5675fa76","name":"peckshield.medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Eleven Finance underwent at least one external audit by CertiK, with the audit delivered on July 19, 2021 — approximately four weeks after the exploit. The CertiK audit covered lending bank contracts (addstrat.sol, bankConfig.sol, borrow.sol, eleUSD.sol, and related files) and found no critical issues, with 1 major and 2 medium findings. Notably, the exploited NRV vault contracts were not included in the scope of the CertiK audit. The team acknowledged that the vulnerability had existed since the vaults' inception and was overlooked in code review. This audit gap — covering lending contracts but not the yield vault contracts that were drained — represents a material security failure. Solidity Finance is also cited as an auditor of the platform in some documentation. The ELE token contract itself was reported to have no submitted security audit.","heading":"Audit History and Security Failures","sources":[{"url":"https://skynet.certik.com/projects/elevenfinance","name":"skynet.certik.com","type":"other","credibility":3},{"url":"https://docs.eleven.finance/security","name":"docs.eleven.finance","type":"other","credibility":3},{"url":"https://elevenfinance.medium.com/eleven-finance-nrv-vault-exploit-and-loss-of-funds-a-post-mortem-437a79ded743","name":"elevenfinance.medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the exploit, Eleven Finance published a detailed recovery plan. Within approximately 48 hours, a self-described whitehat hacker voluntarily returned 849.2 BNB (roughly $252,000) to the original Eleven Finance deployer address. An additional $260,000 was recovered from leveraged farming positions (BigFoot) that had been inaccessible during the attack. Phase 1 of the recovery plan distributed approximately $1.2 million (25% of total losses) to affected users, with the team reportedly taking on personal debt of approximately $688,000 beyond the recovered funds to fund this payment. Phase 2 involved issuing 3.6 million '11RV' recovery tokens representing the remaining $3.6 million in owed compensation. These tokens were distributed proportionally to affected users and staked in a Recovery Vault accruing ELE emissions. In October 2021, Eleven Finance announced that the full principal of exploited funds had been recovered, and that a second distribution would bring affected users close to 100% compensation in BUSD. The team cited ongoing local police reports regarding the original attacker. Whether 100% of users received full compensation is not independently verifiable from available sources.","heading":"Recovery Plan and Compensation","sources":[{"url":"https://elevenfinance.medium.com/eleven-finance-recovery-plan-a3869f8242d0","name":"elevenfinance.medium.com","type":"other","credibility":3},{"url":"https://elevenfinance.medium.com/eleven-finance-a-plan-for-the-return-of-funds-recovered-from-the-nerve-vault-exploit-39a006af20d3","name":"elevenfinance.medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The ELE token is a BEP-20 token on Binance Smart Chain at contract address 0xacd7b3d9c10e97d0efa418903c0c7669e702e4c0. The token reached an all-time high of approximately $1.45 and as of 2025–2026 trades at roughly $0.0028–$0.005, representing a decline of approximately 99.7–99.8% from peak. Reported 24-hour trading volume is effectively zero on most price tracking platforms, and the token trades on approximately 16 markets with negligible liquidity. Max supply is capped at 11 million ELE. The protocol was intended to expand to Arbitrum, Fantom, and Solana, but no evidence of significant multi-chain expansion is verifiable from public sources. The platform website (eleven.finance) appears to remain accessible, but community activity and development updates have dropped substantially since 2021–2022.","heading":"ELE Token and Protocol Status","sources":[{"url":"https://bscscan.com/token/0xacd7b3d9c10e97d0efa418903c0c7669e702e4c0","name":"bscscan.com","type":"other","credibility":3},{"url":"https://coinmarketcap.com/currencies/eleven-finance/","name":"coinmarketcap.com","type":"other","credibility":3},{"url":"https://coinpaprika.com/coin/ele-eleven-finance/","name":"coinpaprika.com","type":"other","credibility":3}],"severity":"medium"},{"content":"ZachXBT, a prominent on-chain investigator, has been cited in connection with Eleven Finance in the context of trust and risk intelligence platforms flagging the protocol as elevated risk following the 2021 exploit. No specific ZachXBT investigation thread or Telegram post attributing a distinct fraud allegation (beyond the exploit) to Eleven Finance is independently verifiable from available public sources. Scam Detector assigned eleven.finance a medium trust score (58.9) and flagged the site for high-risk signals including phishing and spam indicators. The isthiscoinascam.com platform also has an entry for the protocol. These flags appear to be informed primarily by the documented exploit rather than evidence of intentional fraud by the team.","heading":"ZachXBT and Community Flags","sources":[{"url":"https://www.scam-detector.com/validator/eleven-finance-review/","name":"scam-detector.com","type":"other","credibility":3},{"url":"https://isthiscoinascam.com/check/eleven-finance","name":"isthiscoinascam.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2021-04","event":"Eleven Finance publishes April 2021 update detailing vault ecosystem on BSC and Polygon, introducing the ELE token and Bigfoot leveraged yield farming platform.","source":"","date_original":"2021-04-01"},{"date":"2021-06-22","event":"Attacker exploits the emergencyBurn() vulnerability in six Nerve-partnership vaults on BSC. Approximately $4.5–4.8 million is drained via flash loan attack. Attacker bridges proceeds to Ethereum via the Nerve bridge.","source":""},{"date":"2021-06-24","event":"Eleven Finance publishes post-mortem acknowledging developer oversight as root cause. Confirms NRV vaults represented 4% of total TVL and that remaining vaults continued operating. Bigfoot/BigFoot platform taken offline temporarily.","source":""},{"date":"2021-06-25","event":"A self-described whitehat hacker returns 849.2 BNB (~$252,000) to the Eleven Finance deployer address.","source":""},{"date":"2021-07","event":"Eleven Finance publishes full Recovery Plan. Phase 1 distributes 25% of losses (~$1.2M) to affected users. Team announces personal debt assumption and 11RV token structure for Phase 2 compensation.","source":"","date_original":"2021-07-01"},{"date":"2021-07-19","event":"CertiK delivers audit of Eleven Finance lending bank contracts. Exploited vault contracts were not in audit scope.","source":""},{"date":"2021-10-04","event":"Eleven Finance announces full recovery of exploited funds. Phase 2 distribution planned to bring users near 100% compensation in BUSD.","source":""},{"date":"2022","event":"Team reports full compensation repayment to affected Nerve Vault exploit users, approximately 3 months ahead of initial estimate.","source":"","date_original":"2022-01-01"}],"sources_used":[{"url":"https://rekt.news/11-rekt","name":"Eleven Finance — REKT News","type":"news_article","archive_url":"http://web.archive.org/web/20260518003748/https://rekt.news/11-rekt","credibility":2,"archive_timestamp":"2026-05-18T00:37:48+00:00"},{"url":"https://elevenfinance.medium.com/eleven-finance-nrv-vault-exploit-and-loss-of-funds-a-post-mortem-437a79ded743","name":"Eleven Finance NRV Vault Exploit Post-Mortem (Medium)","type":"official","archive_url":"https://web.archive.org/web/20260725191405/https://elevenfinance.medium.com/eleven-finance-nrv-vault-exploit-and-loss-of-funds-a-post-mortem-437a79ded743","credibility":2,"archive_timestamp":"2026-07-25T19:14:05+00:00"},{"url":"https://peckshield.medium.com/eleven-finance-incident-root-cause-analysis-123b5675fa76","name":"PeckShield Incident Root Cause Analysis (Medium)","type":"research","archive_url":"http://web.archive.org/web/20250910051218/https://peckshield.medium.com/eleven-finance-incident-root-cause-analysis-123b5675fa76","credibility":2,"archive_timestamp":"2025-09-10T05:12:18+00:00"},{"url":"https://elevenfinance.medium.com/eleven-finance-recovery-plan-a3869f8242d0","name":"Eleven.Finance Recovery Plan (Medium)","type":"official","archive_url":"http://web.archive.org/web/20250815033104/https://elevenfinance.medium.com/eleven-finance-recovery-plan-a3869f8242d0","credibility":2,"archive_timestamp":"2025-08-15T03:31:04+00:00"},{"url":"https://elevenfinance.medium.com/eleven-finance-a-plan-for-the-return-of-funds-recovered-from-the-nerve-vault-exploit-39a006af20d3","name":"Eleven Finance — Plan for Return of Recovered Funds (Medium)","type":"official","archive_url":"https://web.archive.org/web/20260725191129/https://elevenfinance.medium.com/eleven-finance-a-plan-for-the-return-of-funds-recovered-from-the-nerve-vault-exploit-39a006af20d3","credibility":2,"archive_timestamp":"2026-07-25T19:11:29+00:00"},{"url":"https://skynet.certik.com/projects/elevenfinance","name":"CertiK Skynet — Eleven Finance","type":"research","archive_url":"http://web.archive.org/web/20260518094357/https://skynet.certik.com/projects/elevenfinance","credibility":2,"archive_timestamp":"2026-05-18T09:43:57+00:00"},{"url":"https://bscscan.com/token/0xacd7b3d9c10e97d0efa418903c0c7669e702e4c0","name":"Eleven Finance ELE Token on BscScan","type":"on_chain","archive_url":"https://web.archive.org/web/20260724174914/https://bscscan.com/token/0xacd7b3d9c10e97d0efa418903c0c7669e702e4c0#transactions","credibility":1,"archive_timestamp":"2026-07-24T17:49:14+00:00"},{"url":"https://coinmarketcap.com/currencies/eleven-finance/","name":"CoinMarketCap — Eleven Finance (ELE)","type":"other","archive_url":"https://web.archive.org/web/20260725035512/https://coinmarketcap.com/currencies/eleven-finance/","credibility":2,"archive_timestamp":"2026-07-25T03:55:12+00:00"},{"url":"https://www.scam-detector.com/validator/eleven-finance-review/","name":"Scam Detector — eleven.finance Review","type":"community_report","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://elevenfinance.medium.com/eleven-finance-nerve-vaults-exploit-an-important-community-update-92e508a88d52","name":"Eleven Finance — Nerve Vaults Exploit Community Update (Medium)","type":"official","archive_url":"https://web.archive.org/web/20260725191403/https://elevenfinance.medium.com/eleven-finance-nerve-vaults-exploit-an-important-community-update-92e508a88d52","credibility":2,"archive_timestamp":"2026-07-25T19:14:03+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:56.621999+00:00","updated_at":"2026-08-29T01:35:49.381+00:00"}}