{"investigation":{"slug":"euler-finance","entity_name":"Euler Finance","trust_score":58,"severity_base":null,"score_modifier":0,"confidence":0.88,"status":"published","content_type":"investigation","summary":"Euler Finance is an Ethereum-based non-custodial lending protocol founded in 2020 by Michael Bentley (PhD, Oxford) that pioneered permissionless lending for long-tail ERC-20 assets. On March 13, 2023, the protocol suffered a ~$197 million flash loan exploit — the largest DeFi hack of 2023 — caused by a missing health check in the donateToReserves() function. In an unusual outcome, the attacker, who communicated under the alias 'Jacob,' returned approximately $240 million in assets (including ETH price appreciation) over three weeks following on-chain negotiations, enabling full user restitution. The protocol relaunched as Euler V2 in September 2024 with a modular architecture, 45+ security audits, and subsequently grew TVL to over $1.5 billion by early 2025.","sections":[{"content":"Euler Finance is a permissionless, non-custodial lending protocol deployed on Ethereum mainnet, designed to enable borrowing and lending of a broad range of ERC-20 tokens beyond the curated asset lists of incumbent protocols like Aave and Compound. Euler Labs was incorporated in September 2020 and launched the V1 protocol with key innovations including reactive interest rates, Dutch-auction liquidations, risk-adjusted borrow factors, and protected collateral. The protocol introduced a tiered asset classification system (isolated, cross, collateral tiers) to manage risk for long-tail assets. EUL is the native ERC-20 governance token used for protocol votes and treasury management. The protocol raised $40 million across two rounds: a ~$8 million round in August 2021 backed by Paradigm, and a $32 million Series B in June 2022 led by Haun Ventures with participation from FTX Ventures, Coinbase Ventures, Jump Crypto, Jane Street, and Uniswap Labs Ventures.","heading":"Protocol Overview","sources":[{"url":"https://www.euler.finance/","name":"euler.finance","type":"other","credibility":3},{"url":"https://www.theblock.co/linked/150447/haun-ventures-leads-32-million-round-in-ethereum-protocol-euler","name":"theblock.co","type":"other","credibility":3},{"url":"https://oakresearch.io/en/reports/protocols/euler-v2-eul-comprehensive-overview-modular-lending-ecosystem","name":"oakresearch.io","type":"other","credibility":3}],"severity":"medium"},{"content":"On March 13, 2023, Euler Finance was exploited for approximately $197 million in a multi-transaction flash loan attack, representing the largest single DeFi hack of 2023. The attacker drained funds across four asset categories: approximately $135.8 million in stETH, $33.85 million in USDC, $18.5 million in WBTC, and $8.75 million in DAI. The exploit was executed by using a $20 million DAI flash loan to deposit into Euler, then leveraging the position to a 10x multiple, and exploiting the donateToReserves() function — which lacked a solvency check — to artificially create an undercollateralized position that could be immediately self-liquidated at a profit. Two primary on-chain addresses were involved: a front-running MEV bot (0x5F259D0b76665c337c6104145894F4D1D2758B8c) and the hacker's primary wallet (0xb66cd966670d962C227B3EABA30a872DbFb995db). Euler paused the vulnerable module within hours of the attack. No formal regulatory action by the SEC, CFTC, or DOJ has been publicly announced in connection with this exploit as of May 2026.","heading":"March 2023 Flash Loan Exploit","sources":[{"url":"https://www.chainalysis.com/blog/euler-finance-flash-loan-attack/","name":"chainalysis.com","type":"other","credibility":3},{"url":"https://www.bloomberg.com/news/articles/2023-03-13/defi-s-euler-finance-hit-by-197-million-hack-experts-say","name":"bloomberg.com","type":"other","credibility":3},{"url":"https://therecord.media/cryptocurrency-heist-de-fi-euler","name":"therecord.media","type":"other","credibility":3},{"url":"https://www.coinbase.com/blog/euler-compromise-investigation-part-1-the-exploit","name":"coinbase.com","type":"other","credibility":3},{"url":"https://blocksec.com/blog/euler-finance-incident-the-largest-hack-of-2023","name":"blocksec.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The exploited vulnerability originated from a patch deployed in July 2022. A whitehat researcher named Kankodu reported a 'first depositor' bug through the Immunefi bug bounty program, receiving a $50,000 reward. Euler's fix introduced the donateToReserves() function to bootstrap reserve balances — but this function lacked a health check to verify that a user's position remained solvent after donating. This single missing check enabled the March 2023 attack. The vulnerability existed on-chain for approximately eight months before exploitation, despite a $1 million public bug bounty. Euler had undergone ten separate audit engagements by six firms — Halborn, Solidified, ZK Labs, Certora, Sherlock, and Omniscia — between May 2021 and September 2022. Critically, the audit that covered the donateToReserves() function was only one of the ten engagements; the auditors who reviewed it did not identify the missing solvency check. CEO Michael Bentley publicly acknowledged the protocol had been 'hacked despite 10 audits in 2 years.' Sherlock, the on-chain audit and coverage platform, subsequently acknowledged vulnerability in its coverage and agreed to compensate Euler $4.5 million.","heading":"Vulnerability Root Cause and Audit Failures","sources":[{"url":"https://cryptonews.net/news/security/20684043/","name":"cryptonews.net","type":"other","credibility":3},{"url":"https://www.theblock.co/post/249413/euler-finance-whitehat-unknowingly-caused-200-million-hack","name":"theblock.co","type":"other","credibility":3},{"url":"https://hacken.io/discover/euler-finance-hack/","name":"hacken.io","type":"other","credibility":3},{"url":"https://www.cyfrin.io/blog/how-did-the-euler-finance-hack-happen-hack-analysis","name":"cyfrin.io","type":"other","credibility":3},{"url":"https://euler.finance/blog/securing-euler","name":"euler.finance","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the exploit, Euler Labs issued an on-chain ultimatum to the attacker, offering a $1 million bounty for information leading to the attacker's identity and demanding return of 90% of funds within 24 hours to avoid legal escalation. The negotiation period lasted approximately three weeks. On March 18, 2023, the attacker returned 3,000 ETH (~$5.3 million). On March 25, the attacker returned 51,000 ETH (~$90 million). Between March 25 and 28, additional tranches including 7,000 ETH and $10 million in DAI were sent. By April 3, 2023, the final tranche was returned, with Euler announcing full recovery of all recoverable funds. Due to ETH price appreciation during negotiations, the total returned was approximately $240 million — exceeding the original $197 million stolen. The attacker communicated using the alias 'Jacob' and sent an on-chain apology reading: 'I fucked up. I didn't want to, but I messed with others' money, others' jobs, others' lives. I really fucked up. I'm sorry.' Euler opened user redemptions on April 12, 2023, allowing affected depositors to claim their share of recovered assets. No user suffered a permanent net loss of funds.","heading":"Fund Recovery and On-Chain Negotiations","sources":[{"url":"https://www.euler.finance/blog/war-peace-behind-the-scenes-of-eulers-240m-exploit-recovery","name":"euler.finance","type":"other","credibility":3},{"url":"https://fortune.com/crypto/2023/04/06/how-an-elite-team-pressured-a-hacker-to-return-200m-he-stole-from-defi-platorm-euler/","name":"fortune.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/tech/2023/03/28/hacker-behind-200m-euler-attack-apologizes-returns-millions-in-ether-dai-to-protocol","name":"coindesk.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2023/04/12/euler-finance-lets-users-redeem-recovered-funds-following-200m-theft","name":"coindesk.com","type":"other","credibility":3},{"url":"https://decrypt.co/125373/euler-finance-exploiter-returns-recoverable-funds-200m-hack","name":"decrypt.co","type":"other","credibility":3}],"severity":"medium"},{"content":"The attacker's true identity was never publicly confirmed. Initial blockchain forensics flagged that the exploiter's wallet had sent 100 ETH to an address previously attributed by the U.S. Treasury's Office of Foreign Assets Control to North Korea's Lazarus Group in connection with the Ronin bridge hack. This prompted early speculation of state-sponsored involvement. However, subsequent investigation — including a notable incident in which Lazarus Group operatives appeared to attempt a phishing attack against the Euler exploiter's wallet — was characterized by Chainalysis and independent researchers as a likely false flag or coincidence rather than evidence of affiliation. Euler's own post-mortem noted the attacker appeared to lack sophisticated anonymization tradecraft, suggesting an individual rather than an organized criminal group. The alias 'Jacob' was used in encrypted communications, but no identity was publicly confirmed. The case was investigated by cybersecurity firms and on-chain analytics providers; no arrest or indictment has been publicly announced as of May 2026.","heading":"Attacker Identity and Lazarus Group Investigation","sources":[{"url":"https://www.chainalysis.com/blog/euler-finance-flash-loan-attack/","name":"chainalysis.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2023/03/21/hacker-vs-hacker-north-koreans-attempt-to-phish-euler-exploiter-of-200m-in-crypto-experts-say","name":"coindesk.com","type":"other","credibility":3},{"url":"https://cryptopotato.com/interaction-detected-between-wallet-tied-to-euler-finance-exploiter-and-north-koreas-lazarus-group/","name":"cryptopotato.com","type":"other","credibility":3},{"url":"https://www.euler.finance/blog/war-peace-behind-the-scenes-of-eulers-240m-exploit-recovery","name":"euler.finance","type":"other","credibility":3}],"severity":"medium"},{"content":"One month after the attack, Seraphim Czecker, Head of Risk at Euler Labs, publicly announced his resignation, stating there was 'not much I can help them with at this stage.' CEO Michael Bentley disputed the characterization, stating the resignation had been planned prior to the hack. Euler Labs chose not to shut down operations after the exploit, instead committing to a full protocol redesign. The team rebuilt Euler from the ground up over approximately 18 months. In January 2026, Michael Bentley announced he would step down from the CEO role to take a more advisory and product-focused position, citing a desire not to 'stand in the way' of the protocol's momentum. Jonathan Han, formerly SVP of Business Development at crypto intelligence firm The Tie, was named as the incoming CEO with a stated focus on institutional, fintech, and retail user growth.","heading":"Organizational Response and Personnel Changes","sources":[{"url":"https://blockworks.co/news/euler-labs-risk-head-resigns/","name":"blockworks.co","type":"other","credibility":3},{"url":"https://cryptoslate.com/eulers-head-of-risk-resigns-saying-not-much-i-can-help-them-with/","name":"cryptoslate.com","type":"other","credibility":3},{"url":"https://thedefiant.io/news/people/euler-ceo-michael-bentley-steps-down","name":"thedefiant.io","type":"other","credibility":3}],"severity":"medium"},{"content":"Euler V2 launched on Ethereum mainnet in September 2024, approximately 18 months after the V1 protocol went offline. The redesigned architecture is built around the Euler Vault Kit (EVK), which allows developers to create customizable ERC-4626-compliant lending vaults, and the Ethereum Vault Connector (EVC), which acts as an interoperability layer enabling cross-vault collateral recognition. The V2 model moved away from the monolithic single-market design of V1 toward a modular system where each vault functions as an independently configurable lending protocol. Prior to the V2 launch, Euler underwent 45 audit engagements by 13 security firms, a $1.25 million code audit competition with Cantina (with no high or medium severity findings), and a $3.5 million Capture The Flag challenge with Hats Finance. The protocol also launched EulerSwap, an integrated DEX combining lending and swapping via Uniswap v4 compatibility. From its V2 launch, TVL grew from approximately $4.5 million to over $1.5 billion by early 2025, surpassing the V1 historical TVL peak of $323 million. In April 2026, Euler proactively froze markets exposed to rsETH collateral following the KelpDAO bridge exploit ($292 million), demonstrating improved risk response.","heading":"Euler V2 Relaunch and Security Overhaul","sources":[{"url":"https://www.theblock.co/post/314655/euler-launches-v2-modular-defi-lending-protocol-following-hack","name":"theblock.co","type":"other","credibility":3},{"url":"https://www.euler.finance/blog/euler-v2-the-new-modular-age-of-defi","name":"euler.finance","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2025/03/14/euler-looks-to-build-on-v2-s-defi-lending-comeback-story","name":"coindesk.com","type":"other","credibility":3},{"url":"https://blockworks.com/news/euler-finance-exploit-comeback","name":"blockworks.com","type":"other","credibility":3},{"url":"https://defillama.com/protocol/euler-v2","name":"defillama.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Euler V2's modular architecture introduces new composability surface area that may present risks not yet fully characterized by existing security literature. The protocol's rapid TVL growth to over $1.5 billion within months of relaunch may outpace the maturation of its risk monitoring and governance infrastructure. The April 2026 KelpDAO incident demonstrated that Euler remains exposed to systemic risk from third-party collateral assets, even when individual smart contract code is sound. The EUL governance token remains subject to market volatility; the token reached an all-time high of $15.81 but was trading at approximately $1.19 as of May 2026. The protocol's investor base included FTX Ventures, which subsequently became insolvent; the direct impact of this on Euler's governance or treasury was not materially disclosed. The protocol has not been subject to any known SEC, CFTC, or DOJ enforcement action as of May 2026.","heading":"Current Risk Considerations","sources":[{"url":"https://coinmarketcap.com/currencies/euler-finance/","name":"coinmarketcap.com","type":"other","credibility":3},{"url":"https://defillama.com/protocol/euler-v2","name":"defillama.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/markets/2026/04/20/defi-tvl-drops-more-than-usd13-billion-in-two-days-following-kelp-dao-hack","name":"coindesk.com","type":"other","credibility":3},{"url":"https://www.euler.finance/risk-disclosures","name":"euler.finance","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2020-09","event":"Euler Labs incorporated; development of permissionless DeFi lending protocol begins.","source":"","date_original":"2020-09-01"},{"date":"2021-08-25","event":"Euler raises ~$8 million in Series A funding, with Paradigm as a lead investor.","source":""},{"date":"2021-05","event":"First audit engagements begin; Halborn, Solidified, and other firms begin reviewing Euler smart contracts.","source":"","date_original":"2021-05-01"},{"date":"2022-06-07","event":"Euler raises $32 million Series B led by Haun Ventures; investors include FTX Ventures, Coinbase Ventures, Jump Crypto, and Jane Street.","source":""},{"date":"2022-07","event":"Whitehat researcher Kankodu reports 'first depositor' bug via Immunefi bug bounty; awarded $50,000. Euler deploys fix introducing donateToReserves() function.","source":"","date_original":"2022-07-01"},{"date":"2022-09","event":"WatchPug audit of donateToReserves() function conducted; missing solvency check not identified. Vulnerable code deployed on mainnet.","source":"","date_original":"2022-09-01"},{"date":"2023-03-13","event":"Flash loan exploit drains ~$197 million from Euler Finance across stETH, USDC, WBTC, and DAI. Euler pauses vulnerable module same day. Lazarus Group wallet interaction flagged by on-chain analysts.","source":""},{"date":"2023-03-14","event":"Euler offers $1 million bounty for information on attacker identity. On-chain ultimatum demands return of 90% of funds within 24 hours.","source":""},{"date":"2023-03-18","event":"Attacker returns first tranche: 3,000 ETH (~$5.3 million). On-chain negotiations continue.","source":""},{"date":"2023-03-21","event":"Lazarus Group operatives allegedly attempt phishing attack against the Euler exploiter's wallet; investigators treat this as a false flag, not evidence of affiliation.","source":""},{"date":"2023-03-25","event":"Attacker returns 51,000 ETH (~$90 million) in major tranche.","source":""},{"date":"2023-03-28","event":"Attacker returns additional 7,000 ETH and $10 million DAI. On-chain apology sent by exploiter using alias 'Jacob.'","source":""},{"date":"2023-04-03","event":"Final tranche of stolen funds returned. Total recovered: ~$240 million (exceeding original $197 million due to ETH price appreciation).","source":""},{"date":"2023-04-12","event":"Euler opens user redemptions, allowing affected depositors to claim recovered funds. No net user losses recorded.","source":""},{"date":"2023-04-19","event":"Seraphim Czecker, Head of Risk at Euler Labs, publicly resigns approximately one month after the hack.","source":""},{"date":"2024-02","event":"Euler V2 architecture publicly announced; development and security audit program underway.","source":"","date_original":"2024-02-01"},{"date":"2024-09","event":"Euler V2 launches on Ethereum mainnet following 45 audit engagements across 13 firms, a $1.25M Cantina code competition, and a $3.5M CTF challenge. TVL begins rapid growth from ~$4.5 million.","source":"","date_original":"2024-09-01"},{"date":"2025-03","event":"Euler V2 TVL surpasses $1 billion, exceeding the V1 historical peak of $323 million. EUL token rises ~70% in Q1 2025.","source":"","date_original":"2025-03-01"},{"date":"2026-01-12","event":"Co-founder and CEO Michael Bentley announces step-down from CEO role; Jonathan Han named incoming CEO.","source":""},{"date":"2026-04-19","event":"KelpDAO bridge exploit ($292 million). Euler proactively freezes rsETH-collateralized lending markets to limit protocol exposure.","source":""}],"sources_used":[{"url":"https://www.euler.finance/","name":"euler.finance","type":"other","credibility":3},{"url":"https://www.theblock.co/linked/150447/haun-ventures-leads-32-million-round-in-ethereum-protocol-euler","name":"theblock.co","type":"other","credibility":3},{"url":"https://oakresearch.io/en/reports/protocols/euler-v2-eul-comprehensive-overview-modular-lending-ecosystem","name":"oakresearch.io","type":"other","credibility":3},{"url":"https://www.chainalysis.com/blog/euler-finance-flash-loan-attack/","name":"chainalysis.com","type":"other","credibility":3},{"url":"https://www.bloomberg.com/news/articles/2023-03-13/defi-s-euler-finance-hit-by-197-million-hack-experts-say","name":"bloomberg.com","type":"other","credibility":3},{"url":"https://therecord.media/cryptocurrency-heist-de-fi-euler","name":"therecord.media","type":"other","credibility":3},{"url":"https://www.coinbase.com/blog/euler-compromise-investigation-part-1-the-exploit","name":"coinbase.com","type":"other","credibility":3},{"url":"https://blocksec.com/blog/euler-finance-incident-the-largest-hack-of-2023","name":"blocksec.com","type":"other","credibility":3},{"url":"https://cryptonews.net/news/security/20684043/","name":"cryptonews.net","type":"other","credibility":3},{"url":"https://www.theblock.co/post/249413/euler-finance-whitehat-unknowingly-caused-200-million-hack","name":"theblock.co","type":"other","credibility":3},{"url":"https://hacken.io/discover/euler-finance-hack/","name":"hacken.io","type":"other","credibility":3},{"url":"https://www.cyfrin.io/blog/how-did-the-euler-finance-hack-happen-hack-analysis","name":"cyfrin.io","type":"other","credibility":3},{"url":"https://euler.finance/blog/securing-euler","name":"euler.finance","type":"other","credibility":3},{"url":"https://www.euler.finance/blog/war-peace-behind-the-scenes-of-eulers-240m-exploit-recovery","name":"euler.finance","type":"other","credibility":3},{"url":"https://fortune.com/crypto/2023/04/06/how-an-elite-team-pressured-a-hacker-to-return-200m-he-stole-from-defi-platorm-euler/","name":"fortune.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/tech/2023/03/28/hacker-behind-200m-euler-attack-apologizes-returns-millions-in-ether-dai-to-protocol","name":"coindesk.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2023/04/12/euler-finance-lets-users-redeem-recovered-funds-following-200m-theft","name":"coindesk.com","type":"other","credibility":3},{"url":"https://decrypt.co/125373/euler-finance-exploiter-returns-recoverable-funds-200m-hack","name":"decrypt.co","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2023/03/21/hacker-vs-hacker-north-koreans-attempt-to-phish-euler-exploiter-of-200m-in-crypto-experts-say","name":"coindesk.com","type":"other","credibility":3},{"url":"https://cryptopotato.com/interaction-detected-between-wallet-tied-to-euler-finance-exploiter-and-north-koreas-lazarus-group/","name":"cryptopotato.com","type":"other","credibility":3},{"url":"https://blockworks.co/news/euler-labs-risk-head-resigns/","name":"blockworks.co","type":"other","credibility":3},{"url":"https://cryptoslate.com/eulers-head-of-risk-resigns-saying-not-much-i-can-help-them-with/","name":"cryptoslate.com","type":"other","credibility":3},{"url":"https://thedefiant.io/news/people/euler-ceo-michael-bentley-steps-down","name":"thedefiant.io","type":"other","credibility":3},{"url":"https://www.theblock.co/post/314655/euler-launches-v2-modular-defi-lending-protocol-following-hack","name":"theblock.co","type":"other","credibility":3},{"url":"https://www.euler.finance/blog/euler-v2-the-new-modular-age-of-defi","name":"euler.finance","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2025/03/14/euler-looks-to-build-on-v2-s-defi-lending-comeback-story","name":"coindesk.com","type":"other","credibility":3},{"url":"https://blockworks.com/news/euler-finance-exploit-comeback","name":"blockworks.com","type":"other","credibility":3},{"url":"https://defillama.com/protocol/euler-v2","name":"defillama.com","type":"other","credibility":3},{"url":"https://coinmarketcap.com/currencies/euler-finance/","name":"coinmarketcap.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/markets/2026/04/20/defi-tvl-drops-more-than-usd13-billion-in-two-days-following-kelp-dao-hack","name":"coindesk.com","type":"other","credibility":3},{"url":"https://www.euler.finance/risk-disclosures","name":"euler.finance","type":"other","credibility":3}],"source_tags":[],"addresses":[],"reviewed":true,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-30T18:25:09.831791+00:00","updated_at":"2026-08-29T01:35:17.797+00:00"}}