{"investigation":{"slug":"fei-rari","entity_name":"Fei Protocol / Rari Capital","trust_score":6,"severity_base":null,"score_modifier":0,"confidence":0.93,"status":"published","content_type":"investigation","summary":"Fei Protocol and Rari Capital merged in December 2021 under Tribe DAO to form a combined DeFi liquidity and lending platform. On April 30, 2022, a reentrancy attack targeting a known flaw in the Compound Finance codebase drained approximately $80 million from seven Rari Fuse lending pools. Tribe DAO ultimately wound down in late 2022 following contentious governance disputes over victim compensation, and Rari Capital's co-founders faced SEC enforcement action in 2024.","sections":[{"content":"Fei Protocol was a decentralized stablecoin protocol that issued the FEI token, pegged to the US dollar. Rari Capital operated Fuse, a permissionless lending platform that allowed users to create and manage isolated money markets on top of a Compound Finance fork. In November 2021, the two projects announced a planned merger. Token holders of both protocols voted in December 2021, with 93% of Rari's RGT holders and 90% of Fei's TRIBE holders approving the union. The merged entity operated under the name Tribe DAO, with Rari's RGT token converted to TRIBE at a rate of 26.7 TRIBE per RGT. At the time of merger, the combined protocols held approximately $2 billion in total value locked (TVL). As part of the merger terms, Fei Protocol assumed Rari Capital's outstanding liabilities from a prior $10.6 million hack that occurred in May 2021.","heading":"Background: Fei Protocol, Rari Capital, and the Tribe DAO Merger","sources":[{"url":"https://www.coindesk.com/tech/2021/12/21/rari-capital-fei-protocol-token-holders-approve-multibillion-dollar-defi-merger","name":"coindesk.com","type":"other","credibility":3},{"url":"https://thedefiant.io/news/defi/rari-capital-fei-merger","name":"thedefiant.io","type":"other","credibility":3}],"severity":"medium"},{"content":"On April 30, 2022, beginning at approximately 09:00 UTC (2:20 AM PT), seven Rari Fuse lending pools — pools 8, 18, 27, 127, 144, 146, and 156 — were exploited in rapid succession. The attacker, operating from address 0x6162759edad730152f0df8115c698a42e666157f, drained approximately $79.75 million across the affected pools. Assets stolen included approximately 6,037 ETH, 20.25 million FEI, 14.28 million DAI, 13.1 million FRAX, 10.06 million USDC, 2.77 million UST, 1.95 million LUSD, and smaller amounts of RAI and USDT. The exploit was identified by blockchain security firm BlockSec as a classic reentrancy vulnerability rooted in a known flaw within the Compound Finance codebase that had previously been used against other Compound forks. A follow-up attack on Rari's Arbitrum deployment occurred on May 1, 2022, resulting in approximately 100 additional ETH in losses.","heading":"The April 2022 Exploit: Reentrancy Attack on Rari Fuse Pools","sources":[{"url":"https://rekt.news/fei-rari-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2022/04/30/defi-lender-rari-capitalfei-loses-80m-in-hack","name":"coindesk.com","type":"other","credibility":3},{"url":"https://www.theblock.co/linked/144511/hackers-steal-80-million-from-rari-capitals-lending-pools","name":"theblock.co","type":"other","credibility":3}],"severity":"medium"},{"content":"The root cause of the exploit was a violation of the checks-effects-interactions (CEI) security pattern within the Fuse protocol's borrow() function. The borrow() function used a low-level .call.value()() call to transfer ETH to borrowers, which permitted arbitrary code execution and consumed unlimited gas. This transfer occurred before the protocol updated its internal accounting records. When the attacker's contract received ETH via this call, its fallback function triggered a reentrant call to exitMarket() — a function that was not protected by Fuse's global reentrancy lock. By calling exitMarket() mid-transaction before borrow state was updated, the attacker was able to withdraw their collateral while the system still had no record of the outstanding borrow. The attacker bootstrapped the attack using a flash loan of 150 million USDC and 50,000 WETH, used these as collateral to borrow ETH, and then repeated the pattern across all seven affected pools. Smart contract auditors noted that this specific reentrancy vector — re-entering via exitMarket() — had been a known Compound codebase issue that was never patched in Rari's fork.","heading":"Technical Analysis: The exitMarket() Reentrancy Vulnerability","sources":[{"url":"https://www.certik.com/resources/blog/6LiXVtPQ8q5AQfqOUPnTOS-revisiting-fei-protocol-incident","name":"certik.com","type":"other","credibility":3},{"url":"https://medium.com/@JackLongarzo/fuse-exploit-post-mortem-76ce18d8974","name":"medium.com","type":"other","credibility":3},{"url":"https://blog.solidityscan.com/rari-capital-re-entrancy-vulnerability-analysis-25df2bbfc803","name":"blog.solidityscan.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following detection of the exploit, Rari Capital paused all borrowing globally across Fuse pools to prevent further losses. Rari developer Jack Longarzo publicly confirmed seven pools were affected and identified a temporary fix involving setting interest rates on affected pools to a flat 3% and consolidating the attacker's account balances to isolate bad debt. Fei Protocol publicly offered the attacker a $10 million bounty with no questions asked in exchange for the return of the remaining stolen funds. The attacker did not respond to the bounty offer. The attacker deposited approximately 5,400 ETH (roughly $15 million at the time) into the Tornado Cash privacy mixer before halting further fund movements, leaving an estimated $62.7 million sitting in the attacker's wallet. The funds were never returned.","heading":"Immediate Response and Bounty Offer","sources":[{"url":"https://cointelegraph.com/news/rari-fuze-hacker-offered-10m-bounty-by-fei-protocol-to-return-80m-loot","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://decrypt.co/99103/fei-protocol-offers-10m-bounty-after-80m-rari-capital-exploit","name":"decrypt.co","type":"other","credibility":3},{"url":"https://rekt.news/fei-rari-rekt","name":"rekt.news","type":"other","credibility":3}],"severity":"medium"},{"content":"Rari Capital suffered an earlier exploit in May 2021 in which approximately $11 million (roughly 60% of all user funds held in its Ethereum pool at the time) was stolen. The attack leveraged a price manipulation vulnerability in Alpha Finance's ibETH contracts that was integrated with Rari's pool. The attacker inflated the value of ibETH tokens within Rari's pool using the ibETH.work() function, then withdrew more ETH than originally deposited. Following that incident, the Rari Capital team chose to forgo their personal token allocations in RGT, collectively worth over $20 million, to reimburse affected users. The assumption of this liability was incorporated into the terms of the December 2021 merger with Fei Protocol.","heading":"Prior Security Incident: May 2021 Hack","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-rari-capital-hack-may-2021","name":"halborn.com","type":"other","credibility":3},{"url":"https://cryptobriefing.com/after-11m-hack-rari-capital-team-reimburse-lost-funds/","name":"cryptobriefing.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/rari-capital-falls-victim-to-11-million-exploit","name":"cointelegraph.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the April 2022 hack, Tribe DAO entered a prolonged governance crisis over whether to compensate hack victims using the DAO's treasury. An initial May 2022 vote passed with approximately 75% support for repaying victims, but subsequent proposals to execute the repayment were vetoed. Multiple additional votes were required over several months. On August 19, 2022, Fei Labs proposed winding down Tribe DAO, citing the challenging macroeconomic environment and the ongoing fallout from the Fuse hack as key factors. A final governance vote held on September 20, 2022 — the last substantive decision in the DAO's history — passed with 99% support and authorized partial repayment of hack victims totaling 12.68 million FEI and 26.61 million DAI. Individual victims received compensation in FEI while DAO victims were compensated in DAI. Tribe DAO then effectively ceased operations, representing what was described by some observers as one of the largest DAO shutdowns in DeFi history.","heading":"Tribe DAO Governance Crisis and Wind-Down","sources":[{"url":"https://cointelegraph.com/news/tribe-dao-votes-in-favor-of-repaying-victims-of-80m-rari-hack","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://decrypt.co/110102/tribe-dao-votes-repay-rari-capital-hack-victims-again","name":"decrypt.co","type":"other","credibility":3},{"url":"https://protos.com/tribe-kills-dao-overrules-vote-to-pay-crypto-debt/","name":"protos.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On September 18, 2024, the U.S. Securities and Exchange Commission announced settled charges against Rari Capital, Inc. and its three co-founders — Jai Bhavnani, Jack Lipstone, and David Lucid — for misleading investors and engaging in unregistered broker activity. The SEC alleged that Rari Capital misled investors by claiming its Earn pools would automatically rebalance into the highest-yield opportunities, when in practice manual intervention was frequently required but not always performed. The SEC further alleged that Rari Capital operated as an unregistered broker through its Fuse platform. The charges covered the period when the platforms collectively held crypto assets worth more than $1 billion at peak. Without admitting or denying the allegations, the parties consented to final judgments entered by the U.S. District Court for the Central District of California on September 19, 2024. Remedies included permanent injunctions, five-year equitable officer-and-director bars against all three co-founders, civil penalties, and disgorgement with prejudgment interest. Monetary amounts ordered were $63,567.51 against Bhavnani, $43,199.98 against Lipstone, and $45,208.92 against Lucid.","heading":"SEC Enforcement Action (2024)","sources":[{"url":"https://www.sec.gov/newsroom/press-releases/2024-138","name":"sec.gov","type":"other","credibility":3},{"url":"https://www.coindesk.com/policy/2024/09/18/defi-lending-platform-rari-capital-settles-sec-charges","name":"coindesk.com","type":"other","credibility":3},{"url":"https://cryptobriefing.com/sec-rari-capital-settlement/","name":"cryptobriefing.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Security researchers at PeckShield and CertiK noted that the reentrancy vector exploited in the April 2022 Fuse attack was not novel — the same class of vulnerability in Compound forks had been identified and exploited previously across multiple protocols. The failure to address this known vulnerability in Rari's codebase, despite the Compound ecosystem's well-documented reentrancy risks, represented a significant failure of due diligence. The specific gap — failing to protect the exitMarket() function from reentrancy despite implementing a global reentrancy lock on other functions — had been highlighted in prior security discussions. The Rari team's post-mortem authored by developer Jack Longarzo confirmed the fix involved replacing .call.value()() with .transfer() to enforce a 2,300 gas limit preventing reentrant callbacks, and correcting the checks-effects-interactions ordering in the borrow function. Rari also announced plans to migrate to Foundry for testing and develop a redesigned Fuse v2 architecture; neither was fully realized as Tribe DAO subsequently wound down.","heading":"Pattern of Risk: Repeated Compound Fork Vulnerability","sources":[{"url":"https://medium.com/@JackLongarzo/fuse-exploit-post-mortem-76ce18d8974","name":"medium.com","type":"other","credibility":3},{"url":"https://www.certik.com/resources/blog/6LiXVtPQ8q5AQfqOUPnTOS-revisiting-fei-protocol-incident","name":"certik.com","type":"other","credibility":3},{"url":"https://securityaffairs.com/130768/hacking/80m-hack-defi-rari-capital-fei-protocol.html","name":"securityaffairs.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2021-05-08","event":"Rari Capital suffers first major exploit: approximately $11 million stolen from its Ethereum pool via a price manipulation attack on Alpha Finance's ibETH contracts. The Rari team foregoes personal token allocations to reimburse users.","source":""},{"date":"2021-11-23","event":"Rari Capital and Fei Protocol announce a planned merger into a unified entity to be called Tribe DAO.","source":""},{"date":"2021-12-21","event":"Token holders of both protocols vote to approve the merger. RGT holders vote 93% in favor; TRIBE holders vote 90% in favor. The combined protocols hold approximately $2 billion TVL.","source":""},{"date":"2022-04-30","event":"Reentrancy attack drains approximately $79.75 million from seven Rari Fuse pools (8, 18, 27, 127, 144, 146, 156) over roughly 35 minutes starting at 09:00 UTC. Attacker address: 0x6162759edad730152f0df8115c698a42e666157f. Borrowing is paused globally.","source":""},{"date":"2022-04-30","event":"Fei Protocol offers attacker a $10 million bounty with no questions asked to return stolen funds. The offer is not accepted.","source":""},{"date":"2022-05","event":"Follow-up attack on Rari's Arbitrum deployment results in approximately 100 ETH in additional losses.","source":"","date_original":"2022-05-01"},{"date":"2022-05","event":"Attacker deposits approximately 5,400 ETH (~$15 million) into Tornado Cash and then halts fund movements, leaving approximately $62.7 million unreturned.","source":"","date_original":"2022-05-01"},{"date":"2022-05","event":"Initial Tribe DAO governance vote on repaying hack victims passes with approximately 75% support, but subsequent execution proposals are vetoed.","source":"","date_original":"2022-05-01"},{"date":"2022-08-19","event":"Fei Labs proposes winding down Tribe DAO, citing the macroeconomic environment and the Fuse hack fallout as key reasons.","source":""},{"date":"2022-09-20","event":"Final Tribe DAO governance vote passes with 99% support, authorizing partial repayment of hack victims: 12.68 million FEI to individual victims and 26.61 million DAI to affected DAOs.","source":""},{"date":"2022-09-20","event":"Tribe DAO ceases active governance operations following the repayment vote, effectively shutting down.","source":""},{"date":"2024-09-18","event":"SEC announces settled charges against Rari Capital, Inc. and co-founders Jai Bhavnani, Jack Lipstone, and David Lucid for misleading investors and acting as unregistered brokers.","source":""},{"date":"2024-09-19","event":"U.S. District Court for the Central District of California enters final judgments against Rari Capital and its co-founders. Five-year officer-and-director bars are imposed on all three founders.","source":""}],"sources_used":[{"url":"https://www.coindesk.com/tech/2021/12/21/rari-capital-fei-protocol-token-holders-approve-multibillion-dollar-defi-merger","name":"coindesk.com","type":"other","credibility":3},{"url":"https://thedefiant.io/news/defi/rari-capital-fei-merger","name":"thedefiant.io","type":"other","credibility":3},{"url":"https://rekt.news/fei-rari-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2022/04/30/defi-lender-rari-capitalfei-loses-80m-in-hack","name":"coindesk.com","type":"other","credibility":3},{"url":"https://www.theblock.co/linked/144511/hackers-steal-80-million-from-rari-capitals-lending-pools","name":"theblock.co","type":"other","credibility":3},{"url":"https://www.certik.com/resources/blog/6LiXVtPQ8q5AQfqOUPnTOS-revisiting-fei-protocol-incident","name":"certik.com","type":"other","credibility":3},{"url":"https://medium.com/@JackLongarzo/fuse-exploit-post-mortem-76ce18d8974","name":"medium.com","type":"other","credibility":3},{"url":"https://blog.solidityscan.com/rari-capital-re-entrancy-vulnerability-analysis-25df2bbfc803","name":"blog.solidityscan.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/rari-fuze-hacker-offered-10m-bounty-by-fei-protocol-to-return-80m-loot","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://decrypt.co/99103/fei-protocol-offers-10m-bounty-after-80m-rari-capital-exploit","name":"decrypt.co","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-rari-capital-hack-may-2021","name":"halborn.com","type":"other","credibility":3},{"url":"https://cryptobriefing.com/after-11m-hack-rari-capital-team-reimburse-lost-funds/","name":"cryptobriefing.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/rari-capital-falls-victim-to-11-million-exploit","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/tribe-dao-votes-in-favor-of-repaying-victims-of-80m-rari-hack","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://decrypt.co/110102/tribe-dao-votes-repay-rari-capital-hack-victims-again","name":"decrypt.co","type":"other","credibility":3},{"url":"https://protos.com/tribe-kills-dao-overrules-vote-to-pay-crypto-debt/","name":"protos.com","type":"other","credibility":3},{"url":"https://www.sec.gov/newsroom/press-releases/2024-138","name":"sec.gov","type":"other","credibility":3},{"url":"https://www.coindesk.com/policy/2024/09/18/defi-lending-platform-rari-capital-settles-sec-charges","name":"coindesk.com","type":"other","credibility":3},{"url":"https://cryptobriefing.com/sec-rari-capital-settlement/","name":"cryptobriefing.com","type":"other","credibility":3},{"url":"https://securityaffairs.com/130768/hacking/80m-hack-defi-rari-capital-fei-protocol.html","name":"securityaffairs.com","type":"other","credibility":3}],"source_tags":[],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-30T18:29:15.475026+00:00","updated_at":"2026-08-29T01:33:54.144+00:00"}}