{"investigation":{"slug":"foom-cash","entity_name":"FOOM Cash","trust_score":28,"severity_base":null,"score_modifier":0,"confidence":0.72,"status":"published","content_type":"investigation","summary":"FOOM Cash (foom.cash) is a pseudonymous, privacy-focused decentralized lottery protocol built on Ethereum and Base, marketed as an 'upgraded Tornado Cash' using zk-SNARKs cryptography. On February 26, 2026, the protocol suffered a $2.26 million exploit caused by a critical deployment error in its Groth16 trusted setup — a flaw publicly known from an identical exploit on Veil Cash days earlier that the team failed to patch. The team had been silent for approximately three months prior to the attack and was subsequently flagged as a notable risk by AVOID.NET due to compounding concerns: anonymous founders, serious operational negligence, misleading post-incident communications, and unverifiable audit claims.","sections":[{"content":"FOOM Cash is a decentralized lottery protocol operating on Ethereum and Base, using Groth16 zkSNARK cryptography to allow users to participate in lottery draws while breaking the on-chain link between their originating wallet and winnings. The project self-describes as a next-generation privacy protocol and positions itself as an evolution of Tornado Cash. The official website claims the protocol is backed by a treasury of approximately 34,000 ETH, though this claim has not been independently verified through on-chain analytics. The FOOM token has been tradeable since at least January 2024 and has a fully diluted market capitalization of approximately $8.2 million as of early 2026. The token supply is 175 trillion units, and the contract is deployed on Ethereum (0xd0D56273290D339aaF1417D9bfa1bb8cFe8A0933) and Base (0x02300ac24838570012027e0a90d3feccef3c51d2). The team is fully pseudonymous with no publicly verifiable founders or leadership.","heading":"Overview and Background","sources":[{"url":"https://www.coingecko.com/en/coins/foom","name":"coingecko.com","type":"other","credibility":3},{"url":"https://coinmarketcap.com/currencies/foom/","name":"coinmarketcap.com","type":"other","credibility":3},{"url":"https://etherscan.io/token/0xd0D56273290D339aaF1417D9bfa1bb8cFe8A0933","name":"etherscan.io","type":"other","credibility":3},{"url":"https://basescan.org/address/0xdb203504ba1fea79164af3ceffba88c59ee8aafd","name":"basescan.org","type":"other","credibility":3},{"url":"https://foom.cash/","name":"foom.cash","type":"other","credibility":3}],"severity":"medium"},{"content":"On February 26, 2026, FOOM Cash suffered a $2.26 million exploit across its Ethereum and Base deployments. The attack drained 24,283,773,519,600 FOOM tokens. A single malicious transaction on the Base network accounted for approximately $427,000 of losses, with the remainder drained from Ethereum. The root cause was a fatal deployment oversight: during Phase 2 of the Groth16 zkSNARK trusted setup process, a required circuit-specific contribution step was skipped. This left the cryptographic parameters gamma (γ) and delta (δ) set to identical default values — the BN254 G2 generator on both networks — from the day of deployment. This misconfiguration allowed attackers to forge withdrawal proofs without making any legitimate deposits, enabling unlimited unauthorized withdrawals. The vulnerability was identified as a copycat of an identical flaw exploited against Veil Cash, a smaller Base-network privacy protocol, in the days immediately preceding the FOOM Cash attack. A public post-mortem on the Veil Cash vulnerability existed before FOOM Cash was targeted, providing a documented blueprint that the FOOM Cash team did not act upon. Security blockchain firm BlockSec and research platform NomosLabs both identified the flaw as a Groth16 verifier misconfiguration.","heading":"Security Exploit — February 26, 2026","sources":[{"url":"https://cointelegraph.com/news/white-hat-hacker-recovers-2-26m-foom-cash-exploit","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://rekt.news/the-unfinished-proof","name":"rekt.news","type":"other","credibility":3},{"url":"https://phemex.com/news/article/foomcash-loses-226-million-in-copycat-attack-exploiting-zksnark-vulnerability-62810","name":"phemex.com","type":"other","credibility":3},{"url":"https://www.kucoin.com/news/flash/privacy-gaming-platform-foom-cash-suffers-2-26m-loss-in-attack","name":"kucoin.com","type":"other","credibility":3},{"url":"https://www.ainvest.com/news/foom-cash-exploit-2-26m-loss-1-83m-white-hat-recovery-flow-2603/","name":"ainvest.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Prior to the exploit, the FOOM Cash team had published a public bug bounty challenge on Bitcointalk offering approximately $500,000 in FOOM tokens. The stated terms were: 'THE ONLY RULE IS CODE. If your code can take the funds, YOU'VE WON.' The bounty contained no restitution clause, no partial return requirement, and no disclosure deadline. When the exploit occurred on February 26, 2026, a pseudonymous participant known as Duha (also identified under the handle Hao Pham) exploited the Base network contract under these bounty terms. After the exploit, the FOOM Cash team reportedly demanded 90% of funds be returned, creating a public dispute. Duha subsequently entered the EthSecurity Telegram group to publicly defend their position and requested SEAL (Security Alliance) as a mediator. The dispute was ultimately resolved: FOOM Cash awarded Duha a $320,000 bounty and retained Decurity, a blockchain security firm, to recover funds on Ethereum. Decurity was awarded a $100,000 security fee. In total, $1.84 million (approximately 81%) of the stolen $2.26 million was secured. In its March 1, 2026 public statement — issued four days after the exploit — the FOOM Cash team described Duha as having 'identified the vulnerability and moved to secure the funds on Base before malicious actors could strike,' omitting any reference to the public bounty dispute or the initial demand for fund return. Security researchers have characterized this framing as a significant restatement of events.","heading":"White Hat Recovery and Bounty Dispute","sources":[{"url":"https://rekt.news/the-unfinished-proof","name":"rekt.news","type":"other","credibility":3},{"url":"https://www.mexc.com/news/839809","name":"mexc.com","type":"other","credibility":3},{"url":"https://financefeeds.com/foom-cash-recovers-1-84m-after-2-26m-exploit-with-help-from-white-hat-hacker/","name":"financefeeds.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/white-hat-hacker-recovers-2-26m-foom-cash-exploit","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://phemex.com/news/article/white-hat-hacker-recovers-81-of-226m-stolen-from-foom-cash-63670","name":"phemex.com","type":"other","credibility":3}],"severity":"medium"},{"content":"According to analysis published by rekt.news, the FOOM Cash team had been silent on all social channels for approximately three months prior to the February 26, 2026 exploit — from roughly November 2025 through the date of the attack. During this period, the protocol continued to hold millions of dollars in user funds with no public acknowledgment of team activity or protocol maintenance. The team issued no public statement until March 1, 2026, four days after the exploit occurred. This prolonged silence is considered a significant operational red flag, particularly given that the identical Groth16 misconfiguration had been publicly disclosed via the Veil Cash incident in the days before the FOOM Cash attack. The failure to monitor public vulnerability disclosures for a protocol holding millions in user deposits is characterized by multiple security analysts as gross negligence, regardless of intent.","heading":"Team Inactivity and Operational Negligence","sources":[{"url":"https://rekt.news/the-unfinished-proof","name":"rekt.news","type":"other","credibility":3},{"url":"https://www.ainvest.com/news/foom-cash-exploit-2-26m-flow-breakdown-2602/","name":"ainvest.com","type":"other","credibility":3},{"url":"https://tradersunion.com/news/cryptocurrency-news/show/1572208-foom-cash-a-next/","name":"tradersunion.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The official FOOM Cash website states that its smart contracts 'have undergone a comprehensive third-party audit to ensure they are secure and function as intended.' The website also claims the code is 'fully open-source, professionally audited, and continuously tested by a live $500,000 bug bounty.' However, the critical Groth16 trusted setup vulnerability that was exploited was present in the deployed contracts from day one — indicating the claimed audit either did not cover the trusted setup parameters or was ineffective in identifying a fundamental cryptographic configuration error. No named third-party auditor, audit report, or audit date has been publicly identified in relation to FOOM Cash. The gap between stated audit assurances and the actual state of deployed contracts represents a material discrepancy. Users relying on the audit claims as a basis for trust were exposed to a vulnerability that should have been caught by any competent zkSNARK security review.","heading":"Audit Claims vs. Reality","sources":[{"url":"https://rekt.news/the-unfinished-proof","name":"rekt.news","type":"other","credibility":3},{"url":"https://foom.cash/","name":"foom.cash","type":"other","credibility":3},{"url":"https://financefeeds.com/foom-cash-recovers-1-84m-after-2-26m-exploit-with-help-from-white-hat-hacker/","name":"financefeeds.com","type":"other","credibility":3},{"url":"https://www.ainvest.com/news/foom-cash-exploit-2-26m-loss-1-83m-white-hat-recovery-flow-2603/","name":"ainvest.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The FOOM Cash team is fully pseudonymous. No founders, developers, or team members have been publicly identified or verified. This anonymity, while common in privacy-focused protocols, compounds existing concerns when combined with the team's three-month communication blackout, the post-exploit narrative reframing, and unverifiable audit claims. The protocol markets itself as related to the FOOM ecosystem, described as 'a forward-thinking project focused on building a new, privacy-focused internet layer for a future where AGI and humans coexist,' but no verifiable organizational structure, entity registration, or identifiable personnel exist in public records. The treasury claim of approximately 34,000 ETH has not been independently confirmed through on-chain analysis in any published source reviewed during this investigation.","heading":"Anonymity and Transparency Concerns","sources":[{"url":"https://foom.cash/","name":"foom.cash","type":"other","credibility":3},{"url":"https://rekt.news/the-unfinished-proof","name":"rekt.news","type":"other","credibility":3},{"url":"https://www.coingecko.com/en/coins/foom","name":"coingecko.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The FOOM token has a circulating supply of 175 trillion units and a market capitalization of approximately $8.2 million as of early 2026. The CoinGecko listing notes a Market Cap/FDV ratio of 1.0, indicating the entire supply is in circulation. The all-time high of $0.061871 was recorded on October 6, 2025, and the token has traded at extremely low per-unit prices throughout its history. The token experienced notable price pressure following the February 2026 exploit. Security analysts noted that the $1.84 million in recovered funds, held by white hat actors, represented a potential near-term supply overhang that could further pressure price. Analysts also flagged that recovery efforts on Ethereum appeared to function more as front-running operations against the original attacker rather than conventional white-hat coordination, suggesting the on-chain picture is more complex than the official narrative presents.","heading":"Token Economics and Market Risks","sources":[{"url":"https://www.coingecko.com/en/coins/foom","name":"coingecko.com","type":"other","credibility":3},{"url":"https://coinmarketcap.com/currencies/foom/","name":"coinmarketcap.com","type":"other","credibility":3},{"url":"https://www.ainvest.com/news/foom-cash-exploit-2-26m-loss-1-83m-white-hat-recovery-flow-2603/","name":"ainvest.com","type":"other","credibility":3},{"url":"https://coinpaprika.com/coin/foom-foom/","name":"coinpaprika.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2024-01-23","event":"FOOM token records its all-time low price of $0.071455, indicating the token has been tradeable since at least this date.","source":""},{"date":"2025-10-06","event":"FOOM token records its all-time high price of $0.061871 according to CoinGecko.","source":""},{"date":"2025-11","event":"FOOM Cash team social accounts go silent, entering an approximately three-month communication blackout while holding millions in user funds (approximate date per rekt.news analysis).","source":"","date_original":"2025-11-01"},{"date":"2026-02-20","event":"Veil Cash, a smaller Base-network privacy protocol using the same Groth16 setup, is exploited via identical gamma/delta misconfiguration. A public post-mortem is published.","source":""},{"date":"2026-02-26","event":"FOOM Cash exploited for $2.26 million across Ethereum and Base. A single Base transaction drains approximately $427,000. Pseudonymous actor Duha exploits the Base contract under the terms of the publicly posted Bitcointalk bug bounty.","source":""},{"date":"2026-02-26","event":"Duha enters the EthSecurity Telegram group to publicly dispute FOOM Cash's demand for 90% fund return, citing the unconditional bounty terms. SEAL is requested as mediator.","source":""},{"date":"2026-02-27","event":"Security firm Decurity conducts recovery operations on Ethereum, front-running the original attacker to secure approximately $1.84 million of the stolen funds.","source":""},{"date":"2026-03","event":"FOOM Cash issues its first public statement in approximately three months, four days after the exploit. The statement reframes Duha as a white hat who 'moved to secure funds' and makes no mention of the bounty dispute or initial demand for fund return.","source":"","date_original":"2026-03-01"},{"date":"2026-03-03","event":"Final recovery figures confirmed: $1.84 million (81%) recovered. Duha awarded $320,000 bounty; Decurity awarded $100,000 security fee. $420,000 in funds remains unrecovered.","source":""}],"sources_used":[{"url":"https://www.coingecko.com/en/coins/foom","name":"coingecko.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://coinmarketcap.com/currencies/foom/","name":"coinmarketcap.com","type":"other","archive_url":"http://web.archive.org/web/20260420005346/https://coinmarketcap.com/currencies/foom/","credibility":3,"archive_timestamp":"2026-04-20T00:53:46+00:00"},{"url":"https://etherscan.io/token/0xd0D56273290D339aaF1417D9bfa1bb8cFe8A0933","name":"etherscan.io","type":"other","archive_url":"http://web.archive.org/web/20260613033821/https://etherscan.io/token/0xd0D56273290D339aaF1417D9bfa1bb8cFe8A0933","credibility":3,"archive_timestamp":"2026-06-13T03:38:21+00:00"},{"url":"https://basescan.org/address/0xdb203504ba1fea79164af3ceffba88c59ee8aafd","name":"basescan.org","type":"other","archive_url":"https://web.archive.org/web/20260830031645/https://basescan.org/address/0xdb203504ba1fea79164af3ceffba88c59ee8aafd","credibility":3,"archive_timestamp":"2026-08-30T03:16:45+00:00"},{"url":"https://foom.cash/","name":"foom.cash","type":"other","archive_url":"http://web.archive.org/web/20260313144514/https://foom.cash/","credibility":3,"archive_timestamp":"2026-03-13T14:45:14+00:00"},{"url":"https://cointelegraph.com/news/white-hat-hacker-recovers-2-26m-foom-cash-exploit","name":"cointelegraph.com","type":"other","archive_url":"http://web.archive.org/web/20260610062156/https://cointelegraph.com/news/white-hat-hacker-recovers-2-26m-foom-cash-exploit","credibility":3,"archive_timestamp":"2026-06-10T06:21:56+00:00"},{"url":"https://rekt.news/the-unfinished-proof","name":"rekt.news","type":"other","archive_url":"http://web.archive.org/web/20260414185742/https://rekt.news/the-unfinished-proof","credibility":3,"archive_timestamp":"2026-04-14T18:57:42+00:00"},{"url":"https://phemex.com/news/article/foomcash-loses-226-million-in-copycat-attack-exploiting-zksnark-vulnerability-62810","name":"phemex.com","type":"other","archive_url":"http://web.archive.org/web/20260829050313/https://phemex.com/news/article/foomcash-loses-226-million-in-copycat-attack-exploiting-zksnark-vulnerability-62810","credibility":3,"archive_timestamp":"2026-08-29T05:03:13+00:00"},{"url":"https://www.kucoin.com/news/flash/privacy-gaming-platform-foom-cash-suffers-2-26m-loss-in-attack","name":"kucoin.com","type":"other","archive_url":"https://web.archive.org/web/20260829090608/https://www.kucoin.com/news/flash/privacy-gaming-platform-foom-cash-suffers-2-26m-loss-in-attack","credibility":3,"archive_timestamp":"2026-08-29T09:06:08+00:00"},{"url":"https://www.ainvest.com/news/foom-cash-exploit-2-26m-loss-1-83m-white-hat-recovery-flow-2603/","name":"ainvest.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.mexc.com/news/839809","name":"mexc.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://financefeeds.com/foom-cash-recovers-1-84m-after-2-26m-exploit-with-help-from-white-hat-hacker/","name":"financefeeds.com","type":"other","archive_url":"https://web.archive.org/web/20260829225917/https://financefeeds.com/foom-cash-recovers-1-84m-after-2-26m-exploit-with-help-from-white-hat-hacker/","credibility":3,"archive_timestamp":"2026-08-29T22:59:17+00:00"},{"url":"https://phemex.com/news/article/white-hat-hacker-recovers-81-of-226m-stolen-from-foom-cash-63670","name":"phemex.com","type":"other","archive_url":"http://web.archive.org/web/20260308035353/https://phemex.com/news/article/white-hat-hacker-recovers-81-of-226m-stolen-from-foom-cash-63670","credibility":3,"archive_timestamp":"2026-03-08T03:53:53+00:00"},{"url":"https://www.ainvest.com/news/foom-cash-exploit-2-26m-flow-breakdown-2602/","name":"ainvest.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://tradersunion.com/news/cryptocurrency-news/show/1572208-foom-cash-a-next/","name":"tradersunion.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://coinpaprika.com/coin/foom-foom/","name":"coinpaprika.com","type":"other","archive_url":"http://web.archive.org/web/20260829074211/https://coinpaprika.com/coin/foom-foom/","credibility":3,"archive_timestamp":"2026-08-29T07:42:11+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:18.558943+00:00","updated_at":"2026-08-30T03:54:58.657983+00:00"}}