{"investigation":{"slug":"gamma","entity_name":"Gamma Strategies","trust_score":28,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"Gamma Strategies is a DeFi active liquidity management (ALM) protocol built on Uniswap v3 and other concentrated-liquidity DEXs, formerly known as Visor Finance. The protocol suffered a significant flash loan exploit on January 4, 2024, resulting in losses of approximately $6.18 million across four vaults on Arbitrum; the attacker laundered the majority of stolen funds through Tornado Cash. This was not the protocol's first security incident: its predecessor Visor Finance lost approximately $8.2 million to an infinite mint vulnerability in December 2021, leading to a rebrand.","sections":[{"content":"Gamma Strategies is a non-custodial DeFi protocol providing automated, active concentrated liquidity management (ALM) services for decentralized exchanges that implement the Uniswap v3 concentrated-liquidity model. The protocol's core product is a smart contract called a 'Hypervisor,' which manages liquidity positions on behalf of depositors, automating range rebalancing, fee compounding, and LP token issuance. Gamma is deployed across multiple chains including Arbitrum, Ethereum mainnet, and Polygon. The protocol was originally launched as Visor Finance before rebranding to Gamma Strategies following a severe exploit in December 2021. The GAMMA token is distributed to stakers who receive a share of protocol-generated fees. Prior to the January 2024 exploit, Gamma reported annualized revenues of approximately $8.97 million.","heading":"Protocol Overview","sources":[{"url":"https://consensys.io/blog/gamma-strategies-an-innovative-solution-to-the-challenge-of-liquidity-management","name":"consensys.io","type":"other","credibility":3},{"url":"https://defillama.com/protocol/gamma","name":"defillama.com","type":"other","credibility":3},{"url":"https://gammastrategies.medium.com/post-mortem-remediation-plan-9a62f10d90f3","name":"gammastrategies.medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Before rebranding to Gamma Strategies, the protocol operated as Visor Finance. In December 2021, Visor Finance suffered a loss of approximately $8.2 million due to an infinite mint vulnerability — an access control bug that allowed an attacker to mint unbounded shares. The exploit was severe enough to force a rebrand and token migration, with Gamma Strategies announced shortly after the incident. Security researchers at REKT noted that the rebrand occurred with reportedly no original developers or founders remaining from the Visor Finance project, representing a near-complete overhaul of team composition.","heading":"Visor Finance Predecessor Exploit (December 2021)","sources":[{"url":"https://rekt.news/gamma-strategies-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://medium.com/visorfinance/introducing-gamma-an-organization-dedicated-to-funding-active-lp-strategies-and-market-making-bb6617168566","name":"medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On January 4, 2024, at approximately 03:30 UTC, Gamma Strategies was exploited in a flash loan attack targeting stablecoin and liquid staking token (LST) vaults deployed on Arbitrum. The attack was first detected by blockchain security firm PeckShield and initially misattributed to CryptoAlgebra before Gamma confirmed it was their own contracts.\n\nThe root cause was a misconfiguration in Gamma's automation scripts that set the deposit price change threshold far higher than intended. Instead of the intended 2% tolerance, the scripts erroneously configured certain vaults to allow price changes of -50% to +100%. This misconfiguration bypassed four existing deposit protection mechanisms and enabled the attacker to manipulate pool prices using flash loans from Uniswap and Balancer, deposit assets at artificially inflated prices, and receive a disproportionately large quantity of LP tokens that could then be redeemed for more than the deposited value.\n\nFour vaults were specifically targeted: the gDAI-DAI vault on Uniswap (~$2.74M loss), the wstETH-WETH vault on Camelot (~$771K), the USDT-USDC.e vault on Camelot (~$1.357M), and the USDC-USDC.e vault on Ramses (~$1.313M). Total losses across these vaults summed to approximately $6.18 million.\n\nThe attacker's wallet (0x5351536145610aa448a8bf85ba97c71caf31909c on Ethereum and Arbitrum) had been funded via Tornado Cash approximately 2.5 hours prior to the attack. Post-attack, the exploiter bridged stolen stablecoin funds from Arbitrum to Ethereum mainnet using the Stargate bridge, converted assets to ETH, and deposited approximately 1,000 ETH (approximately $2.27 million) into Tornado Cash. A further 1,535 ETH (approximately $3.43 million) was separately accounted for in the attacker's conversion of proceeds.\n\nGamma acknowledged the exploit approximately 90 minutes after it began and immediately paused all vault deposits while leaving existing liquidity under management. The Gamma team sent an on-chain message to the attacker's wallet at 10:54 AM UTC on January 4 offering bug bounty negotiations, but received no substantive response. Despite three prior smart contract security audits, none had identified the misconfiguration vector.","heading":"January 2024 Flash Loan Exploit","sources":[{"url":"https://rekt.news/gamma-strategies-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://www.theblock.co/post/270338/defi-protocol-gamma-strategies-suffers-an-estimated-3-4-million-exploit","name":"theblock.co","type":"other","credibility":3},{"url":"https://gammastrategies.medium.com/post-mortem-remediation-plan-9a62f10d90f3","name":"gammastrategies.medium.com","type":"other","credibility":3},{"url":"https://www.web3isgoinggreat.com/?id=gamma-strategies-exploit","name":"web3isgoinggreat.com","type":"other","credibility":3},{"url":"https://www.vidma.io/blog/gamma-strategies-hack-4-5m-exploit-exposes-defi-vulnerabilities","name":"vidma.io","type":"other","credibility":3},{"url":"https://medium.com/neptune-mutual/how-was-gamma-protocol-exploited-6b63e6c127ba","name":"medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the January 2024 exploit, Gamma Strategies published a post-mortem and remediation plan. The team stated it did not have sufficient reserves to immediately reimburse affected users in full, estimating that total losses of $6.18 million would take approximately 1.73 years to repay through protocol revenue at then-current revenue levels of $8.97 million annualized.\n\nThe remediation plan established a Recovery Pool funded by at least 45% of biweekly protocol revenue distributions, contingent on the team meeting a $2 million annual payroll threshold. An initial seed of 281,500 USDC from a company multisig was designated for the pool. Affected users were listed in a public spreadsheet with a one-week dispute window. GAMMA token stakers were suspended from receiving revenue distributions until the full debt was repaid, with GAMMA token emissions continuing at 1.7 million per year as a substitute.\n\nUser recovery rates were estimated at 25–40% depending on vault and user category. Gamma engaged OpenZeppelin for a third-party smart contract audit before reopening deposits, with an estimated 1–3 week timeline for the audit completion. The protocol also attempted to engage law enforcement in parallel with its on-chain negotiation attempts with the attacker. The attacker's deposit of funds into Tornado Cash prior to any negotiation response strongly indicated no intent to return stolen assets.","heading":"Fund Recovery and User Compensation","sources":[{"url":"https://gammastrategies.medium.com/post-mortem-remediation-plan-9a62f10d90f3","name":"gammastrategies.medium.com","type":"other","credibility":3},{"url":"https://medium.com/gamma-strategies/updates-to-the-remediation-plan-01d0c6604c75","name":"medium.com","type":"other","credibility":3},{"url":"https://www.web3isgoinggreat.com/?id=gamma-strategies-exploit","name":"web3isgoinggreat.com","type":"other","credibility":3},{"url":"https://coinlive.com/news-flash/416064","name":"coinlive.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Gamma Strategies had undergone at least three smart contract security audits prior to the January 2024 exploit, conducted by ConsenSys Diligence and Arbitrary Execution, among others. None of the audits identified the misconfigured price change threshold that enabled the January 2024 attack. The exploit was explicitly attributed by the team to a configuration error in automation scripts rather than a fundamental smart contract code flaw, underscoring that operational security controls are not fully addressed by smart contract code audits alone.\n\nThe protocol's history includes two major security incidents across its operational lifetime under both the Visor Finance and Gamma Strategies names: the December 2021 infinite mint bug ($8.2M) and the January 2024 flash loan exploit ($6.18M). This pattern of repeat incidents at a protocol that had undergone multiple audits raises concerns about the depth of operational security reviews, particularly around configuration management and deployment processes. Following the 2024 exploit, Gamma engaged OpenZeppelin for an additional audit focused specifically on the deposit proxy configuration logic.","heading":"Security Audit History and Pattern of Incidents","sources":[{"url":"https://docs.gamma.xyz/gamma/learn/audits","name":"docs.gamma.xyz","type":"other","credibility":3},{"url":"https://medium.com/gamma-strategies/gammas-v2-smart-contract-audits-completed-by-consensys-diligence-arbitrary-execution-29004e6b63c3","name":"medium.com","type":"other","credibility":3},{"url":"https://rekt.news/gamma-strategies-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://www.vidma.io/blog/gamma-strategies-hack-4-5m-exploit-exposes-defi-vulnerabilities","name":"vidma.io","type":"other","credibility":3}],"severity":"medium"},{"content":"Blockchain analysis confirms that the attacker wallet (0x5351536145610aa448a8bf85ba97c71caf31909c) was funded via Tornado Cash approximately 2.5 hours before the January 4, 2024 attack commenced. The attacker deployed approximately 40 malicious contracts to execute the multi-vault exploit. After draining funds, the attacker used the Stargate bridge to move stolen USDT from Arbitrum to Ethereum mainnet, then converted to ETH, and deposited approximately 1,000 ETH into Tornado Cash — a strong indicator of intentional obfuscation rather than a good-faith disclosure. The use of Tornado Cash for both funding and laundering represents a hallmark of malicious exploiters rather than whitehat researchers. PeckShield, CharlesWang of Paladin, and Gamma Strategies' own security team each provided independent on-chain analysis confirming these fund movements.","heading":"On-Chain Evidence and Attacker Behavior","sources":[{"url":"https://rekt.news/gamma-strategies-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://medium.com/neptune-mutual/how-was-gamma-protocol-exploited-6b63e6c127ba","name":"medium.com","type":"other","credibility":3},{"url":"https://blog.solidityscan.com/gamma-hack-analysis-6c074e61709e/","name":"blog.solidityscan.com","type":"other","credibility":3},{"url":"https://immunebytes.com/blog/list-of-flash-loan-attacks-in-crypto/","name":"immunebytes.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2021-12","event":"Visor Finance (predecessor to Gamma Strategies) suffers approximately $8.2 million loss due to an infinite mint (access control) vulnerability.","source":"","date_original":"2021-12-01"},{"date":"2021-12-03","event":"Visor Finance announces rebrand to Gamma Strategies with a new token and reported team overhaul following the exploit.","source":""},{"date":"2024-01-04","event":"Gamma Strategies exploited via flash loan and price manipulation attack on Arbitrum vaults beginning at approximately 03:30 UTC. Total losses reach approximately $6.18 million across four vaults. PeckShield first alerts on social media.","source":""},{"date":"2024-01-04","event":"Gamma Strategies acknowledges the exploit approximately 90 minutes after it began and pauses all vault deposits across the protocol.","source":""},{"date":"2024-01-04","event":"Attacker bridges stolen USDT from Arbitrum to Ethereum via Stargate bridge and deposits approximately 1,000 ETH into Tornado Cash.","source":""},{"date":"2024-01-04","event":"At 10:54 AM UTC, Gamma Strategies sends on-chain message to attacker's wallet (0x5351536145610aa448a8bf85ba97c71caf31909c) offering bug bounty negotiations. No substantive response is received.","source":""},{"date":"2024-01-05","event":"Gamma Strategies publishes preliminary investigation disclosing root cause: a configuration error in automation scripts set price change thresholds to -50%/+100% instead of the intended 2%.","source":""},{"date":"2024-01-09","event":"Gamma Strategies announces engagement of OpenZeppelin for a third-party smart contract security audit. Deposits remain paused pending audit results, with a 1–3 week estimated timeline.","source":""},{"date":"2024-01-10","event":"Gamma Strategies publishes post-mortem and remediation plan, establishing the Recovery Pool funded by at least 45% of protocol revenues, with affected users listed in a public spreadsheet.","source":""}],"sources_used":[{"url":"https://rekt.news/gamma-strategies-rekt","name":"Gamma Strategies - REKT","type":"news_article","archive_url":"http://web.archive.org/web/20260415171633/https://rekt.news/gamma-strategies-rekt","credibility":2,"archive_timestamp":"2026-04-15T17:16:33+00:00"},{"url":"https://www.theblock.co/post/270338/defi-protocol-gamma-strategies-suffers-an-estimated-3-4-million-exploit","name":"DeFi protocol Gamma Strategies suffers an estimated $3.4 million exploit — The Block","type":"news_article","archive_url":"http://web.archive.org/web/20260214073035/https://www.theblock.co/post/270338/defi-protocol-gamma-strategies-suffers-an-estimated-3-4-million-exploit","credibility":2,"archive_timestamp":"2026-02-14T07:30:35+00:00"},{"url":"https://gammastrategies.medium.com/post-mortem-remediation-plan-9a62f10d90f3","name":"Gamma Strategies Post-Mortem and Remediation Plan — Medium","type":"official","archive_url":"http://web.archive.org/web/20260214073042/https://gammastrategies.medium.com/post-mortem-remediation-plan-9a62f10d90f3","credibility":2,"archive_timestamp":"2026-02-14T07:30:42+00:00"},{"url":"https://www.web3isgoinggreat.com/?id=gamma-strategies-exploit","name":"Gamma Strategies exploited for $6.2 million — Web3 Is Going Great","type":"news_article","archive_url":"http://web.archive.org/web/20260122065518/https://www.web3isgoinggreat.com/?id=gamma-strategies-exploit","credibility":2,"archive_timestamp":"2026-01-22T06:55:18+00:00"},{"url":"https://www.vidma.io/blog/gamma-strategies-hack-4-5m-exploit-exposes-defi-vulnerabilities","name":"Gamma Strategies Hack: $4.5M Exploit Exposes DeFi Vulnerabilities — Vidma","type":"research","archive_url":"http://web.archive.org/web/20260418202826/https://www.vidma.io/blog/gamma-strategies-hack-4-5m-exploit-exposes-defi-vulnerabilities","credibility":2,"archive_timestamp":"2026-04-18T20:28:26+00:00"},{"url":"https://medium.com/neptune-mutual/how-was-gamma-protocol-exploited-6b63e6c127ba","name":"How Was Gamma Protocol Exploited? — Neptune Mutual","type":"research","archive_url":null,"credibility":2,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://medium.com/gamma-strategies/updates-to-the-remediation-plan-01d0c6604c75","name":"Gamma Strategies Updates to the Remediation Plan — Medium","type":"official","archive_url":"https://web.archive.org/web/20260725085336/https://gammastrategies.medium.com/updates-to-the-remediation-plan-01d0c6604c75","credibility":2,"archive_timestamp":"2026-07-25T08:53:36+00:00"},{"url":"https://blog.solidityscan.com/gamma-hack-analysis-6c074e61709e/","name":"Gamma Hack Analysis — SolidityScan","type":"research","archive_url":"http://web.archive.org/web/20260420004517/https://blog.solidityscan.com/gamma-hack-analysis-6c074e61709e/","credibility":2,"archive_timestamp":"2026-04-20T00:45:17+00:00"},{"url":"https://cryptopotato.com/defi-protocol-gamma-strategies-discloses-vulnerability-after-preliminary-investigation/","name":"DeFi Protocol Gamma Strategies Discloses Vulnerability — CryptoPotato","type":"news_article","archive_url":"http://web.archive.org/web/20251010021832/https://cryptopotato.com/defi-protocol-gamma-strategies-discloses-vulnerability-after-preliminary-investigation/","credibility":2,"archive_timestamp":"2025-10-10T02:18:32+00:00"},{"url":"https://defillama.com/protocol/gamma","name":"Gamma TVL, Fees and Revenue — DeFiLlama","type":"on_chain","archive_url":"http://web.archive.org/web/20251014043253/https://defillama.com/protocol/gamma","credibility":2,"archive_timestamp":"2025-10-14T04:32:53+00:00"},{"url":"https://medium.com/gamma-strategies/gammas-v2-smart-contract-audits-completed-by-consensys-diligence-arbitrary-execution-29004e6b63c3","name":"Gamma Strategies v2 Audit by ConsenSys Diligence and Arbitrary Execution — Medium","type":"official","archive_url":null,"credibility":2,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://docs.gamma.xyz/gamma/learn/audits","name":"Gamma Audits Documentation","type":"official","archive_url":"http://web.archive.org/web/20260411204118/https://docs.gamma.xyz/gamma/learn/audits","credibility":2,"archive_timestamp":"2026-04-11T20:41:18+00:00"},{"url":"https://www.coinlive.com/news-flash/416064","name":"Arbitrum's Gamma Protocol to Collaborate with OpenZeppelin for Security Audit — CoinLive","type":"news_article","archive_url":"https://web.archive.org/web/20260724184024/https://www.coinlive.com/news-flash/416064","credibility":2,"archive_timestamp":"2026-07-24T18:40:24+00:00"},{"url":"https://medium.com/visorfinance/introducing-gamma-an-organization-dedicated-to-funding-active-lp-strategies-and-market-making-bb6617168566","name":"Introducing Gamma from Visor Finance — Medium","type":"official","archive_url":null,"credibility":2,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://defiteller.com/gamma-strategies-2024-ethereum-hack-analysis","name":"Gamma Strategies January 2024 Hack Analysis — DeFi Teller","type":"research","archive_url":"http://web.archive.org/web/20260513021801/https://defiteller.com/gamma-strategies-2024-ethereum-hack-analysis","credibility":2,"archive_timestamp":"2026-05-13T02:18:01+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:52.144504+00:00","updated_at":"2026-08-29T01:33:25.737+00:00"}}