{"investigation":{"slug":"gempad","entity_name":"GemPad","trust_score":28,"severity_base":null,"score_modifier":0,"confidence":0.78,"status":"published","content_type":"investigation","summary":"GemPad is a multi-chain no-code token launchpad and crowdfunding platform operating primarily on BNB Smart Chain, Ethereum, and Base, launched around 2021. On December 17, 2024, a reentrancy vulnerability in its LP Locker V2 smart contract was exploited across three chains, draining approximately $1.9–$2.2 million in locked liquidity from at least 27 dependent projects. Stolen funds were routed through Tornado Cash, and GemPad issued no public compensation plan for affected projects.","sections":[{"content":"GemPad (ticker: GEMS) is a multi-chain decentralized launchpad and crowdfunding platform that enables project owners to launch tokens without coding skills. The platform supports diverse fundraising models including Seed Rounds, Private Sales, Presales, Fair Launches, Hyper Launches, and Stealth Launches. Its native GEMS token, launched in 2022 on BSC, grants holders whitelist access, staking pool benefits, and membership in the 'Alpha Club' for early project access. GemPad claims to have hosted over 1,000 project launches across Ethereum, BNB Chain, Base, Arbitrum, Polygon, and Solana. Team identities are not publicly disclosed on the platform, and no named founders appear in available public records.","heading":"Platform Overview","sources":[{"url":"https://iq.wiki/wiki/gempad","name":"iq.wiki","type":"other","credibility":3},{"url":"https://www.bitbond.com/resources/gempad-launchpad-review/","name":"bitbond.com","type":"other","credibility":3},{"url":"https://gempad.app/","name":"gempad.app","type":"other","credibility":3}],"severity":"medium"},{"content":"On December 17, 2024, an attacker exploited a reentrancy vulnerability in GemPad's LP Locker V2 smart contract, draining approximately $1.9 million to $2.2 million in locked liquidity across Ethereum, BNB Chain, and Base networks. The attacker used identical contract addresses across all three chains (0xFDd9b0A7e7e16b5Fd48a3D1e242aF362bC81bCaa) and a matching attack contract to methodically drain locked positions. The attack exploited the collectFees function: by deploying a malicious token whose custom transfer callback re-entered the GemPad Locker contract and called the multipleLock function, the attacker was able to repeatedly withdraw locked LP amounts well beyond what was originally deposited. The exploit also leveraged flash loan strategies and Uniswap V2/V3 liquidity manipulations. At least 27 of GemPad's 3,000+ projects using locker services were impacted. Named affected projects include Munch Protocol, AnonFi, Borderless Pay (BPay), Nutcoin Ecosystem, FOMO Network, Alien Base DEX's DUB token, Law of Attraction Coin, and Hemera Trading AI. FOMO Network's native token crashed from $0.004 to $0.00098, BPay declined approximately 75% from $0.004 to $0.001, and Nutcoin had all of its Ethereum liquidity drained, with approximately 400 ETH sent directly to Tornado Cash. The attacker consolidated stolen funds by swapping tokens for ETH and BNB before routing the majority through Tornado Cash, making recovery effectively impossible.","heading":"December 2024 Smart Contract Exploit","sources":[{"url":"https://rekt.news/gempad-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-gempad-hack-december-2024","name":"halborn.com","type":"other","credibility":3},{"url":"https://cryptorank.io/news/feed/07a70-gem-pad-token-launchpad-exploited-2m","name":"cryptorank.io","type":"other","credibility":3},{"url":"https://theholycoins.com/blog/gempad-exploit-up-to-usd2-2-million-lost-to-reentrancy-vulnerability-27-projects-impacted-a","name":"theholycoins.com","type":"other","credibility":3},{"url":"https://howdylittlecrypto.com/gempads-december-crisis-technical-breakdown-of-the-2-2m-smart-contract-breach/","name":"howdylittlecrypto.com","type":"other","credibility":3}],"severity":"medium"},{"content":"GemPad's LP Locker V2 contract had been audited by two separate firms — SolidProof and Cyberscope — prior to the exploit. Cyberscope had recently given the smart contract a high security score. Neither audit detected the reentrancy flaw in the collectFees function. Following the exploit, SolidProof publicly claimed the smart contract had been modified after their audit was completed; GemPad disputed this, asserting no changes were made to the contracts after each audit. The disagreement over contract modification was not publicly resolved with on-chain evidence as of the time of reporting. Security researchers at Halborn and Audita noted that the vulnerability represents a failure both in audit methodology and in GemPad's pre-deployment testing, describing it as 'smart contract security's oldest foe' slipping past multiple review processes. The incident raised broader questions about the reliability of audits from SolidProof and Cyberscope for infrastructure-level contracts.","heading":"Audit Failures and Disputed Responsibility","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-gempad-hack-december-2024","name":"halborn.com","type":"other","credibility":3},{"url":"https://howdylittlecrypto.com/gempads-december-crisis-technical-breakdown-of-the-2-2m-smart-contract-breach/","name":"howdylittlecrypto.com","type":"other","credibility":3},{"url":"https://www.cyberscope.io/audits/gems","name":"cyberscope.io","type":"other","credibility":3},{"url":"https://cryptorank.io/news/feed/07a70-gem-pad-token-launchpad-exploited-2m","name":"cryptorank.io","type":"other","credibility":3}],"severity":"medium"},{"content":"Following confirmation of the exploit, GemPad disabled its Locker service and stated it 'immediately contacted all of our partners and experts in the space to investigate and resolve the situation.' The platform confirmed it was back online with the Locker service offline pending further notice. However, GemPad did not publicly release a detailed compensation or recovery plan for the affected 27 projects. No public timeline was provided for restoring locker features or reimbursing victims. Munch Protocol published a community update on X describing a 'recovery plan' after the incident, indicating that affected projects were left to manage their own communication and recovery. The majority of stolen funds routed through Tornado Cash are considered unrecoverable.","heading":"Post-Exploit Response and Compensation","sources":[{"url":"https://rekt.news/gempad-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://theholycoins.com/blog/gempad-exploit-up-to-usd2-2-million-lost-to-reentrancy-vulnerability-27-projects-impacted-a","name":"theholycoins.com","type":"other","credibility":3},{"url":"https://x.com/MunchToken/status/1869762866066100699","name":"x.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The GEMS token reached an all-time high of approximately $0.07164 and as of 2025 trades approximately 97% below that peak. In 2022 the token declined 78.5% year-over-year. Community reports from early 2023 cited dissatisfaction with decision-making processes and fund allocation, prompting governance discussions, though no formal governance framework was publicly implemented. The team's anonymity and the token's extreme depreciation relative to its all-time high are noted as compounding risk factors by community observers. Third-party trust scoring services including Scam-Detector flagged gempad.app with a score of 34.8/100 and categorized it as 'questionable' based on automated signals including phishing and spam risk indicators.","heading":"GEMS Token Performance and Governance Concerns","sources":[{"url":"https://www.scam-detector.com/validator/gempad-app-review/","name":"scam-detector.com","type":"other","credibility":3},{"url":"https://www.coingecko.com/en/coins/gempad","name":"coingecko.com","type":"other","credibility":3},{"url":"https://coinlaunch.space/launchpads/gempad/","name":"coinlaunch.space","type":"other","credibility":3}],"severity":"medium"},{"content":"The December 2024 exploit demonstrated a systemic risk inherent in GemPad's model: projects that use GemPad's locker infrastructure inherit the security assumptions of that infrastructure. Even though individual project token contracts may be separately audited, a flaw in the shared GemPad Locker contract exposes all dependent projects simultaneously. This infrastructure-level risk is particularly acute for the platform's Locker service, which is used by projects to demonstrate liquidity commitment to their communities. The exploit drained funds from projects that had no individual security vulnerabilities of their own, illustrating that a launchpad's security posture directly affects all projects built on it. Security analysts at Halborn concluded that 'outsourcing security doesn't mean outsourcing responsibility,' a criticism directed at GemPad's reliance on pre-audited contract templates.","heading":"Systemic Risk to Dependent Projects","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-gempad-hack-december-2024","name":"halborn.com","type":"other","credibility":3},{"url":"https://rekt.news/gempad-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://cryptorank.io/news/feed/07a70-gem-pad-token-launchpad-exploited-2m","name":"cryptorank.io","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2021-08","event":"GemPad mainnet launches, initially on BNB Smart Chain as a no-code token launchpad","source":"","date_original":"2021-08-01"},{"date":"2022-04-30","event":"GemPad and the GEMS token listed on CoinMarketCap; GEMS native token launched on BSC","source":""},{"date":"2022-12-31","event":"GEMS token ends year down approximately 78.5%, tracking broader 2022 crypto market decline","source":""},{"date":"2023","event":"Community dissatisfaction reports emerge regarding fund allocation and governance transparency; team initiates community vote","source":"","date_original":"2023-01-01"},{"date":"2024-01-31","event":"GemPad releases 'Evolution Update,' expanding platform to include Linear and OTC Sales","source":""},{"date":"2024-12-17","event":"Attacker (0xFDd9b0A7e7e16b5Fd48a3D1e242aF362bC81bCaa) exploits reentrancy vulnerability in GemPad LP Locker V2 across Ethereum, BNB Chain, and Base; approximately $1.9–$2.2 million drained from 27 projects including Munch Protocol, AnonFi, BPay, Nutcoin, and FOMO Network","source":""},{"date":"2024-12-17","event":"Stolen funds swapped to ETH and BNB; majority routed through Tornado Cash mixer, approximately 400 ETH sent from Nutcoin's drained Ethereum liquidity to Tornado Cash","source":""},{"date":"2024-12-17","event":"GemPad disables Locker service and acknowledges exploit; no compensation plan announced for affected projects","source":""},{"date":"2024-12-18","event":"Munch Protocol posts community update on X describing its own recovery plan following the GemPad incident","source":""}],"sources_used":[{"url":"https://iq.wiki/wiki/gempad","name":"iq.wiki","type":"other","archive_url":"http://web.archive.org/web/20260215012607/https://iq.wiki/wiki/gempad","credibility":3,"archive_timestamp":"2026-02-15T01:26:07+00:00"},{"url":"https://www.bitbond.com/resources/gempad-launchpad-review/","name":"bitbond.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://gempad.app/","name":"gempad.app","type":"other","archive_url":"http://web.archive.org/web/20260210160528/https://gempad.app/","credibility":3,"archive_timestamp":"2026-02-10T16:05:28+00:00"},{"url":"https://rekt.news/gempad-rekt","name":"rekt.news","type":"other","archive_url":"http://web.archive.org/web/20260513155734/https://rekt.news/gempad-rekt","credibility":3,"archive_timestamp":"2026-05-13T15:57:34+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-gempad-hack-december-2024","name":"halborn.com","type":"other","archive_url":"http://web.archive.org/web/20260121120439/https://www.halborn.com/blog/post/explained-the-gempad-hack-december-2024","credibility":3,"archive_timestamp":"2026-01-21T12:04:39+00:00"},{"url":"https://cryptorank.io/news/feed/07a70-gem-pad-token-launchpad-exploited-2m","name":"cryptorank.io","type":"other","archive_url":"https://web.archive.org/web/20260829074826/https://cryptorank.io/news/feed/07a70-gem-pad-token-launchpad-exploited-2m","credibility":3,"archive_timestamp":"2026-08-29T07:48:26+00:00"},{"url":"https://theholycoins.com/blog/gempad-exploit-up-to-usd2-2-million-lost-to-reentrancy-vulnerability-27-projects-impacted-a","name":"theholycoins.com","type":"other","archive_url":"https://web.archive.org/web/20260829082311/https://theholycoins.com/news/gempad-exploit-up-to-usd2-2-million-lost-to-reentrancy-vulnerability-27-projects-impacted-a","credibility":3,"archive_timestamp":"2026-08-29T08:23:11+00:00"},{"url":"https://howdylittlecrypto.com/gempads-december-crisis-technical-breakdown-of-the-2-2m-smart-contract-breach/","name":"howdylittlecrypto.com","type":"other","archive_url":"http://web.archive.org/web/20260412062159/https://howdylittlecrypto.com/gempads-december-crisis-technical-breakdown-of-the-2-2m-smart-contract-breach/","credibility":3,"archive_timestamp":"2026-04-12T06:21:59+00:00"},{"url":"https://www.cyberscope.io/audits/gems","name":"cyberscope.io","type":"other","archive_url":"http://web.archive.org/web/20260517142917/https://www.cyberscope.io/audits/gems","credibility":3,"archive_timestamp":"2026-05-17T14:29:17+00:00"},{"url":"https://x.com/MunchToken/status/1869762866066100699","name":"x.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://www.scam-detector.com/validator/gempad-app-review/","name":"scam-detector.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.coingecko.com/en/coins/gempad","name":"coingecko.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://coinlaunch.space/launchpads/gempad/","name":"coinlaunch.space","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:26.797057+00:00","updated_at":"2026-08-30T03:55:00.550394+00:00"}}