{"investigation":{"slug":"glori-finance","entity_name":"Glori Finance","trust_score":2,"severity_base":null,"score_modifier":0,"confidence":1,"status":"published","content_type":"investigation","summary":"Glori Finance was an alleged DeFi lending protocol deployed on the Arbitrum network in early 2024, operating as a Compound V2 fork with approximately $1.4 million in total value locked (TVL) at the time of its exposure. On April 14, 2024, blockchain investigator ZachXBT identified that the top GLORI token holders had seeded liquidity using funds stolen from prior scams — specifically the Crolend, Hash DAO, and HellHoundFi frauds — linking Glori Finance to a serial scam ring responsible for over $20 million in cumulative losses. Following ZachXBT's public disclosure, the Glori Finance X account was deactivated and the protocol's website went offline, consistent with an exit scam.","sections":[{"content":"Glori Finance presented itself as an algorithmic, autonomous, and cross-chain lending protocol built on perpetual DEX (perpDEX) LP tokens, operating on the Arbitrum network. The protocol's native token was GLORI. Its website domain was glori.finance and it maintained a Twitter/X presence at @GloriFinance with approximately 3,200 followers prior to deactivation. The protocol was a fork of Compound V2, a widely cloned open-source lending framework. At the time ZachXBT flagged the project in April 2024, Glori Finance held approximately $1.4 million in total value locked. No independently verified information about the founding team's identities has been confirmed; team members are alleged to have used falsified KYC documentation to create the appearance of legitimacy.","heading":"Protocol Overview","sources":[],"severity":"medium"},{"content":"On April 14, 2024, on-chain investigator ZachXBT published findings identifying Glori Finance as part of an active serial scam operation. ZachXBT traced the wallets of the top GLORI token holders and found that the liquidity provided to the protocol had originated from funds stolen in earlier schemes: specifically the Crolend, Hash DAO, and HellHoundFi frauds. The same wallet cluster was simultaneously funding two other alleged scam protocols — Leaper Finance on the Blast network and Zebra DAO on the Base network — indicating coordinated multi-chain deployment. ZachXBT stated: 'In the past they let the TVL grow to 7 figs before stealing all of users funds deposited to the protocol and falsify KYC documents + use low tier audit firms.' He urged users to withdraw funds from Glori Finance immediately. Shortly after the investigation was posted publicly, the Leaper Finance team taunted ZachXBT on X, writing 'Nice work! My comrades here at Lazarus fear you yet admire you!' — referencing the North Korean Lazarus Group, though no verified attribution to Lazarus Group has been confirmed by law enforcement.","heading":"ZachXBT Investigation and Warning","sources":[],"severity":"medium"},{"content":"ZachXBT's investigation placed Glori Finance within a broader pattern of serial exit scams attributed to the same group. The identified prior operations by this alleged group include: Solfire ($4.8 million, January 2022), Kokomo Finance ($4–5.5 million, March 2023), Magnate Finance ($6.5 million), Lendora (amount unspecified), Crolend, Hash DAO, and HellHoundFi. The concurrent operations at the time of the April 2024 exposure were Leaper Finance (Blast), Zebra DAO (Base), and Glori Finance (Arbitrum). All identified fraudulent protocols were Compound V2 forks. The group is alleged to have operated across Base, Solana, Scroll, Optimism, Arbitrum, Ethereum, and Avalanche. Total cumulative losses attributed to the group exceed $20 million, with some estimates citing over $26.4 million. The group's laundering methodology involved recycling stolen funds as seed liquidity into the next protocol to attract retail depositors before executing another exit.","heading":"Serial Scam Ring Connections","sources":[],"severity":"medium"},{"content":"According to ZachXBT's documented findings, this scam group followed a consistent operational template. They deployed Compound V2 forks on emerging or high-activity L2 networks, submitted falsified KYC documentation to confer apparent legitimacy, and engaged low-tier or less-scrutinized audit firms to generate audit reports for marketing purposes. They then allowed TVL to accumulate into seven figures before executing the exit. In an alleged tactical evolution noted by investigators, the group reportedly engaged BlockSec — a more reputable security firm — to audit at least one of their concurrent protocols, suggesting an attempt to circumvent tightening due diligence practices in the ecosystem. However, the specific protocol audited by BlockSec in this context was not confirmed as Glori Finance specifically across all sources reviewed. After ZachXBT's April 2024 disclosure, the scammers briefly engaged publicly on X before deactivating all accounts and taking websites offline.","heading":"Modus Operandi and Tactical Evolution","sources":[],"severity":"medium"},{"content":"Following ZachXBT's April 14, 2024 public warning, the Glori Finance X account (@GloriFinance) was deactivated and the protocol's website (glori.finance) went offline. The pattern was mirrored simultaneously by Leaper Finance and Zebra DAO. No team members have been publicly identified by name with verified evidence. No law enforcement action specifically naming Glori Finance has been confirmed in publicly available records as of the time of this investigation. Funds held in the protocol at the time of shutdown — approximately $1.4 million — are alleged to have been stolen or rendered inaccessible to depositors, though the precise mechanics of fund extraction from Glori Finance specifically have not been documented in sources reviewed. No specific attacker wallet addresses for the Glori Finance exit have been independently confirmed in available public sources; the on-chain tracing documented by ZachXBT connected the seed liquidity wallets to prior frauds rather than isolating a distinct exit transaction.","heading":"Exit and Aftermath","sources":[],"severity":"medium"}],"timeline":[{"date":"2022","event":"Solfire exit scam ($4.8 million) — alleged earliest confirmed operation by the same scam group","source":"","source_url":"https://cryptopotato.com/warning-malicious-group-threatening-layer-2-networks-exposed/","date_original":"2022-01-01"},{"date":"2023-03","event":"Kokomo Finance exit scam ($4–5.5 million) — alleged second major operation by the same group","source":"","source_url":"https://bitcoinist.com/kokomo-finance-pulls-exit-scam/","date_original":"2023-03-01"},{"date":"2023-08","event":"Magnate Finance exit scam ($6.5 million) — alleged operation by same group","source":"","source_url":"https://coingape.com/magnate-finance-deployer-exploited-17-mln-from-multiple-rug-pulls/","date_original":"2023-08-01"},{"date":"2024","event":"Crolend, Hash DAO, and HellHoundFi scams executed; stolen funds later traced as seed liquidity for Glori Finance","source":"","source_url":"https://www.coinlive.com/news/zachxbt-sounds-alarm-on-scammers-associated-with-defi-protocol","date_original":"2024-01-01"},{"date":"2024-04-14","event":"ZachXBT publishes investigation on X identifying Glori Finance (Arbitrum), Leaper Finance (Blast), and Zebra DAO (Base) as simultaneous exit scams operated by the same serial fraud group; advises users to withdraw immediately","source":"","source_url":"https://cryptopotato.com/warning-malicious-group-threatening-layer-2-networks-exposed/"},{"date":"2024-04-14","event":"Leaper Finance team taunts ZachXBT on X referencing Lazarus Group before deactivating accounts; Glori Finance X account and website go offline","source":"","source_url":"https://beincrypto.com/fraud-ethereum-layer-2-base-blast-arbitrum/"}],"sources_used":[],"source_tags":["zachxbt"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet","created_at":"2026-05-04T16:04:58.549469+00:00","updated_at":"2026-08-29T01:35:01.999+00:00"}}