{"investigation":{"slug":"gondi-v3","entity_name":"Gondi V3","trust_score":52,"severity_base":null,"score_modifier":0,"confidence":0.78,"status":"published","content_type":"investigation","summary":"Gondi V3 is a decentralized, non-custodial NFT lending and borrowing protocol on Ethereum developed by Florida Street, which launched in July 2023 and raised a $5.35 million seed round from Hack.vc, Dragonfly Capital, and Pantera Capital. On March 9, 2026, the protocol suffered a smart contract exploit in its newly deployed Purchase Bundler component, resulting in the theft of approximately 78 NFTs valued at roughly $230,000 from users who had granted approvals to the vulnerable contract. The team disabled the affected feature, pledged full restitution using protocol fees, and engaged security firm Blockaid for a post-incident review; platform operations for other functions resumed the following day.","sections":[{"content":"Gondi V3 is a peer-to-peer, non-custodial NFT liquidity protocol built on Ethereum. It is developed by Florida Street, a Web3 software company. The protocol enables users to borrow against blue-chip NFT collateral, lend at fixed rates, refinance loans, and — as of the V3 release — sell and buy NFTs within a single integrated interface. V3 also extended support to ERC-20 token loans and expanded to the HypeEVM network alongside Ethereum Mainnet. As of mid-2025, Gondi reported over $100 million in total value locked, approximately $45 million in outstanding debt, and annualized loan volume above $400 million, making it the largest NFT lending protocol by share of outstanding loans at roughly 54% of market share. The protocol whitelists blue-chip collections including CryptoPunks, Bored Ape Yacht Club, Art Blocks, Doodles, and others. Florida Street raised a $5.35 million seed round co-led by Hack.vc and Foundation Capital, with participation from Dragonfly Capital, Pantera Capital, and 6th Man Ventures. The protocol has been flagged by blockchain investigator ZachXBT in connection with the March 2026 exploit incident.","heading":"Protocol Overview and Background","sources":[{"url":"https://www.coindesk.com/web3/2023/07/11/nft-lender-gondi-goes-live-raises-53m-round-led-by-hackvc","name":"coindesk.com","type":"other","credibility":3},{"url":"https://www.newswire.com/news/gondi-debuts-full-stack-nft-liquidity-marketplace-now-supports-erc-20-22600295","name":"newswire.com","type":"other","credibility":3},{"url":"https://docs.gondi.xyz/","name":"docs.gondi.xyz","type":"other","credibility":3}],"severity":"medium"},{"content":"On March 9, 2026, at approximately 8:12 AM UTC, Gondi V3 was exploited through a logic flaw in its Purchase Bundler smart contract, a component of the Sell & Repay feature that had been deployed on February 20, 2026. The vulnerability consisted of a missing msg.sender ownership check in the contract's buy function: any caller could invoke the function and instruct it to transfer NFTs using approvals that users had previously granted during normal platform interactions. Because the Purchase Bundler did not verify whether the caller was the legitimate owner or borrower of an NFT, an attacker was able to scan on-chain records for users who had granted approvals to the contract without holding an active collateralized loan at the time, and then execute unauthorized transfers of those idle NFTs. The attacker executed approximately 40 transactions, draining an estimated 78 NFTs. Assets under active loan collateral were not affected, as those tokens were escrowed separately. The exploit was deployed on both Ethereum Mainnet and HypeEVM. Security firm Blockaid detected and publicly disclosed the attack shortly after it began, noting that the exploiter had already begun selling stolen assets on secondary NFT marketplaces. The total value of stolen assets was reported at approximately $230,000, with the single largest individual victim losing approximately $108,000 worth of NFTs. Stolen collections included Art Blocks (44 tokens), Doodles (10 tokens), SuperRare pieces, and Beeple Spring Collection works.","heading":"March 2026 Smart Contract Exploit","sources":[{"url":"https://cointelegraph.com/news/nft-platform-gondi-secure-after-230k-hack","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://dev.to/cryip/gondi-nft-lending-platform-hack-a-detailed-report-489c","name":"dev.to","type":"other","credibility":3},{"url":"https://www.theblock.co/post/392909/nft-platform-gondi-moves-users-whole-230000-contract-exploit","name":"theblock.co","type":"other","credibility":3},{"url":"https://blog.autosec.dev/security-events/NFT-lending-agreement-Gondi-was-hacked/","name":"blog.autosec.dev","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the exploit, Gondi immediately disabled the Sell & Repay functionality and issued public guidance advising all users to revoke approvals for the affected Purchase Bundler contract addresses via Revoke.cash. The team confirmed that buying, selling, trading, and active lending functions remained operational and unaffected. Platform operations resumed on March 10, 2026, with the compromised contracts excluded. Gondi engaged Blockaid, a blockchain security firm, and retained an independent auditor who subsequently reviewed the remaining contracts and determined the platform to be safe for continued use. The protocol reached out directly to all users identified as impacted. Community members voluntarily returned several NFTs, including a Doodle, Aluminum Gazer, Lil Pudgy, and Servant of the Muse tokens. Gondi also contacted secondary buyers who had unknowingly purchased stolen NFTs and requested their assistance in returning assets to original owners. The team confirmed that the attacker's wallet still held some of the stolen NFTs while the remainder had been sold. Crypto researcher \"Tinoch\" was credited in press coverage for identifying the largest single victim's losses.","heading":"Incident Response and Remediation","sources":[{"url":"https://cointelegraph.com/news/nft-platform-gondi-secure-after-230k-hack","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://crypto.news/nft-platform-gondi-to-compensate-users-affected-in-250k-smart-contract-exploit/","name":"crypto.news","type":"other","credibility":3},{"url":"https://cryptoadventure.com/gondi-exploit-puts-nft-loan-approvals-and-asset-recovery-in-focus/","name":"cryptoadventure.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Gondi publicly committed to making all affected users whole following the exploit. The protocol stated it would purchase comparable NFTs from the same collections using accumulated protocol fees and distribute them to victims. In an official statement, the team said: \"While not the exact same piece, we believe this is a fair and meaningful resolution and are coordinating directly with each owner.\" For unique one-of-one NFTs that cannot be straightforwardly replaced with comparable items, the protocol indicated it was in ongoing discussions with affected collectors to determine alternative arrangements. Gondi confirmed it had successfully recovered and returned several NFTs through a combination of direct community cooperation and marketplace buybacks. The restitution plan was funded through protocol fee reserves rather than any new token issuance or user dilution. As of the date of known reporting, Gondi had not disclosed the full extent or timeline for completion of all restitution payments.","heading":"Restitution and Compensation","sources":[{"url":"https://www.theblock.co/post/392909/nft-platform-gondi-moves-users-whole-230000-contract-exploit","name":"theblock.co","type":"other","credibility":3},{"url":"https://crypto.news/nft-platform-gondi-to-compensate-users-affected-in-250k-smart-contract-exploit/","name":"crypto.news","type":"other","credibility":3},{"url":"https://www.allcryptocurrencydaily.com/latestnews/2026/03/10/nft-platform-gondi-vows-restitution-after-230000-exploit/","name":"allcryptocurrencydaily.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Gondi V3's smart contracts were audited prior to their primary deployment by multiple security firms and competitive audit platforms. Documented auditors include Zenith (formerly Code4rena), Halborn, 0xQuit, and Qckhp. Code4rena conducted a Gondi Invitational audit in April 2024 with $74,600 in USDC allocated to the contest, followed by a Gondi Mitigation Review in May 2024. Known findings from the mitigation review included issues related to tranche merging affecting loan termination accounting, division-before-multiplication ordering errors in the WithdrawalQueue module, and access control gaps in the distribute() function. Specific audit reports for the V3.1 Purchase Bundler contract update deployed February 20, 2026 — the one that introduced the exploited vulnerability — have not been confirmed as independently reviewed prior to deployment. Gondi's documentation lists a bug bounty program accessible via Discord private ticket, but does not publish specific bounty amounts or severity tiers. The March 2026 exploit underscores the risk that incremental contract updates, even on otherwise audited protocol codebases, can introduce new vulnerabilities if not subject to equivalent scrutiny before deployment.","heading":"Audit History and Security Posture","sources":[{"url":"https://docs.gondi.xyz/gondi-v3/security-and-audits","name":"docs.gondi.xyz","type":"other","credibility":3},{"url":"https://code4rena.com/audits/2024-04-gondi-invitational","name":"code4rena.com","type":"other","credibility":3},{"url":"https://code4rena.com/audits/2024-05-gondi-mitigation-review","name":"code4rena.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The Gondi V3 exploit highlighted a category of smart contract risk that is not unique to Gondi but is particularly acute in protocols that request persistent on-chain approvals as part of routine user interactions. Users who had previously granted approval to the Purchase Bundler contract — even those without active outstanding loans — remained exposed to unauthorized transfers so long as the approval persisted. The attacker specifically targeted users whose approvals were live but who had no active loan, meaning the collateral protection mechanisms did not apply. Security researchers and Gondi's own incident communication cited this as a key risk vector for NFT protocol users generally: approvals granted to contracts for feature access do not expire automatically and can be exploited if the underlying contract is later found to contain logic flaws. Gondi directed users to revoke all approvals to affected contract addresses using Revoke.cash as an immediate mitigation. Users interacting with any protocol that requests broad NFT approvals — including setApprovalForAll calls — are advised by security practitioners to revoke approvals promptly after completing transactions rather than leaving them active indefinitely.","heading":"Smart Contract Approval Risk for Users","sources":[{"url":"https://dev.to/cryip/gondi-nft-lending-platform-hack-a-detailed-report-489c","name":"dev.to","type":"other","credibility":3},{"url":"https://cryptoadventure.com/gondi-exploit-puts-nft-loan-approvals-and-asset-recovery-in-focus/","name":"cryptoadventure.com","type":"other","credibility":3},{"url":"https://blog.autosec.dev/security-events/NFT-lending-agreement-Gondi-was-hacked/","name":"blog.autosec.dev","type":"other","credibility":3}],"severity":"medium"},{"content":"Gondi V3 operates in the NFT-collateralized lending sector, a niche market that has faced significant headwinds following the broader NFT market contraction of 2023-2025. Average NFT loan sizes reportedly dropped approximately 71% year-over-year from approximately $14,000 in May 2024 to approximately $4,000 in 2025. Despite market conditions, Gondi reported growth milestones including the largest on-chain NFT loan ever — a $2.75 million USDC loan secured by a seven-attribute CryptoPunk — and claimed the dominant position in outstanding NFT lending volume. The protocol's expansion to ERC-20 token loans and the HypeEVM chain represented an attempt to broaden its addressable market beyond pure NFT collateral. The March 2026 exploit, while limited in dollar terms relative to major DeFi hacks, caused reputational damage in a market where user trust is a primary retention factor. The protocol's prompt response, restitution pledge, and rapid resumption of other operations were received by most observers as responsible crisis management, though the incident raised questions about deployment review processes for incremental contract updates.","heading":"Market Context and Protocol Standing","sources":[{"url":"https://defillama.com/protocol/gondi","name":"defillama.com","type":"other","credibility":3},{"url":"https://www.nftgators.com/nft-lending-app-gondi-hits-record-34m-in-tvl-following-v3-rollout/","name":"nftgators.com","type":"other","credibility":3},{"url":"https://www.newswire.com/news/gondi-debuts-full-stack-nft-liquidity-marketplace-now-supports-erc-20-22600295","name":"newswire.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2023-07-11","event":"Gondi NFT lending protocol launches publicly on Ethereum; Florida Street announces $5.35 million seed round co-led by Hack.vc and Foundation Capital with participation from Dragonfly Capital and Pantera Capital.","source":""},{"date":"2024-04-08","event":"Code4rena (Zenith) conducts a Gondi Invitational audit with $74,600 USDC in prizes, reviewing V3 smart contracts.","source":""},{"date":"2024-05-14","event":"Code4rena conducts a Gondi Mitigation Review audit, identifying issues including tranche accounting errors, division ordering bugs, and access control gaps; mitigation review period runs through May 24, 2024.","source":""},{"date":"2026-02-20","event":"Gondi deploys an updated version of the Sell & Repay contract containing the Purchase Bundler component with a missing caller-verification check in the buy function.","source":""},{"date":"2026-03-09","event":"At approximately 8:12 AM UTC, an attacker executes approximately 40 transactions exploiting the Purchase Bundler's missing msg.sender check, draining 78 NFTs worth approximately $230,000 from users with active approvals but no outstanding loans. Blockaid detects and publicly discloses the attack. Stolen collections include Art Blocks, Doodles, SuperRare, and Beeple works.","source":""},{"date":"2026-03-09","event":"Gondi disables the Sell & Repay functionality and advises all users to revoke approvals for affected contracts via Revoke.cash. The team confirms active loan collateral was not affected.","source":""},{"date":"2026-03-10","event":"Gondi platform resumes operations for buying, selling, trading, and lending functions with the compromised contract excluded. Blockaid and an independent auditor review remaining contracts and clear them as safe. Gondi pledges restitution via protocol fee-funded comparable NFT purchases.","source":""},{"date":"2026-03-10","event":"Community members return several NFTs voluntarily, including Doodle, Aluminum Gazer, Lil Pudgy, and Servant of the Muse tokens. The largest single victim's loss is identified as approximately $108,000.","source":""}],"sources_used":[{"url":"https://www.coindesk.com/web3/2023/07/11/nft-lender-gondi-goes-live-raises-53m-round-led-by-hackvc","name":"coindesk.com","type":"other","archive_url":"https://web.archive.org/web/20260915160028/https://www.coindesk.com/web3/2023/07/11/nft-lender-gondi-goes-live-raises-53m-round-led-by-hackvc","credibility":3,"archive_timestamp":"2026-09-15T16:00:28+00:00"},{"url":"https://www.newswire.com/news/gondi-debuts-full-stack-nft-liquidity-marketplace-now-supports-erc-20-22600295","name":"newswire.com","type":"other","archive_url":"http://web.archive.org/web/20260508123128/https://www.newswire.com/news/gondi-debuts-full-stack-nft-liquidity-marketplace-now-supports-erc-20-22600295","credibility":3,"archive_timestamp":"2026-05-08T12:31:28+00:00"},{"url":"https://docs.gondi.xyz/","name":"docs.gondi.xyz","type":"other","archive_url":"http://web.archive.org/web/20260721140000/https://docs.gondi.xyz/","credibility":3,"archive_timestamp":"2026-07-21T14:00:00+00:00"},{"url":"https://cointelegraph.com/news/nft-platform-gondi-secure-after-230k-hack","name":"cointelegraph.com","type":"other","archive_url":"http://web.archive.org/web/20260727051834/https://cointelegraph.com/news/nft-platform-gondi-secure-after-230k-hack","credibility":3,"archive_timestamp":"2026-07-27T05:18:34+00:00"},{"url":"https://dev.to/cryip/gondi-nft-lending-platform-hack-a-detailed-report-489c","name":"dev.to","type":"other","archive_url":"https://web.archive.org/web/20260829114525/https://dev.to/cryip/gondi-nft-lending-platform-hack-a-detailed-report-489c","credibility":3,"archive_timestamp":"2026-08-29T11:45:25+00:00"},{"url":"https://www.theblock.co/post/392909/nft-platform-gondi-moves-users-whole-230000-contract-exploit","name":"theblock.co","type":"other","archive_url":"http://web.archive.org/web/20260310111059/https://www.theblock.co/post/392909/nft-platform-gondi-moves-users-whole-230000-contract-exploit","credibility":3,"archive_timestamp":"2026-03-10T11:10:59+00:00"},{"url":"https://blog.autosec.dev/security-events/NFT-lending-agreement-Gondi-was-hacked/","name":"blog.autosec.dev","type":"other","archive_url":"http://web.archive.org/web/20260725125427/http://blog.autosec.dev/security-events/NFT-lending-agreement-Gondi-was-hacked/","credibility":3,"archive_timestamp":"2026-07-25T12:54:27+00:00"},{"url":"https://crypto.news/nft-platform-gondi-to-compensate-users-affected-in-250k-smart-contract-exploit/","name":"crypto.news","type":"other","archive_url":"http://web.archive.org/web/20260412144559/https://crypto.news/nft-platform-gondi-to-compensate-users-affected-in-250k-smart-contract-exploit/","credibility":3,"archive_timestamp":"2026-04-12T14:45:59+00:00"},{"url":"https://cryptoadventure.com/gondi-exploit-puts-nft-loan-approvals-and-asset-recovery-in-focus/","name":"cryptoadventure.com","type":"other","archive_url":"https://web.archive.org/web/20260829030213/https://cryptoadventure.com/gondi-exploit-puts-nft-loan-approvals-and-asset-recovery-in-focus/","credibility":3,"archive_timestamp":"2026-08-29T03:02:13+00:00"},{"url":"https://www.allcryptocurrencydaily.com/latestnews/2026/03/10/nft-platform-gondi-vows-restitution-after-230000-exploit/","name":"allcryptocurrencydaily.com","type":"other","archive_url":"https://web.archive.org/web/20260829083127/https://www.allcryptocurrencydaily.com/latestnews/2026/03/10/nft-platform-gondi-vows-restitution-after-230000-exploit/","credibility":3,"archive_timestamp":"2026-08-29T08:31:27+00:00"},{"url":"https://docs.gondi.xyz/gondi-v3/security-and-audits","name":"docs.gondi.xyz","type":"other","archive_url":"http://web.archive.org/web/20260718181701/https://docs.gondi.xyz/gondi-v3/security-and-audits","credibility":3,"archive_timestamp":"2026-07-18T18:17:01+00:00"},{"url":"https://code4rena.com/audits/2024-04-gondi-invitational","name":"code4rena.com","type":"other","archive_url":"http://web.archive.org/web/20251212062311/https://code4rena.com/audits/2024-04-gondi-invitational","credibility":3,"archive_timestamp":"2025-12-12T06:23:11+00:00"},{"url":"https://code4rena.com/audits/2024-05-gondi-mitigation-review","name":"code4rena.com","type":"other","archive_url":"http://web.archive.org/web/20260514171411/https://code4rena.com/audits/2024-05-gondi-mitigation-review","credibility":3,"archive_timestamp":"2026-05-14T17:14:11+00:00"},{"url":"https://defillama.com/protocol/gondi","name":"defillama.com","type":"other","archive_url":"http://web.archive.org/web/20250913020543/https://defillama.com/protocol/gondi","credibility":3,"archive_timestamp":"2025-09-13T02:05:43+00:00"},{"url":"https://www.nftgators.com/nft-lending-app-gondi-hits-record-34m-in-tvl-following-v3-rollout/","name":"nftgators.com","type":"other","archive_url":"http://web.archive.org/web/20260417032930/https://www.nftgators.com/nft-lending-app-gondi-hits-record-34m-in-tvl-following-v3-rollout/","credibility":3,"archive_timestamp":"2026-04-17T03:29:30+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":true,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:18.347627+00:00","updated_at":"2026-09-15T16:02:39.36364+00:00"}}