{"investigation":{"slug":"grim-finance","entity_name":"Grim Finance","trust_score":8,"severity_base":null,"score_modifier":0,"confidence":0.92,"status":"published","content_type":"investigation","summary":"Grim Finance was a Fantom-based DeFi yield optimizer (fork of Beefy Finance) that suffered a devastating reentrancy exploit on December 19, 2021, resulting in approximately $30 million in user funds stolen. The vulnerability — a missing reentrancy guard in the depositFor() function — had existed in an audited codebase and was classified by security researchers as an entirely preventable, well-understood attack class. The protocol has since collapsed to a near-zero TVL of roughly $29,000 and its proposed compensation plan yielded no meaningful restitution for affected users.","sections":[{"content":"On December 19, 2021, an unknown attacker exploited a critical reentrancy vulnerability in Grim Finance's GrimBoostVault smart contract, draining approximately $30 million from the protocol's yield vaults on the Fantom Opera blockchain. The attacker's address was identified as 0xdefc385d7038f391eb0063c2f7c238cfb55b206c, and the primary exploit transaction hash was 0x19315e5b150d0a83e797203bb9c957ec1fa8a6f404f4f761d970cb29a74a5dd6.\n\nThe attack leveraged a flash loan to borrow WFTM and BTC tokens, which were then supplied to Spirit Swap to obtain Spirit-LP certificates. The attacker passed a malicious contract address as the token parameter to the depositFor() function. When the GrimBoostVault contract called safeTransferFrom() on this malicious address, the attacker's contract re-invoked depositFor() recursively — executing five sequential reentrancy loops. Each loop updated the internal _pool balance variable, causing the contract to mint shares based on a progressively inflated deposit value. By the time the outermost transaction settled, the attacker had received share credit worth roughly five times their actual deposit, enabling them to withdraw $30 million in underlying assets.\n\nThe Grim Finance team publicly acknowledged the breach approximately six hours after the attack occurred, pausing all vaults to halt further losses. At the time of the announcement, the attacker's wallet already contained the full stolen sum. The protocol's total value locked plummeted from approximately $98.9 million to $4.2 million within 24 hours — an 84% collapse. The GRIM native token fell approximately 81%, from $0.80 to $0.15.","heading":"The December 2021 Reentrancy Exploit","sources":[{"url":"https://www.coindesk.com/tech/2021/12/20/fantom-defi-project-grim-finance-exploited-for-30m","name":"coindesk.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/defi-protocol-grim-finance-lost-30m-in-5x-reentrancy-hack","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://slowmist.medium.com/analysis-of-the-grim-finance-hack-bc440108b069","name":"slowmist.medium.com","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-grim-finance-hack-december-2021","name":"halborn.com","type":"other","credibility":3},{"url":"https://www.quadrigainitiative.com/casestudy/grimfinancereentrancyattack.php","name":"quadrigainitiative.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Security researchers and watchdog organizations identified two root causes for the exploit: (1) the depositFor() function accepted an arbitrary, user-controlled token address without validation, and (2) no reentrancy guard was applied to the function despite it interacting with external contracts. Both failures represent elementary Solidity security hygiene — the reentrancy attack pattern has been documented since at least the 2016 DAO hack.\n\nGrim Finance had been audited by Solidity Finance approximately four months before the exploit, in August 2021. Following the breach, Solidity Finance issued a public statement acknowledging it had missed the vulnerability. The firm attributed the failure to internal organizational stress: the audit was performed by a newly onboarded analyst while the firm's CTO was on vacation, and the peer review process did not catch the issue. Solidity Finance stated this was their second missed exploit across approximately 900 audits.\n\nDeFi watchdog Rugdoc.io publicly criticized the project, stating that 'experienced Solidity developers' should have fundamental knowledge of reentrancy guards before building protocols that hold significant user funds. Rugdoc noted that installing a standard reentrancy guard would have prevented the attack entirely.\n\nDeFiSafety's Process Quality Review rated Grim Finance at 24% with a FAIL designation as of March 2022, reflecting the protocol's inadequate security processes. The audit report had reportedly claimed reentrancy protection was in place — a claim that the exploit proved false.\n\nAfter the hack, Solidity Finance offered Grim Finance a complimentary senior-level contract review and proposed funding a full audit from either QuantStamp or Certik. A subsequent SourceHat audit of the GrimVaultV2 contract confirmed that ReentrancyGuard had been added to the revised deposit() function.","heading":"Security Failures and Audit Negligence","sources":[{"url":"https://cryptonews.net/news/security/2913195/","name":"cryptonews.net","type":"other","credibility":3},{"url":"https://www.technologyforyou.org/30-million-stolen-from-defi-protocol-grim-finance-audit-firm-apologizes-for-missing-vulnerability/","name":"technologyforyou.org","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-grim-finance-hack-december-2021","name":"halborn.com","type":"other","credibility":3},{"url":"https://www.defisafety.com/app/pqrs/423","name":"defisafety.com","type":"other","credibility":3},{"url":"https://sourcehat.com/audits/GrimVaultV2/","name":"sourcehat.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the exploit, the attacker rapidly converted the stolen assets into stablecoins using Fantom-based decentralized exchanges including SpookySwap and AnySwap. The Grim Finance team contacted Circle (USDC issuer), MakerDAO (DAI), and AnySwap in an attempt to freeze assets tied to the attacker's address. However, by the time these notifications were sent, the attacker had already begun laundering the funds.\n\nAlleged laundering activity involved bridging USDC and DAI from the Fantom mainnet to the Ethereum mainnet, and reportedly routing funds through Tornado Cash — a cryptocurrency mixer that was subsequently sanctioned by the U.S. Treasury's OFAC in August 2022. Approximately $3.3 million of the stolen funds were alleged to have been deposited into Tornado Cash. No portion of the stolen $30 million was recovered or returned.","heading":"Stolen Funds and Laundering","sources":[{"url":"https://www.coindesk.com/tech/2021/12/20/fantom-defi-project-grim-finance-exploited-for-30m","name":"coindesk.com","type":"other","credibility":3},{"url":"https://decrypt.co/88727/grim-finance-hacked-30-million-fantom-tokens","name":"decrypt.co","type":"other","credibility":3},{"url":"https://www.quadrigainitiative.com/casestudy/grimfinancereentrancyattack.php","name":"quadrigainitiative.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the exploit, Grim Finance published a post-mortem and announced a multi-pronged compensation strategy. The plan included: (1) creation of a new token to be airdropped proportionally to affected users, with 50% of all future platform revenues allocated to the token indefinitely; (2) an ongoing insurance fund drawing 0.2% of platform fees; (3) partnership restitution involving NFT airdrops from a project called Pod Town; and (4) a donation vault mechanism allowing community members to voluntarily contribute funds for victims.\n\nAffected users were required to submit claims by January 7, 2022 — approximately two weeks after the exploit. However, given the protocol's subsequent collapse in TVL to under $30,000, the revenue-sharing mechanism has generated negligible value. No public reporting confirms that meaningful restitution was delivered to victims. The compensation plan was contingent on future platform revenue that effectively never materialized at a scale sufficient to compensate the $30 million in losses.","heading":"Compensation Plan and Failure to Reimburse","sources":[{"url":"https://medium.com/@grimfinance11/grim-finance-update-to-exploit-15226e6df736","name":"medium.com","type":"other","credibility":3},{"url":"https://www.quadrigainitiative.com/casestudy/grimfinancereentrancyattack.php","name":"quadrigainitiative.com","type":"other","credibility":3},{"url":"https://defillama.com/protocol/grim-finance","name":"defillama.com","type":"other","credibility":3}],"severity":"medium"},{"content":"As of 2025-2026, Grim Finance's total value locked stands at approximately $28,759 spread across six chains (predominantly Fantom), per DeFiLlama data — a de facto ghost protocol. The project's Twitter/X account (@FinanceGrim) has gone largely quiet since early 2022. No credible evidence of active development, new audits, or meaningful community engagement has been identified since the aftermath of the hack.\n\nGrim Finance was a fork of Beefy Finance and never established an independent identity or differentiated security posture. The protocol's collapse is consistent with the broader pattern of forked DeFi yield optimizers that failed to maintain security standards commensurate with the user funds they held.","heading":"Protocol Status and Abandonment","sources":[{"url":"https://defillama.com/protocol/grim-finance","name":"defillama.com","type":"other","credibility":3},{"url":"https://www.vidma.io/blog/the-grim-reaper-strikes-unraveling-the-30-million-grim-finance-hack","name":"vidma.io","type":"other","credibility":3}],"severity":"medium"},{"content":"Grim Finance presents a critical risk profile across all evaluated dimensions. The protocol lost $30 million in a single attack exploiting a well-known, preventable vulnerability class. Its auditor failed to catch the flaw due to internal process failures. No meaningful user compensation was delivered. The stolen funds were alleged to have been laundered through a mixer subsequently sanctioned by the U.S. Treasury. The protocol is now functionally abandoned with under $30,000 in TVL. Users should treat any remaining Grim Finance vaults as effectively unsupported and high-risk. The trust score of 8/100 reflects the severity of the exploit, the failure of the audit process, the collapse of the compensation promise, and the protocol's de facto cessation of operations.","heading":"Risk Assessment Summary","sources":[{"url":"https://www.coindesk.com/tech/2021/12/20/fantom-defi-project-grim-finance-exploited-for-30m","name":"coindesk.com","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-grim-finance-hack-december-2021","name":"halborn.com","type":"other","credibility":3},{"url":"https://defillama.com/protocol/grim-finance","name":"defillama.com","type":"other","credibility":3},{"url":"https://www.defisafety.com/app/pqrs/423","name":"defisafety.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2021-08","event":"Solidity Finance conducts a smart contract audit of Grim Finance, approximately four months before the exploit. A new analyst performs the review while the firm's CTO is on vacation; the reentrancy vulnerability in depositFor() is not flagged.","source":"","date_original":"2021-08-01"},{"date":"2021-12-19","event":"Attacker (address: 0xdefc385d7038f391eb0063c2f7c238cfb55b206c) exploits the GrimBoostVault depositFor() reentrancy vulnerability using a flash loan and a malicious token contract, draining approximately $30 million from Grim Finance vaults on Fantom.","source":""},{"date":"2021-12-19","event":"Grim Finance team pauses all vaults approximately six hours after the attack begins. The team notifies Circle (USDC), MakerDAO (DAI), and AnySwap to freeze attacker-linked addresses. The attacker has already begun converting and bridging stolen assets.","source":""},{"date":"2021-12-19","event":"Grim Finance TVL collapses from approximately $98.9 million to $4.2 million. The GRIM token falls approximately 81%, from $0.80 to $0.15. Rugdoc.io and other security watchdogs publicly criticize the lack of a basic reentrancy guard.","source":""},{"date":"2021-12-20","event":"Solidity Finance issues a public statement acknowledging the missed vulnerability, attributing it to internal organizational stress and a new analyst performing the review. CoinDesk, CoinTelegraph, and Decrypt report on the breach.","source":""},{"date":"2021-12-20","event":"Attacker alleged to have deposited approximately $3.3 million of stolen funds into Tornado Cash mixer, with additional funds bridged from Fantom to Ethereum mainnet via stablecoin conversions.","source":""},{"date":"2021-12-31","event":"Grim Finance publishes post-mortem and compensation plan announcing a new token airdrop (50% of platform revenues), 0.2% insurance fund, and NFT airdrops from partner Pod Town. Affected users must submit claims by January 7, 2022.","source":""},{"date":"2022-01-07","event":"Claim submission deadline for hack victims passes. No public reporting confirms material restitution was subsequently delivered.","source":""},{"date":"2022-03-17","event":"DeFiSafety publishes a Process Quality Review rating Grim Finance at 24% with a FAIL designation, citing inadequate security processes.","source":""},{"date":"2022-08-08","event":"U.S. Treasury OFAC sanctions Tornado Cash, the mixer allegedly used to launder a portion of the Grim Finance stolen funds.","source":""},{"date":"2026-05","event":"Grim Finance TVL sits at approximately $28,759 across six chains per DeFiLlama, reflecting a functionally abandoned protocol. No meaningful development activity or community engagement has been identified since early 2022.","source":"","date_original":"2026-05-01"}],"sources_used":[{"url":"https://www.coindesk.com/tech/2021/12/20/fantom-defi-project-grim-finance-exploited-for-30m","name":"coindesk.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://cointelegraph.com/news/defi-protocol-grim-finance-lost-30m-in-5x-reentrancy-hack","name":"cointelegraph.com","type":"other","archive_url":"http://web.archive.org/web/20260729045751/https://cointelegraph.com/news/defi-protocol-grim-finance-lost-30m-in-5x-reentrancy-hack","credibility":3,"archive_timestamp":"2026-07-29T04:57:51+00:00"},{"url":"https://slowmist.medium.com/analysis-of-the-grim-finance-hack-bc440108b069","name":"slowmist.medium.com","type":"other","archive_url":"http://web.archive.org/web/20260502044136/https://slowmist.medium.com/analysis-of-the-grim-finance-hack-bc440108b069","credibility":3,"archive_timestamp":"2026-05-02T04:41:36+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-grim-finance-hack-december-2021","name":"halborn.com","type":"other","archive_url":"http://web.archive.org/web/20260609202155/https://www.halborn.com/blog/post/explained-the-grim-finance-hack-december-2021","credibility":3,"archive_timestamp":"2026-06-09T20:21:55+00:00"},{"url":"https://www.quadrigainitiative.com/casestudy/grimfinancereentrancyattack.php","name":"quadrigainitiative.com","type":"other","archive_url":"https://web.archive.org/web/20260830132708/https://www.quadrigainitiative.com/casestudy/grimfinancereentrancyattack.php","credibility":3,"archive_timestamp":"2026-08-30T13:27:08+00:00"},{"url":"https://cryptonews.net/news/security/2913195/","name":"cryptonews.net","type":"other","archive_url":"https://web.archive.org/web/20260901035803/https://cryptonews.net/news/security/2913195/","credibility":3,"archive_timestamp":"2026-09-01T03:58:03+00:00"},{"url":"https://www.technologyforyou.org/30-million-stolen-from-defi-protocol-grim-finance-audit-firm-apologizes-for-missing-vulnerability/","name":"technologyforyou.org","type":"other","archive_url":"https://web.archive.org/web/20260830164408/https://www.technologyforyou.org/30-million-stolen-from-defi-protocol-grim-finance-audit-firm-apologizes-for-missing-vulnerability/","credibility":3,"archive_timestamp":"2026-08-30T16:44:08+00:00"},{"url":"https://www.defisafety.com/app/pqrs/423","name":"defisafety.com","type":"other","archive_url":"https://web.archive.org/web/20260829202406/https://www.defisafety.com/app/pqrs/423","credibility":3,"archive_timestamp":"2026-08-29T20:24:06+00:00"},{"url":"https://sourcehat.com/audits/GrimVaultV2/","name":"sourcehat.com","type":"other","archive_url":"http://web.archive.org/web/20260830091613/https://sourcehat.com/audits/GrimVaultV2/","credibility":3,"archive_timestamp":"2026-08-30T09:16:13+00:00"},{"url":"https://decrypt.co/88727/grim-finance-hacked-30-million-fantom-tokens","name":"decrypt.co","type":"other","archive_url":"http://web.archive.org/web/20260517054616/https://decrypt.co/88727/grim-finance-hacked-30-million-fantom-tokens","credibility":3,"archive_timestamp":"2026-05-17T05:46:16+00:00"},{"url":"https://medium.com/@grimfinance11/grim-finance-update-to-exploit-15226e6df736","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://defillama.com/protocol/grim-finance","name":"defillama.com","type":"other","archive_url":"http://web.archive.org/web/20250915041913/https://defillama.com/protocol/grim-finance","credibility":3,"archive_timestamp":"2025-09-15T04:19:13+00:00"},{"url":"https://www.vidma.io/blog/the-grim-reaper-strikes-unraveling-the-30-million-grim-finance-hack","name":"vidma.io","type":"other","archive_url":"http://web.archive.org/web/20260513064717/https://www.vidma.io/blog/the-grim-reaper-strikes-unraveling-the-30-million-grim-finance-hack","credibility":3,"archive_timestamp":"2026-05-13T06:47:17+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:52.352661+00:00","updated_at":"2026-09-01T04:16:57.10054+00:00"}}