{"investigation":{"slug":"impermax-v3","entity_name":"Impermax V3","trust_score":32,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"Impermax V3 is the third major iteration of Impermax Finance, a DeFi leveraged yield-farming and lending protocol that allows liquidity providers to use Uniswap V3 LP tokens as collateral. The protocol suffered two separate critical exploits in 2025 — a ~$300,000 flash-loan collateral valuation attack in April and a ~$380,000 liquidation logic exploit in November — both on the Base chain, resulting in cumulative losses exceeding $680,000 and leaving lenders with unresolved bad debt. These incidents follow a 2022 private key compromise affecting the IMX token, representing a recurring pattern of security failures across the protocol's history.","sections":[{"content":"Impermax V3 is the latest version of Impermax Finance, a permissionless DeFi protocol founded by Simone Rigolon (Founder and Core Developer) and Brian Tinsman (Economics and Finance). The protocol was first announced via whitepaper in December 2020 and launched its IMX token on April 29, 2021, airdropping 14 million tokens to approximately 35,000 Uniswap V2 liquidity providers. The core mechanism allows liquidity providers to deposit LP tokens from automated market makers such as Uniswap V3 as collateral in order to borrow assets, enabling leveraged yield farming. V3 specifically integrates with Uniswap V3 concentrated liquidity positions. The native governance and utility token is IBEX, which replaced IMX following a 2022 token recovery event. As of mid-2026, the protocol's total value locked (TVL) has declined significantly to approximately $98,000, concentrated almost entirely on the Base network. The protocol hosts a bug bounty program through HackenProof and has undergone audits by BailSec, Guardian, and Cantina.","heading":"Protocol Overview","sources":[{"url":"https://www.impermax.finance/","name":"impermax.finance","type":"other","credibility":3},{"url":"https://defillama.com/protocol/impermax-v3","name":"defillama.com","type":"other","credibility":3},{"url":"https://docs.impermax.finance/getting-started/code-audits","name":"docs.impermax.finance","type":"other","credibility":3},{"url":"https://impermax.medium.com/","name":"impermax.medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On April 26, 2025, beginning at approximately 10:43 UTC, Impermax V3 was subjected to a coordinated flash-loan exploit affecting pools on the Base and Arbitrum blockchains. The attacker, operating from address 0xE3223f7E3343c2C8079f261D59ee1e513086C7C3 via attack contract 0x98E938899902217465f17CF0B76d12B3DCa8CE1b, exploited a critical flaw in the protocol's valuation of uncollected Uniswap V3 fees as collateral. The attack sequence involved: (1) borrowing WETH and USDC via a flash loan from Morpho; (2) creating a Uniswap V3 LP position in a WETH/USDC 1% fee-tier pool with minimal external liquidity to allow price manipulation; (3) executing approximately 50 swaps to generate large artificial uncollected fees concentrated on one side of the position; (4) using those inflated uncollected fee estimates as collateral to borrow assets from Impermax; (5) triggering auto-compounding of the fees at an out-of-range price tick, causing the position value to collapse dramatically; and (6) invoking the protocol's restructureBadDebt function to dilute lender shares and retain borrowed funds while repaying the flash loan. The root cause was a discrepancy between the valuation of uncollected fees versus auto-compounded fees, where the former were assigned full collateral value without accounting for their vulnerability to tick-range manipulation. Audits by BailSec and Guardian conducted shortly before the exploit had not identified this edge-case. The Impermax team's official post-mortem estimated total losses at approximately $300,000 to $400,000. Funds were transferred through multiple attacker-controlled addresses and were not recovered. The team committed to distributing recovered funds to affected lenders based on a pre-exploit snapshot, though specific reimbursement timelines and proportions were not disclosed at time of writing.","heading":"April 2025 Flash Loan Exploit (~$300,000–$400,000)","sources":[{"url":"https://impermax.medium.com/impermax-v3-exploit-post-mortem-6b0818897b25","name":"impermax.medium.com","type":"other","credibility":3},{"url":"https://www.quillaudits.com/blog/hack-analysis/how-impermax-v3-lost-300k-in-flashloan-attack","name":"quillaudits.com","type":"other","credibility":3},{"url":"https://blog.verichains.io/p/inside-the-impermax-v3-hack","name":"blog.verichains.io","type":"other","credibility":3},{"url":"https://monoaudit.com/en/articles/impermax-v3","name":"monoaudit.com","type":"other","credibility":3},{"url":"https://quadrigainitiative.com/casestudy/impermaxfinancev3flashloanfeevaluationflawexploited.php","name":"quadrigainitiative.com","type":"other","credibility":3},{"url":"https://incrypthos.com/security/lending-protocol-impermax-v3-drained-by-collateral-fee-valuation-flaw/","name":"incrypthos.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On November 11, 2025, Impermax V3 suffered a second critical exploit, this time targeting its cbBTC lending vault on the Base network. The attacker exploited a routing error vulnerability in the protocol's liquidation logic. By repeatedly creating minimal-size positions in a cbBTC-tBTC trading pair with near-zero liquidity, the attacker was able to push the borrowable contract's totalBalance progressively toward zero. As the totalBalance approached zero, the exchange rate within the contract collapsed artificially, allowing the attacker to mint an exponentially growing balance of cbBTC borrowable tokens. Once totalBalance reached zero, the contract entered a compromised state in which all incoming deposits were redirected to the attacker's address. The attacker then forced the protocol's lending vault to deposit funds into this compromised borrowable contract and withdrew approximately 5.39 cbBTC, valued at roughly $380,000 at the time. In response, the Impermax team disabled vault connections, added liquidity to low-balance borrowables, and advised all users to withdraw funds as a precautionary measure. This second exploit occurred despite post-April remediation efforts and a re-audit completed in July 2025 by Guardian, BailSec's Charles Wang, and Cantina's Riley Holtereus, indicating that the re-audit did not catch this separate vulnerability class. Combined with the April incident, total confirmed losses for Impermax V3 in 2025 exceeded $680,000.","heading":"November 2025 Liquidation Logic Exploit (~$380,000)","sources":[{"url":"https://www.nominis.io/insights/nominis-monthly-report-crypto-attacks-in-november-2025","name":"nominis.io","type":"other","credibility":3},{"url":"https://defillama.com/protocol/impermax-v3","name":"defillama.com","type":"other","credibility":3},{"url":"https://x.com/ImpermaxFinance/status/1988636882977116667","name":"x.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On July 16, 2022, at approximately 5:00 PM UTC, a hacker gained access to the private keys of several Impermax team wallets. The method of key compromise was not disclosed in the official post-mortem. Approximately 9 million IMX tokens were stolen along with most of the protocol-owned liquidity. The Impermax team elected to frontrun the attacker by selling a large portion of the stolen tokens in the open market before the hacker could execute a single large dump that would have caused a more severe price crash and greater harm to liquidity providers. As a remediation measure, the team executed a full token migration from IMX to a new token, IBEX, with distribution based on a pre-incident snapshot. Holders, lenders, stakers, and liquidity providers who held IMX before the incident received IBEX on a 1:1 basis; liquidity providers additionally received ETH compensation for lost liquidity. Approximately 87.25 million IBEX entered effective circulation after unclaimed tokens were burned. The smart contracts underlying the lending protocol were confirmed to be unaffected; the attack was isolated to team-controlled wallets. This incident predates V3 but is part of the entity's overall security history.","heading":"2022 IMX Private Key Compromise and Token Migration","sources":[{"url":"https://impermax.medium.com/imx-incident-post-mortem-and-recovery-plan-aeecd4e457ce","name":"impermax.medium.com","type":"other","credibility":3},{"url":"https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Impermax_Finance_Private_Key_Compromise_Token_Theft","name":"quadrigainitiative.com","type":"other","credibility":3},{"url":"https://impermax.medium.com/imx-incident-refund-allocations-a873e5393cf3","name":"impermax.medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Impermax Finance has maintained a formal audit program across its protocol versions. An early CertiK audit of the original IMX token contract was completed and is available in the project's GitHub repository. For V3 specifically, BailSec and Guardian each completed an Impermax V3 Core audit in April 2025, prior to the April 26 flash-loan exploit. These audits did not identify the uncollected fee valuation edge-case that was subsequently exploited. Following the April exploit, a joint re-audit was conducted in July 2025 by Guardian, Charles Wang of BailSec, and Riley Holtereus of Cantina. A further Guardian audit for the Aerodrome Slipstream integration was completed in August 2025. Despite this re-audit, the November 2025 cbBTC vault liquidation exploit occurred, targeting a different vulnerability class in the liquidation routing logic. The protocol maintains a bug bounty program through HackenProof with a stated maximum payout. The pattern of two successful exploits within a single calendar year, both occurring after formal audits, raises questions about the completeness of the audit coverage and the thoroughness of post-incident remediation. The protocol's CertiK Skynet score, based on earlier versions, was reported at 85/100, though this rating does not incorporate the 2025 exploit history.","heading":"Audit History and Security Posture","sources":[{"url":"https://docs.impermax.finance/getting-started/code-audits","name":"docs.impermax.finance","type":"other","credibility":3},{"url":"https://hackenproof.com/programs/impermax-finance-smart-contracts","name":"hackenproof.com","type":"other","credibility":3},{"url":"https://skynet.certik.com/projects/impermax","name":"skynet.certik.com","type":"other","credibility":3},{"url":"https://github.com/Impermax-Finance/IMX/blob/main/audit/CertiK%20Audit%20Report%20for%20IMX.pdf","name":"github.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Impermax V3 has been flagged by ZachXBT, an independent on-chain investigator whose signals are tracked by AVOID.NET as a risk indicator. The specific nature and basis of ZachXBT's flag have not been independently confirmed through publicly available posts at the time of this investigation; the flag is noted as a source tag associated with this entity. The protocol's broader risk profile is supported by verifiable on-chain and reported evidence: two confirmed exploits totaling over $680,000 in 2025, a prior 2022 private key compromise, and a post-exploit TVL collapse to approximately $98,000. Community sentiment following the November 2025 exploit was negative, with the team advising users to withdraw funds entirely as a precautionary measure. No formal regulatory actions, SEC filings, or DOJ involvement have been identified in connection with Impermax V3.","heading":"ZachXBT Flag and Community Risk Signals","sources":[{"url":"https://defillama.com/protocol/impermax-v3","name":"defillama.com","type":"other","credibility":3},{"url":"https://www.nominis.io/insights/nominis-monthly-report-crypto-attacks-in-november-2025","name":"nominis.io","type":"other","credibility":3}],"severity":"medium"},{"content":"As of mid-2026, Impermax V3 remains operational with sharply reduced TVL of approximately $98,000, concentrated almost entirely on the Base chain. The protocol shows negligible current fee and revenue activity, with annual fee generation effectively at zero. The team has stated intentions to reimburse affected lenders from both the April and November 2025 exploits based on pre-exploit snapshots, but public disclosures have not confirmed specific reimbursement timelines, percentages completed, or total amounts repaid. The IBEX token continues to trade on secondary markets. Users who withdrew funds following the November 2025 team advisory are not at ongoing risk from current contract exposure, but historical lender losses remain unresolved. The protocol's repeated security failures, combined with an unresolved reimbursement posture and near-zero TVL, reflect a materially diminished operational state.","heading":"Current Protocol Status and Recovery","sources":[{"url":"https://defillama.com/protocol/impermax-v3","name":"defillama.com","type":"other","credibility":3},{"url":"https://impermax.medium.com/impermax-v3-exploit-post-mortem-6b0818897b25","name":"impermax.medium.com","type":"other","credibility":3},{"url":"https://www.impermax.finance/","name":"impermax.finance","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2020-12","event":"Impermax Finance whitepaper published, outlining leveraged yield farming using LP tokens as collateral.","source":""},{"date":"2021-04-29","event":"IMX token launched via airdrop to approximately 35,000 Uniswap V2 liquidity providers. 14 million tokens distributed at token generation event.","source":""},{"date":"2022-07-16","event":"Private key compromise of several Impermax team wallets. Approximately 9 million IMX tokens and protocol-owned liquidity stolen. Team frontran attacker by selling tokens. IMX migrated to IBEX via pre-incident snapshot distribution.","source":""},{"date":"2025-04","event":"BailSec and Guardian each complete Impermax V3 Core audits prior to launch.","source":""},{"date":"2025-04-26","event":"Flash-loan exploit on Impermax V3 exploiting uncollected Uniswap V3 fee valuation flaw. Approximately $300,000–$400,000 drained from Base and Arbitrum pools. Attacker address: 0xE3223f7E3343c2C8079f261D59ee1e513086C7C3.","source":""},{"date":"2025-04-28","event":"Impermax Finance publishes official post-mortem on Medium. Protocol stabilization measures announced. Lender reimbursement plan based on pre-exploit snapshot committed to, with timeline unspecified.","source":""},{"date":"2025-07","event":"Joint re-audit of updated Impermax V3 Core completed by Guardian, BailSec (Charles Wang), and Cantina (Riley Holtereus).","source":""},{"date":"2025-08","event":"Guardian completes audit of Aerodrome Slipstream integration with Impermax V3.","source":""},{"date":"2025-11-11","event":"Second critical exploit on Impermax V3: liquidation routing logic vulnerability in cbBTC lending vault on Base. Approximately 5.39 cbBTC (~$380,000) drained. Team disables vault connections and advises all users to withdraw funds.","source":""},{"date":"2026","event":"Protocol TVL declines to approximately $98,000. Annual fee and revenue activity reported at effectively zero. Lender reimbursement status for both 2025 exploits remains unconfirmed publicly.","source":""}],"sources_used":[{"url":"https://www.impermax.finance/","name":"impermax.finance","type":"other","archive_url":"http://web.archive.org/web/20260611193512/https://www.impermax.finance/","credibility":3,"archive_timestamp":"2026-06-11T19:35:12+00:00"},{"url":"https://defillama.com/protocol/impermax-v3","name":"defillama.com","type":"other","archive_url":"http://web.archive.org/web/20250905161917/https://defillama.com/protocol/impermax-v3","credibility":3,"archive_timestamp":"2025-09-05T16:19:17+00:00"},{"url":"https://docs.impermax.finance/getting-started/code-audits","name":"docs.impermax.finance","type":"other","archive_url":"http://web.archive.org/web/20260718142146/https://docs.impermax.finance/getting-started/code-audits","credibility":3,"archive_timestamp":"2026-07-18T14:21:46+00:00"},{"url":"https://impermax.medium.com/","name":"impermax.medium.com","type":"other","archive_url":"http://web.archive.org/web/20260416150124/https://impermax.medium.com/","credibility":3,"archive_timestamp":"2026-04-16T15:01:24+00:00"},{"url":"https://impermax.medium.com/impermax-v3-exploit-post-mortem-6b0818897b25","name":"impermax.medium.com","type":"other","archive_url":"http://web.archive.org/web/20251204193848/https://impermax.medium.com/impermax-v3-exploit-post-mortem-6b0818897b25","credibility":3,"archive_timestamp":"2025-12-04T19:38:48+00:00"},{"url":"https://www.quillaudits.com/blog/hack-analysis/how-impermax-v3-lost-300k-in-flashloan-attack","name":"quillaudits.com","type":"other","archive_url":"http://web.archive.org/web/20260515102411/https://www.quillaudits.com/blog/hack-analysis/how-impermax-v3-lost-300k-in-flashloan-attack","credibility":3,"archive_timestamp":"2026-05-15T10:24:11+00:00"},{"url":"https://blog.verichains.io/p/inside-the-impermax-v3-hack","name":"blog.verichains.io","type":"other","archive_url":"http://web.archive.org/web/20260419212623/https://blog.verichains.io/p/inside-the-impermax-v3-hack","credibility":3,"archive_timestamp":"2026-04-19T21:26:23+00:00"},{"url":"https://monoaudit.com/en/articles/impermax-v3","name":"monoaudit.com","type":"other","archive_url":"http://web.archive.org/web/20251007122054/https://monoaudit.com/en/articles/impermax-v3","credibility":3,"archive_timestamp":"2025-10-07T12:20:54+00:00"},{"url":"https://quadrigainitiative.com/casestudy/impermaxfinancev3flashloanfeevaluationflawexploited.php","name":"quadrigainitiative.com","type":"other","archive_url":"http://web.archive.org/web/20260519160358/https://quadrigainitiative.com/casestudy/impermaxfinancev3flashloanfeevaluationflawexploited.php","credibility":3,"archive_timestamp":"2026-05-19T16:03:58+00:00"},{"url":"https://incrypthos.com/security/lending-protocol-impermax-v3-drained-by-collateral-fee-valuation-flaw/","name":"incrypthos.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://www.nominis.io/insights/nominis-monthly-report-crypto-attacks-in-november-2025","name":"nominis.io","type":"other","archive_url":"http://web.archive.org/web/20260417161132/https://www.nominis.io/insights/nominis-monthly-report-crypto-attacks-in-november-2025","credibility":3,"archive_timestamp":"2026-04-17T16:11:32+00:00"},{"url":"https://x.com/ImpermaxFinance/status/1988636882977116667","name":"x.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://impermax.medium.com/imx-incident-post-mortem-and-recovery-plan-aeecd4e457ce","name":"impermax.medium.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Impermax_Finance_Private_Key_Compromise_Token_Theft","name":"quadrigainitiative.com","type":"other","archive_url":"https://web.archive.org/web/20260829230814/https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Impermax_Finance_Private_Key_Compromise_Token_Theft","credibility":3,"archive_timestamp":"2026-08-29T23:08:14+00:00"},{"url":"https://impermax.medium.com/imx-incident-refund-allocations-a873e5393cf3","name":"impermax.medium.com","type":"other","archive_url":"http://web.archive.org/web/20251230031805/https://impermax.medium.com/imx-incident-refund-allocations-a873e5393cf3","credibility":3,"archive_timestamp":"2025-12-30T03:18:05+00:00"},{"url":"https://hackenproof.com/programs/impermax-finance-smart-contracts","name":"hackenproof.com","type":"other","archive_url":"http://web.archive.org/web/20260829033906/https://hackenproof.com/programs/impermax-finance-smart-contracts","credibility":3,"archive_timestamp":"2026-08-29T03:39:06+00:00"},{"url":"https://skynet.certik.com/projects/impermax","name":"skynet.certik.com","type":"other","archive_url":"https://web.archive.org/web/20260829040958/https://skynet.certik.com/projects/impermax","credibility":3,"archive_timestamp":"2026-08-29T04:09:58+00:00"},{"url":"https://github.com/Impermax-Finance/IMX/blob/main/audit/CertiK%20Audit%20Report%20for%20IMX.pdf","name":"github.com","type":"other","archive_url":"https://web.archive.org/web/20260829033302/https://github.com/Impermax-Finance/IMX/blob/main/audit/CertiK%20Audit%20Report%20for%20IMX.pdf","credibility":3,"archive_timestamp":"2026-08-29T03:33:02+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:24.018603+00:00","updated_at":"2026-08-29T23:26:12.669096+00:00"}}