{"investigation":{"slug":"indexed-finance","entity_name":"Indexed Finance","trust_score":12,"severity_base":null,"score_modifier":0,"confidence":0.91,"status":"published","content_type":"investigation","summary":"Indexed Finance was an Ethereum-based decentralized protocol offering passively managed index pools, launched in late 2020. On October 14, 2021, the protocol suffered a sophisticated $16 million flash loan exploit targeting its DEFI5 and CC10 pools, destroying most user funds. The alleged attacker, Canadian mathematics prodigy Andean Medjedovic, was later charged by U.S. prosecutors in February 2025 in connection with $65 million in combined DeFi thefts and remains a fugitive as of early 2026.","sections":[{"content":"Indexed Finance was an Ethereum-based decentralized finance (DeFi) protocol designed to provide passively managed, tokenized index pools for crypto assets. The protocol launched its governance token (NDX) and its first index products — including DEFI5 and CC10 — in late 2020 and early 2021. The protocol was developed by a pseudonymous and named team including Laurence Day and Dillon Kellar. Users could stake index tokens or associated Uniswap liquidity tokens to earn NDX governance tokens. The protocol generated revenue from exit fees of 0.5% when users left index pools. Following the October 2021 exploit, the protocol effectively ceased new development, and governance activity largely stalled. By late 2023, the project's treasury held approximately $120,000 and was the target of multiple hostile governance attacks before founders reclaimed control.","heading":"Overview","sources":[{"url":"https://cryptobriefing.com/defi-protocol-indexed-finance-suffers-16m-exploit/","name":"cryptobriefing.com","type":"other","credibility":3},{"url":"https://ndxfi.medium.com/introducing-indexed-finance-ndx-5d91137bde29","name":"ndxfi.medium.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/indexed-finance-thwarts-hijackers-set-to-compensate-2021-hack-victims","name":"cointelegraph.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On October 14, 2021, at approximately 18:37 UTC, Indexed Finance suffered a critical exploit targeting two of its primary index pools: DEFI5 and CC10. The attacker extracted approximately $11 million from DEFI5 and $5 million from CC10, for a combined total of approximately $16 million. Three other pools (DEGEN, NFTP, ORCL5) were unaffected.\n\nThe exploit relied on a vulnerability in the protocol's pool value estimation function, specifically `extrapolatePoolValueFromToken`. This function estimated total pool value by selecting a single reference token — whichever token had the highest target weight and was fully initialized — and extrapolating total pool value from that token's balance alone. An attacker could therefore manipulate this estimate by draining the reference token from the pool, causing the function to drastically undervalue the pool.\n\nThe attack sequence for DEFI5 was as follows: (1) The attacker triggered a re-index of the DEFI5 pool, which caused UNI to be selected as the reference pricing token. (2) The attacker took out approximately $156 million in flash swap loans across multiple assets (UNI, AAVE, COMP, CRV, MKR, SNX) from Sushiswap and Uniswap V2. (3) The attacker purchased nearly all UNI from the DEFI5 pool, drastically reducing its balance. (4) The attacker called `updateMinimumBalance`, which recalculated pool value at only approximately $300,000 based on the depleted UNI balance — a dramatic undervaluation. (5) The attacker used their purchased UNI to mint inflated quantities of DEFI5 index tokens at artificially low valuations. (6) These index tokens were burned to extract the underlying assets repeatedly. (7) Flash loans were repaid, leaving the attacker with approximately $11 million in profit. The CC10 attack followed the same pattern without requiring an initial re-index trigger.\n\nThe transaction was highly complex, generating over 1,000 on-chain events and consuming an entire Ethereum block. Despite prior audits by two independent security experts, the vulnerability was not identified before deployment. The DEFI5 token lost approximately 85% of its value within an hour of the attack (from $88.73 to $3.67), while CC10 collapsed by over 98% (from $62.50 to $0.74).","heading":"October 2021 Flash Loan Exploit ($16 Million)","sources":[{"url":"https://ndxfi.medium.com/indexed-attack-post-mortem-b006094f0bdc","name":"ndxfi.medium.com","type":"other","credibility":3},{"url":"https://cryptobriefing.com/defi-protocol-indexed-finance-suffers-16m-exploit/","name":"cryptobriefing.com","type":"other","credibility":3},{"url":"https://blocksecteam.medium.com/the-analysis-of-indexed-finance-security-incident-8a62b9799836","name":"blocksecteam.medium.com","type":"other","credibility":3},{"url":"https://www.vidma.io/blog/indexed-finance-a-16-million-hack-exposes-defi-vulnerabilities","name":"vidma.io","type":"other","credibility":3},{"url":"https://decrypt.co/83681/defi-protocol-indexed-finance-hacked-for-16-million-team-finds-hacker","name":"decrypt.co","type":"other","credibility":3}],"severity":"medium"},{"content":"Within approximately three days of the exploit, core team members Laurence Day and Dillon Kellar identified the alleged attacker through off-chain digital forensics. The attacker had contacted the team approximately one month prior to the exploit using the Discord handle 'UmbralUpsilon,' posing as someone building an arbitrage bot and asking specific questions about protocol mechanics. This chat was later deleted but aroused suspicion during the investigation.\n\nThe team traced the attacker through a chain of digital evidence: the Discord username was changed to 'BogHolder#1688' — the suffix '1688' being a compound of 16 and 88, both recognized neo-Nazi numerical codes — contest winnings records on the Code4rena (code423n4) platform, GitHub accounts operating under the handles 'mtheorylord1' and 'mtheorylord,' a high school email domain visible in public GitHub commits, Wikipedia editing activity identifying the account holder as a 'notable mathematician,' and Urbit Discord server activity. Ethereum addresses used in the attack were funded via the Tornado Cash privacy mixer.\n\nThe alleged attacker was identified as Andean (\"Andy\") Medjedovic, at the time an 18-year-old Canadian citizen and graduate student in applied mathematics at the University of Waterloo. Medjedovic had completed high school mathematics at approximately age 13 and had published papers on advanced mathematical topics.\n\nThe Ethereum address used in the attack contained the string 'BA5Ed1488,' which investigators noted embedded references to neo-Nazi symbolism. The attack code itself was reported to contain a racial slur targeting Black individuals and a reference to sexual assault, according to subsequent reporting by Bloomberg Law and CoinDesk.\n\nUpon being contacted by Dillon Kellar with a message stating he had been identified and would be reported to law enforcement unless he returned the funds, Medjedovic allegedly replied 'LOL, good luck.' The team subsequently published a comprehensive public identification of the attacker and reported evidence to multiple law enforcement agencies.\n\nMediating this response was an ethical debate within the team about publicly identifying a teenager. That debate was resolved once the attacker's dismissive response was received. The team retained attorney Jason Gottlieb to coordinate law enforcement reporting. Gottlieb stated publicly: 'Code is not law. Law is law...It was market manipulation. It's illegal.' Medjedovic, through subsequent public communications, maintained that his transactions were legitimate arbitrage and that the smart contract itself permitted the operations he performed.","heading":"Attacker Identification and \"Code Is Law\" Defense","sources":[{"url":"https://www.coindesk.com/tech/2021/10/22/after-stealing-16m-this-teen-hacker-seems-intent-on-testing-code-is-law-in-the-courts","name":"coindesk.com","type":"other","credibility":3},{"url":"https://cryptobriefing.com/inside-the-war-room-how-indexed-finance-traced-its-16m-hacker/","name":"cryptobriefing.com","type":"other","credibility":3},{"url":"https://decrypt.co/83681/defi-protocol-indexed-finance-hacked-for-16-million-team-finds-hacker","name":"decrypt.co","type":"other","credibility":3},{"url":"https://news.bloomberglaw.com/tech-and-telecom-law/math-prodigy-whose-hack-upended-defi-wont-give-up-his-millions","name":"news.bloomberglaw.com","type":"other","credibility":3},{"url":"https://www.bloomberg.com/news/features/2022-05-19/crypto-platform-hack-rocks-blockchain-community","name":"bloomberg.com","type":"other","credibility":3}],"severity":"medium"},{"content":"In December 2021, a Canadian court issued an arrest warrant for Andean Medjedovic. He has been a fugitive since that date. By 2023, Medjedovic publicly described his fugitive life as 'exhausting,' noting he had been traveling through Europe, South America, and an unnamed island nation.\n\nOn February 3, 2025, the United States Department of Justice unsealed a five-count federal indictment in the Eastern District of New York (EDNY) charging Medjedovic, then age 22, in connection with a combined $65 million in alleged DeFi thefts across two separate hacks: the 2021 Indexed Finance exploit ($16 million) and the 2023 KyberSwap exploit (approximately $49-50 million).\n\nThe five counts are: (1) wire fraud; (2) unauthorized damage to a protected computer; (3) attempted Hobbs Act extortion; (4) money laundering conspiracy; and (5) money laundering. The maximum penalty, if convicted on all counts, is 90 years in prison — 20 years each for wire fraud, extortion, and both money laundering charges, and 10 years for the computer damage count.\n\nWith respect to the KyberSwap hack, the indictment alleged that Medjedovic planned the attack over several months, writing notes to himself including 'Find time to Strike!' and constructing a 'POST-EXPLOITATION' plan. Eight months before the KyberSwap exploit he had allegedly claimed to be operating as a whitehat hacker. The KyberSwap attack occurred in November 2023.\n\nAs of January 2026, Medjedovic had allegedly slipped a law enforcement dragnet in Serbia and was subsequently reported to have surfaced in Bosnia, according to reporting by Balkan Insight. A spokesperson for the EDNY confirmed to CoinDesk in February 2025 that Medjedovic remains 'at large' and is not believed to be in the United States.","heading":"Criminal Charges and Fugitive Status","sources":[{"url":"https://www.justice.gov/opa/pr/canadian-man-charged-65m-cryptocurrency-hacking-schemes","name":"justice.gov","type":"other","credibility":3},{"url":"https://www.coindesk.com/policy/2025/02/03/u-s-prosecutors-charge-canadian-man-with-usd65m-hacks-of-indexed-finance-kyberswap","name":"coindesk.com","type":"other","credibility":3},{"url":"https://coingeek.com/canadian-teen-faces-arrest-warrant-over-defi-hack-in-code-is-law-case/","name":"coingeek.com","type":"other","credibility":3},{"url":"https://www.theglobeandmail.com/business/article-us-charge-alleged-hacker-in-us65-million-cryptocurrency-scheme/","name":"theglobeandmail.com","type":"other","credibility":3},{"url":"https://balkaninsight.com/2026/01/30/canadian-crypto-fugitive-slips-dragnet-in-serbia-surfaces-in-bosnia/bi/","name":"balkaninsight.com","type":"other","credibility":3},{"url":"https://content.govdelivery.com/attachments/USDOJOPA/2025/02/03/file_attachments/3152493/Medjedovic%20Indictment%20508.pdf","name":"content.govdelivery.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the exploit, the Indexed Finance DAO voted between October 27 and November 2, 2021, on a compensation plan for affected users. The DAO approved the creation of 'Pickle Cornichon' claim tokens — two separate types, one for direct index token holders and one for liquidity pool token holders. Affected parties could burn these claim tokens to receive DAI at their preferred redemption rate.\n\nThe compensation rates approved were approximately 99.32% of losses for direct token holders (DEFI5, CC10, FFF) and approximately 88.5% of losses for liquidity pool token holders. Funding was to come from assets extracted from the affected pools and from ongoing protocol revenue. The DAO explicitly agreed not to inflate the debt amount over time to reflect lost upside opportunity.\n\nAs a contingency, the plan noted that if stolen assets were ever recovered, the DAO would reconvene to determine redistribution mechanisms, potentially including restorative index tokens or additional DAI payouts.\n\nThe compensation process was complex, requiring the team to assemble on-chain subgraphs to calculate affected balances across chains and account for amounts users had already partially recovered through selling or burning tokens prior to the snapshot.","heading":"Victim Compensation Efforts","sources":[{"url":"https://ndxfi.medium.com/indexed-attack-compensation-plan-f2228303507","name":"ndxfi.medium.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/indexed-finance-thwarts-hijackers-set-to-compensate-2021-hack-victims","name":"cointelegraph.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the 2021 exploit, Indexed Finance entered a prolonged period of inactivity. Developer activity declined substantially, and the last governance vote before late 2023 had occurred in mid-2022 during the victim compensation process. By November 2023, the Indexed DAO treasury held approximately $120,000 in digital assets.\n\nIn November 2023, the protocol faced two hostile governance takeover attempts. In the first attempt (Proposal 24), an unknown party accumulated large quantities of NDX tokens and submitted a malicious governance proposal without a title or description — an apparent effort to avoid detection. The proposal nearly passed within one hour before former contributor Laurence Day detected it and rallied community members to vote it down.\n\nThe DAO then passed Proposal 26, a 'poison pill' provision granting the DAO authority to burn all treasury assets if a hostile takeover became the only alternative. A second attacker then submitted Proposal 27, which was passed before the poison pill could be triggered. In response, co-founder Dillon Kellar offered the attacker $10,000 DAI in exchange for voluntarily canceling the proposal, with the alternative being the destruction of all remaining treasury assets. The attacker accepted the offer with approximately four hours remaining before the poison pill would have executed.\n\nFollowing these events, control of the DAO was returned to a multisig controlled by Day, Kellar, and pseudonymous co-founder PR0. The founders announced plans to distribute remaining treasury funds to victims of the 2021 hack. Separately, ZachXBT investigated the second governance attack and alleged that the funding wallet for the attacker was linked to an individual named Alex Chon, described in that report as a suspected DPRK IT worker.","heading":"Post-Hack Governance Attacks (2023)","sources":[{"url":"https://www.newsbtc.com/news/defi/how-indexed-finance-foiled-two-treasury-hijack-attempts-details/","name":"newsbtc.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/indexed-finance-thwarts-hijackers-set-to-compensate-2021-hack-victims","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://coinjournal.net/news/indexed-finance-identifies-attacker-behind-16-million-hack/","name":"coinjournal.net","type":"other","credibility":3}],"severity":"medium"},{"content":"Indexed Finance's smart contracts were audited by two independent security experts prior to deployment. Neither audit identified the vulnerability in the `extrapolatePoolValueFromToken` function that was ultimately exploited in October 2021. This represents a significant audit failure, as the vulnerability — while technically complex — was present in the production code at launch.\n\nThe core issue was the protocol's reliance on a single-token value approximation for pool pricing during rebalancing windows. This design created a manipulable attack surface: any token that could serve as the sole pricing reference could be drained via flash loans to cause the protocol to drastically undervalue the entire pool, enabling minting of disproportionate quantities of index tokens.\n\nThe proposed fix — replacing the approximate value function with one that considers the combined value of all token balances in the pool — was technically sound but was never deployed in a meaningful way, as the protocol effectively ceased development following the exploit. The attack has since been studied as a case study in DeFi AMM design vulnerabilities and the risks of approximate pricing functions in rebalancing protocols.","heading":"Protocol Security and Audit Failures","sources":[{"url":"https://ndxfi.medium.com/indexed-attack-post-mortem-b006094f0bdc","name":"ndxfi.medium.com","type":"other","credibility":3},{"url":"https://blocksecteam.medium.com/the-analysis-of-indexed-finance-security-incident-8a62b9799836","name":"blocksecteam.medium.com","type":"other","credibility":3},{"url":"https://www.vidma.io/blog/indexed-finance-a-16-million-hack-exposes-defi-vulnerabilities","name":"vidma.io","type":"other","credibility":3}],"severity":"medium"},{"content":"Indexed Finance's native governance token NDX declined approximately 35% in the immediate aftermath of the October 2021 exploit. The token subsequently continued to fall and was reported to be down approximately 92% from its all-time high of $27.71 (reached in early February 2021) in the months following the hack.\n\nAs of the time of this report, the NDX token remains traded but at a small fraction of its peak value. The DEFI5 and CC10 index tokens lost between 85% and 98% of their value immediately following the exploit and are not considered viable investment vehicles. The protocol has not resumed active development. The DAO treasury, which held approximately $120,000 in late 2023 after fending off governance attacks, was intended to be distributed to 2021 hack victims.","heading":"Token Performance and Protocol Status","sources":[{"url":"https://cryptonews.net/news/defi/2243873/","name":"cryptonews.net","type":"other","credibility":3},{"url":"https://etherscan.io/token/0x86772b1409b61c639eaac9ba0acfbb6e238e5f83","name":"etherscan.io","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/indexed-finance-thwarts-hijackers-set-to-compensate-2021-hack-victims","name":"cointelegraph.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2020-12","event":"Indexed Finance launches on Ethereum, introducing the NDX governance token and its first passively managed index pools.","source":"","date_original":"2020-12-01"},{"date":"2021-02","event":"NDX token reaches all-time high of approximately $27.71.","source":"","date_original":"2021-02-01"},{"date":"2021-09","event":"An individual later identified as Andean Medjedovic contacts the Indexed Finance team via Discord under the handle 'UmbralUpsilon,' asking specific technical questions allegedly while posing as an arbitrage bot developer.","source":"","date_original":"2021-09-01"},{"date":"2021-10-14","event":"Flash loan exploit drains approximately $16 million from the DEFI5 ($11M) and CC10 ($5M) index pools. DEFI5 drops 85% and CC10 drops 98% within hours. The attack exploits a flaw in the pool's value approximation function during rebalancing.","source":""},{"date":"2021-10-15","event":"Indexed Finance publishes an initial post-mortem describing the vulnerability and proposes a fix. NDX falls approximately 35%.","source":""},{"date":"2021-10-17","event":"Core team members Laurence Day and Dillon Kellar identify the alleged attacker through off-chain digital forensics, tracing GitHub accounts, Discord usernames, and university records to Andean Medjedovic, an 18-year-old University of Waterloo applied mathematics student.","source":""},{"date":"2021-10-17","event":"Dillon Kellar contacts Medjedovic directly, stating he has been identified and will be reported to law enforcement unless funds are returned. Medjedovic allegedly replies 'LOL, good luck.' The team subsequently publishes a full public identification.","source":""},{"date":"2021-10-22","event":"CoinDesk publishes a detailed report on Medjedovic's refusal to return funds and his intent to test the 'code is law' argument in court.","source":""},{"date":"2021-10-27","event":"The Indexed Finance DAO begins voting on a victim compensation plan. Approved rates: 99.32% for direct token holders, 88.5% for LP token holders, funded via pool asset extraction and converted to DAI.","source":""},{"date":"2021-12","event":"A Canadian court issues an arrest warrant for Andean Medjedovic. He does not turn himself in and begins life as a fugitive.","source":"","date_original":"2021-12-01"},{"date":"2022-05-19","event":"Bloomberg publishes an in-depth feature on the Indexed Finance hack and Medjedovic's refusal to return funds, noting hate symbols embedded in the attack code and address.","source":""},{"date":"2023-11","event":"Indexed Finance DAO faces two hostile governance takeover attempts targeting its approximately $120,000 treasury. Both are defeated; the second is resolved after co-founder Dillon Kellar pays the attacker $10,000 DAI to stand down. ZachXBT links the second attacker's wallet to an alleged DPRK IT worker.","source":"","date_original":"2023-11-01"},{"date":"2023-11","event":"KyberSwap is exploited for approximately $49-50 million. U.S. prosecutors later allege Andean Medjedovic carried out this second attack as well.","source":"","date_original":"2023-11-01"},{"date":"2025-02-03","event":"The U.S. Department of Justice unseals a five-count federal indictment in the Eastern District of New York charging Andean Medjedovic, age 22, with wire fraud, unauthorized damage to a protected computer, attempted Hobbs Act extortion, money laundering conspiracy, and money laundering in connection with $65 million in alleged thefts from Indexed Finance and KyberSwap. He faces a maximum of 90 years in prison. He remains at large.","source":""},{"date":"2026-01-30","event":"Balkan Insight reports that Medjedovic slipped a law enforcement dragnet in Serbia and was subsequently reported to be in Bosnia. He remains a fugitive.","source":""}],"sources_used":[{"url":"https://cryptobriefing.com/defi-protocol-indexed-finance-suffers-16m-exploit/","name":"cryptobriefing.com","type":"other","archive_url":"http://web.archive.org/web/20251217151526/https://cryptobriefing.com/defi-protocol-indexed-finance-suffers-16m-exploit/","credibility":3,"archive_timestamp":"2025-12-17T15:15:26+00:00"},{"url":"https://ndxfi.medium.com/introducing-indexed-finance-ndx-5d91137bde29","name":"ndxfi.medium.com","type":"other","archive_url":"http://web.archive.org/web/20251111012919/https://ndxfi.medium.com/introducing-indexed-finance-ndx-5d91137bde29","credibility":3,"archive_timestamp":"2025-11-11T01:29:19+00:00"},{"url":"https://cointelegraph.com/news/indexed-finance-thwarts-hijackers-set-to-compensate-2021-hack-victims","name":"cointelegraph.com","type":"other","archive_url":"https://web.archive.org/web/20260830083756/https://cointelegraph.com/news/indexed-finance-thwarts-hijackers-set-to-compensate-2021-hack-victims","credibility":3,"archive_timestamp":"2026-08-30T08:37:56+00:00"},{"url":"https://ndxfi.medium.com/indexed-attack-post-mortem-b006094f0bdc","name":"ndxfi.medium.com","type":"other","archive_url":"http://web.archive.org/web/20260322055925/https://ndxfi.medium.com/indexed-attack-post-mortem-b006094f0bdc","credibility":3,"archive_timestamp":"2026-03-22T05:59:25+00:00"},{"url":"https://blocksecteam.medium.com/the-analysis-of-indexed-finance-security-incident-8a62b9799836","name":"blocksecteam.medium.com","type":"other","archive_url":"http://web.archive.org/web/20260319184242/https://blocksecteam.medium.com/the-analysis-of-indexed-finance-security-incident-8a62b9799836","credibility":3,"archive_timestamp":"2026-03-19T18:42:42+00:00"},{"url":"https://www.vidma.io/blog/indexed-finance-a-16-million-hack-exposes-defi-vulnerabilities","name":"vidma.io","type":"other","archive_url":"http://web.archive.org/web/20260418185820/https://www.vidma.io/blog/indexed-finance-a-16-million-hack-exposes-defi-vulnerabilities","credibility":3,"archive_timestamp":"2026-04-18T18:58:20+00:00"},{"url":"https://decrypt.co/83681/defi-protocol-indexed-finance-hacked-for-16-million-team-finds-hacker","name":"decrypt.co","type":"other","archive_url":"http://web.archive.org/web/20260315141204/https://decrypt.co/83681/defi-protocol-indexed-finance-hacked-for-16-million-team-finds-hacker","credibility":3,"archive_timestamp":"2026-03-15T14:12:04+00:00"},{"url":"https://www.coindesk.com/tech/2021/10/22/after-stealing-16m-this-teen-hacker-seems-intent-on-testing-code-is-law-in-the-courts","name":"coindesk.com","type":"other","archive_url":"http://web.archive.org/web/20260429184212/https://www.coindesk.com/tech/2021/10/22/after-stealing-16m-this-teen-hacker-seems-intent-on-testing-code-is-law-in-the-courts","credibility":3,"archive_timestamp":"2026-04-29T18:42:12+00:00"},{"url":"https://cryptobriefing.com/inside-the-war-room-how-indexed-finance-traced-its-16m-hacker/","name":"cryptobriefing.com","type":"other","archive_url":"http://web.archive.org/web/20260709144218/https://cryptobriefing.com/inside-the-war-room-how-indexed-finance-traced-its-16m-hacker/","credibility":3,"archive_timestamp":"2026-07-09T14:42:18+00:00"},{"url":"https://news.bloomberglaw.com/tech-and-telecom-law/math-prodigy-whose-hack-upended-defi-wont-give-up-his-millions","name":"news.bloomberglaw.com","type":"other","archive_url":"https://web.archive.org/web/20260829194815/https://news.bloomberglaw.com/tech-and-telecom-law/math-prodigy-whose-hack-upended-defi-wont-give-up-his-millions","credibility":3,"archive_timestamp":"2026-08-29T19:48:15+00:00"},{"url":"https://www.bloomberg.com/news/features/2022-05-19/crypto-platform-hack-rocks-blockchain-community","name":"bloomberg.com","type":"other","archive_url":"http://web.archive.org/web/20250901230833/https://www.bloomberg.com/news/features/2022-05-19/crypto-platform-hack-rocks-blockchain-community","credibility":3,"archive_timestamp":"2025-09-01T23:08:33+00:00"},{"url":"https://www.justice.gov/opa/pr/canadian-man-charged-65m-cryptocurrency-hacking-schemes","name":"justice.gov","type":"other","archive_url":"http://web.archive.org/web/20260712093555/https://www.justice.gov/opa/pr/canadian-man-charged-65m-cryptocurrency-hacking-schemes","credibility":3,"archive_timestamp":"2026-07-12T09:35:55+00:00"},{"url":"https://www.coindesk.com/policy/2025/02/03/u-s-prosecutors-charge-canadian-man-with-usd65m-hacks-of-indexed-finance-kyberswap","name":"coindesk.com","type":"other","archive_url":"http://web.archive.org/web/20260728015123/https://www.coindesk.com/policy/2025/02/03/u-s-prosecutors-charge-canadian-man-with-usd65m-hacks-of-indexed-finance-kyberswap","credibility":3,"archive_timestamp":"2026-07-28T01:51:23+00:00"},{"url":"https://coingeek.com/canadian-teen-faces-arrest-warrant-over-defi-hack-in-code-is-law-case/","name":"coingeek.com","type":"other","archive_url":"http://web.archive.org/web/20260308140013/https://coingeek.com/canadian-teen-faces-arrest-warrant-over-defi-hack-in-code-is-law-case/","credibility":3,"archive_timestamp":"2026-03-08T14:00:13+00:00"},{"url":"https://www.theglobeandmail.com/business/article-us-charge-alleged-hacker-in-us65-million-cryptocurrency-scheme/","name":"theglobeandmail.com","type":"other","archive_url":"http://web.archive.org/web/20260727015620/https://www.theglobeandmail.com/business/article-us-charge-alleged-hacker-in-us65-million-cryptocurrency-scheme/","credibility":3,"archive_timestamp":"2026-07-27T01:56:20+00:00"},{"url":"https://balkaninsight.com/2026/01/30/canadian-crypto-fugitive-slips-dragnet-in-serbia-surfaces-in-bosnia/bi/","name":"balkaninsight.com","type":"other","archive_url":"http://web.archive.org/web/20260324202901/https://balkaninsight.com/2026/01/30/canadian-crypto-fugitive-slips-dragnet-in-serbia-surfaces-in-bosnia/bi/","credibility":3,"archive_timestamp":"2026-03-24T20:29:01+00:00"},{"url":"https://content.govdelivery.com/attachments/USDOJOPA/2025/02/03/file_attachments/3152493/Medjedovic%20Indictment%20508.pdf","name":"content.govdelivery.com","type":"other","archive_url":"https://web.archive.org/web/20260830084605/https://content.govdelivery.com/attachments/USDOJOPA/2025/02/03/file_attachments/3152493/Medjedovic%20Indictment%20508.pdf","credibility":3,"archive_timestamp":"2026-08-30T08:46:05+00:00"},{"url":"https://ndxfi.medium.com/indexed-attack-compensation-plan-f2228303507","name":"ndxfi.medium.com","type":"other","archive_url":"http://web.archive.org/web/20251111021034/https://ndxfi.medium.com/indexed-attack-compensation-plan-f2228303507","credibility":3,"archive_timestamp":"2025-11-11T02:10:34+00:00"},{"url":"https://www.newsbtc.com/news/defi/how-indexed-finance-foiled-two-treasury-hijack-attempts-details/","name":"newsbtc.com","type":"other","archive_url":"http://web.archive.org/web/20250912094306/https://www.newsbtc.com/news/defi/how-indexed-finance-foiled-two-treasury-hijack-attempts-details/","credibility":3,"archive_timestamp":"2025-09-12T09:43:06+00:00"},{"url":"https://coinjournal.net/news/indexed-finance-identifies-attacker-behind-16-million-hack/","name":"coinjournal.net","type":"other","archive_url":"https://web.archive.org/web/20260830203230/https://coinjournal.net/news/proshares-bitcoin-futures-etf-set-to-be-listed-today/?dynamic","credibility":3,"archive_timestamp":"2026-08-30T20:32:30+00:00"},{"url":"https://cryptonews.net/news/defi/2243873/","name":"cryptonews.net","type":"other","archive_url":"https://web.archive.org/web/20260829192119/https://cryptonews.net/news/defi/2243873/","credibility":3,"archive_timestamp":"2026-08-29T19:21:19+00:00"},{"url":"https://etherscan.io/token/0x86772b1409b61c639eaac9ba0acfbb6e238e5f83","name":"etherscan.io","type":"other","archive_url":"https://web.archive.org/web/20260829192700/https://etherscan.io/token/0x86772b1409b61c639eaac9ba0acfbb6e238e5f83","credibility":3,"archive_timestamp":"2026-08-29T19:27:00+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:53.678451+00:00","updated_at":"2026-08-30T20:47:33.939284+00:00"}}