{"investigation":{"slug":"levyathan","entity_name":"Levyathan","trust_score":18,"severity_base":null,"score_modifier":0,"confidence":0.75,"status":"published","content_type":"investigation","summary":"Levyathan was a Binance Smart Chain DeFi protocol billing itself as the first crypto index fund on BSC, launching in mid-2021. On July 30, 2021, the project collapsed after private keys controlling the token minting contract were left exposed in a public GitHub repository for approximately four months, enabling an attacker to mint and dump a quadrillion LEV tokens. A concurrent bug in the emergencyWithdraw() function compounded losses for stakers, and stolen funds were bridged to Ethereum and routed through Tornado Cash; the project never recovered and effectively disbanded.","sections":[{"content":"On July 30, 2021, Levyathan.finance suffered a catastrophic exploit on the Binance Smart Chain. An attacker gained control of the LEV token minting contract by exploiting a private key that the development team had inadvertently left publicly accessible in the project's GitHub governance repository for an estimated four months. Using those credentials, the attacker transferred ownership of the MasterChef contract through a Timelock transaction initiated on July 28, 2021 and executed on July 30, 2021. The attacker then minted a reported 100 quintillion (100,000,000,000,000,000,000,000,000) LEV tokens, dumped them on the market, and bridged the proceeds to Ethereum. The token price collapsed from approximately $0.15 to near zero. Total value locked in the protocol at the time of the exploit was approximately $1.5 million.","heading":"Exploit Overview","sources":[{"url":"https://rekt.news/levyathan-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://levyathan-index.medium.com/post-mortem-levyathan-c3ff7f9a6f65","name":"levyathan-index.medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"A separate but related vulnerability in the emergencyWithdraw() function allowed certain users to drain additional funds from the staking contract. The function contained a logic error referencing rewardDebt instead of user.amount when computing the quantity of tokens to return. This caused the contract to return far more tokens than stakers were owed. Early users who noticed the discrepancy withdrew repeatedly, depleting the contract and leaving later stakers with nothing to claim. The bug was introduced after Levyathan's initial CertiK security audit; CertiK later acknowledged it reviewed updated code but failed to catch the flaw during the re-audit.","heading":"Secondary Exploit: emergencyWithdraw Bug","sources":[{"url":"https://rekt.news/levyathan-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://levyathan-index.medium.com/post-mortem-levyathan-c3ff7f9a6f65","name":"levyathan-index.medium.com","type":"other","credibility":3},{"url":"https://levyathan-index.medium.com/levyathan-our-past-and-future-396b8e6f164b","name":"levyathan-index.medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Levyathan had undergone a security audit by CertiK prior to the exploit. CertiK's assessment identified 18 total issues, none labeled Critical. The emergencyWithdraw() bug was introduced or modified by a developer after the initial audit pass; CertiK reviewed the updated code but did not flag the error. After the exploit, CertiK publicly acknowledged: 'After internal investigation, it appears that you are absolutely correct. We failed to address the actual issues in our report, together with the incorrect suggestion of the fixes, ultimately lead to tremendous loss of your asset.' CertiK attributed the failure to human error and committed to improving its review processes. The episode became one of several high-profile examples of audited BSC protocols suffering exploits in 2021.","heading":"CertiK Audit Failure","sources":[{"url":"https://levyathan-index.medium.com/levyathan-our-past-and-future-396b8e6f164b","name":"levyathan-index.medium.com","type":"other","credibility":3},{"url":"https://rekt.news/levyathan-rekt","name":"rekt.news","type":"other","credibility":3}],"severity":"medium"},{"content":"The question of whether the exploit was an external attack or an inside job remains disputed. The development team argued that leaving the private keys on a public GitHub repository proved the incident was not orchestrated internally, since an insider would have had no need to use publicly visible credentials. Rekt.news and other observers questioned this logic, suggesting the public key disclosure could have served as deliberate cover, and characterized the team's post-exploit communications as 'tone-deaf' and deflecting of responsibility. No conclusive forensic evidence of insider involvement was publicly documented, and no arrests or regulatory actions were reported. The post-mortem published by the team stated they were cooperating with authorities to trace and recover stolen funds, which were bridged to Ethereum and alleged to have been routed through Tornado Cash.","heading":"Insider Involvement — Disputed","sources":[{"url":"https://rekt.news/levyathan-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://levyathan-index.medium.com/post-mortem-levyathan-c3ff7f9a6f65","name":"levyathan-index.medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"In the aftermath, the Levyathan team published multiple Medium posts requesting that users who had benefited from the emergencyWithdraw bug return funds voluntarily within one week. A multi-signature recovery wallet (0xf3381970372fcA75270C0d67956Fd8D6304377D7) was established to manage returned assets; approximately 265,185 BUSD was reported recovered at time of the final post. New developers who had offered to assist subsequently withdrew due to community hostility and depleted development reserves. The team announced all recovered assets would be directed to victim compensation rather than protocol continuation, and that official social channels and the website would be shut down. A third-party project, Longdrink Finance, independently airdropped 2,500 LONG tokens across 500 affected community members as a gesture of support; the Levyathan team explicitly disclaimed responsibility for Longdrink's security.","heading":"Recovery Efforts and Project Dissolution","sources":[{"url":"https://levyathan-index.medium.com/levyathan-our-past-and-future-396b8e6f164b","name":"levyathan-index.medium.com","type":"other","credibility":3},{"url":"https://levyathan-index.medium.com/post-mortem-levyathan-c3ff7f9a6f65","name":"levyathan-index.medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Several operational failures compounded the severity of the exploit. The Timelock controlling the MasterChef contract was not a multisignature contract, meaning a single compromised key was sufficient to execute ownership transfers. Private keys were stored in a public GitHub repository rather than in a secrets manager or hardware wallet. The emergencyWithdraw bug was introduced post-audit, indicating a lack of internal code review discipline before deployment. Collectively, these failures reflect a pattern of inadequate operational security that is common to exploited BSC-era yield farming projects.","heading":"Security Posture and Operational Red Flags","sources":[{"url":"https://rekt.news/levyathan-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://levyathan-index.medium.com/post-mortem-levyathan-c3ff7f9a6f65","name":"levyathan-index.medium.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2021-06","event":"Levyathan launches on Binance Smart Chain as an alleged first crypto index fund protocol on BSC; LEV token distributed via airdrop and sale.","source":"","date_original":"2021-06-01"},{"date":"2021-07","event":"CertiK completes security audit of Levyathan smart contracts, identifying 18 issues with none labeled Critical.","source":"","date_original":"2021-07-01"},{"date":"2021-07-28","event":"An unknown party submits a Timelock transaction to transfer ownership of the MasterChef contract, using private keys that had been left in Levyathan's public GitHub repository.","source":""},{"date":"2021-07-30","event":"Timelock delay expires; attacker executes ownership transfer, mints approximately 100 quintillion LEV tokens, dumps them on market, and bridges proceeds to Ethereum. LEV price collapses to near zero. Concurrent emergencyWithdraw bug allows early stakers to drain additional funds from the protocol.","source":""},{"date":"2021-07-30","event":"Levyathan team publishes initial post-mortem on Medium acknowledging the private key exposure and emergencyWithdraw bug. Recovery wallet address published.","source":""},{"date":"2021-08-05","event":"Rekt.news publishes detailed analysis of the exploit, questioning whether the public key story was a cover for an inside job and criticizing the team's communications.","source":""},{"date":"2021-08","event":"CertiK formally acknowledges audit failure via statement to the Levyathan team, accepting responsibility for missing the emergencyWithdraw vulnerability in the post-audit code review.","source":"","date_original":"2021-08-01"},{"date":"2021-08-10","event":"Levyathan publishes final Medium post announcing project dissolution, confirming development funds are depleted, new developers have withdrawn, and all recovered funds will be distributed to victims. Official channels to be shut down.","source":""}],"sources_used":[{"url":"https://rekt.news/levyathan-rekt","name":"rekt.news","type":"other","archive_url":"http://web.archive.org/web/20260322055937/https://rekt.news/levyathan-rekt","credibility":3,"archive_timestamp":"2026-03-22T05:59:37+00:00"},{"url":"https://levyathan-index.medium.com/post-mortem-levyathan-c3ff7f9a6f65","name":"levyathan-index.medium.com","type":"other","archive_url":"http://web.archive.org/web/20250910101345/https://levyathan-index.medium.com/post-mortem-levyathan-c3ff7f9a6f65","credibility":3,"archive_timestamp":"2025-09-10T10:13:45+00:00"},{"url":"https://levyathan-index.medium.com/levyathan-our-past-and-future-396b8e6f164b","name":"levyathan-index.medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:55.561487+00:00","updated_at":"2026-08-29T20:45:04.67881+00:00"}}