{"investigation":{"slug":"midas-capital","entity_name":"Midas Capital","trust_score":32,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"Midas Capital is a multichain DeFi isolated lending protocol that forked its codebase from Rari Capital's Fuse implementation. The protocol suffered two separate security exploits in 2023 totaling approximately $1.26 million in losses, with both incidents attributed to known smart contract vulnerabilities that had previously affected other Compound V2 forks. ZachXBT flagged the protocol, and the second exploit resulted in laundered funds routed through Tornado Cash.","sections":[{"content":"Midas Capital is a permissionless isolated lending and borrowing protocol that originated from an approved fork of Rari Capital's Fuse pool implementation. Conceptualized at LisCon 2021, the project aimed to expand Fuse-style isolated money markets to multiple EVM-compatible blockchains, targeting chains with deep liquidity where Rari's original deployment was absent. Unlike monolithic lending protocols such as Aave or Compound, Midas Capital allows any user to create customized, isolated lending pools with bespoke parameters including interest rate models, collateral factors, and supported assets. The protocol is built atop the Compound Finance V2 codebase, a lineage it shares with Rari Capital's Fuse. Midas Capital operated as a DAO within the broader Tribe DAO ecosystem, and offered a 25% token allocation to Tribe DAO, a proposal that passed with 94% governance support. Chains supported at various stages included Polygon, BNB Chain, and others. The lead engineer publicly associated with the project is Carlo Mazzaferro, described as a Data Scientist and Engineer based in Berlin.","heading":"Protocol Overview","sources":[{"url":"https://medium.com/midas-capital/introducing-midas-capital-bb6ce3a256a3","name":"medium.com","type":"other","credibility":3},{"url":"https://medium.com/midas-capital/tech-update-open-source-monorepo-and-building-new-primitives-for-defi-1a1ca21cf9ae","name":"medium.com","type":"other","credibility":3},{"url":"https://github.com/Midas-Protocol","name":"github.com","type":"other","credibility":3},{"url":"https://talk.harmony.one/t/midas-capital-permissionless-lending-borrowing-platform-infrastructure-for-daos-treasuries-individuals/11297","name":"talk.harmony.one","type":"other","credibility":3}],"severity":"medium"},{"content":"On January 15, 2023, the Jarvis Polygon pool operated by Midas Capital was exploited for approximately $660,000 via a read-only reentrancy vulnerability. The attack targeted the WMATIC-stMATIC Curve LP token, which had only recently been listed by the protocol with a supply cap of $250,000. The read-only reentrancy flaw is a known weakness in certain Curve LP token implementations: when liquidity is removed from a Curve pool, an unexpected callback allows the attacker to borrow assets at a stale, artificially elevated price of the LP token. Specifically, the contract's self.D value was updated after the callback, meaning borrows used an outdated self.D, while stMATIC-f was burned before the callback causing borrows to use an updated totalSupply(). This combination caused Midas Capital to overestimate the attacker's collateral by a significant margin. The stolen assets comprised jCHF (273,973), jEUR (368,058), jGBP (45,250), and agEUR (45,435), all of which were swapped to approximately 660,000 MATIC and transferred to Kucoin and Binance. Jarvis Network, whose synthetic fiat tokens were the primary assets drained, committed to covering the approximately $350,000 shortfall in jFIAT backing. Security firm PeckShield confirmed the exploit on-chain. Notably, the same read-only reentrancy vulnerability had previously been exploited against market.xyz in October 2022 for approximately $220,000, meaning the attack vector was a known risk at the time. Midas Capital attempted to contact the attacker to negotiate a bug bounty but no funds were recovered.","heading":"January 2023 Exploit: Jarvis Polygon Pool ($660,000)","sources":[{"url":"https://rekt.news/midas-capital-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://medium.com/neptune-mutual/how-was-midas-capital-exploited-f9d90926eaf2","name":"medium.com","type":"other","credibility":3},{"url":"https://beincrypto.com/midas-capital-releases-660000-exploit-post-mortem-defi-attacks-carry-into-2023/","name":"beincrypto.com","type":"other","credibility":3},{"url":"https://x.com/peckshield/status/1614774855999844352","name":"x.com","type":"other","credibility":3},{"url":"https://quillaudits.substack.com/p/midas-capital-has-suffered-a-loss","name":"quillaudits.substack.com","type":"other","credibility":3},{"url":"https://www.quadrigainitiative.com/hackfraudscam/midascapitalvirtualpricereentrancy.php","name":"quadrigainitiative.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On June 17, 2023 at 5:35 pm UTC, a second exploit struck an isolated pool on Midas Capital's BNB Chain deployment, this one targeting the pool supporting Ankr and Helio Finance. The attacker drained approximately $340,000 according to the team's post-mortem, though security firm PeckShield reported the total loss exceeded $600,000. The root cause was a rounding error in the Compound V2-derived lending logic, a vulnerability pattern that had previously been exploited against Hundred Finance in April 2023 for approximately $7 million. The attack was an exchange rate inflation exploit: the attacker took a flash loan of ANKR tokens from PancakeSwap and AlgebraPool (Thena), minted HAY/BUSD LP tokens, and manipulated the cToken redemption process. By keeping only 1,001 wei of cTokens outstanding after redeeming nearly all their position, the attacker controlled the exchange rate calculation. An incomplete fix to a prior Compound bug (previously identified in the Hundred Finance incident) allowed LP tokens with extremely low denomination to bypass security mechanisms. The attacker donated 259,826.61 HAY/BUSD LP tokens to the exploit contract, inflating the exchange rate so that 1,001 wei of cTokens represented approximately $519,000 in underlying value. The attacker then withdrew 519 LP tokens using just 1 wei of underlying. Per the team's post-mortem, the second phase of the attack also exploited missing borrow limits on ankrBNB collateralized by HAY/BUSD LP tokens. Following the exploit, PeckShield reported that approximately 510 BNB was laundered through Tornado Cash, with an additional 400 BNB also moved to the mixer according to CertiK. Further proceeds were bridged to Ethereum. The protocol paused all pools and contacted authorities. The team published a post-mortem and announced a strategic pivot toward a more permissioned design in which only whitelisted users would be allowed to interact with the protocol.","heading":"June 2023 Exploit: BNB Chain Ankr-Helio Pool ($600,000+)","sources":[{"url":"https://medium.com/midas-capital/midas-exploit-post-mortem-1ae266222994","name":"medium.com","type":"other","credibility":3},{"url":"https://beincrypto.com/midas-capital-pool-exploited/","name":"beincrypto.com","type":"other","credibility":3},{"url":"https://medium.com/neptune-mutual/understanding-midas-capital-exploit-759721f031f8","name":"medium.com","type":"other","credibility":3},{"url":"https://medium.com/kalos/midas-capital-hack-analysis-6fc9f4a48c92","name":"medium.com","type":"other","credibility":3},{"url":"https://www.olympix.ai/blog/midas-capital-lost-600k-due-to-rounding-issue","name":"olympix.ai","type":"other","credibility":3},{"url":"https://blocksec.com/blog/6-hundred-finance-incident-catalyzing-the-wave-of-precision-related-exploits-in-vulnerable-forked-protocols","name":"blocksec.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Midas Capital suffered two separate, technically distinct exploits within six months of each other in 2023. The January 2023 incident involved a read-only reentrancy vulnerability in Curve LP tokens — a known class of vulnerability that had previously been exploited on other protocols. The June 2023 incident involved a rounding and exchange rate inflation attack rooted in the Compound V2 codebase, also a known class of vulnerability that had affected Hundred Finance two months prior. The recurrence of exploits exploiting previously disclosed vulnerability classes raises questions about the protocol's security review process and its responsiveness to security advisories. The Midas Capital documentation references security audits (docs.midascapital.xyz/security/audit), but this page was unavailable at the time of investigation. The protocol's architecture as a permissionless fork of battle-tested but aging codebase (Compound V2 / Rari Fuse) exposes it to inherited vulnerabilities. Following the June 2023 exploit, the team announced a shift toward a permissioned model as a remediation measure. The exploit proceeds in the June 2023 incident were routed through Tornado Cash, a sanctioned mixing service, complicating on-chain recovery efforts.","heading":"Security Posture and Known Vulnerabilities","sources":[{"url":"https://rekt.news/midas-capital-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://medium.com/midas-capital/midas-exploit-post-mortem-1ae266222994","name":"medium.com","type":"other","credibility":3},{"url":"https://beincrypto.com/midas-capital-releases-660000-exploit-post-mortem-defi-attacks-carry-into-2023/","name":"beincrypto.com","type":"other","credibility":3},{"url":"https://blocksec.com/blog/6-hundred-finance-incident-catalyzing-the-wave-of-precision-related-exploits-in-vulnerable-forked-protocols","name":"blocksec.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Midas Capital was established as an approved fork of Rari Capital's Fuse protocol, with explicit governance approval from the Rari and Tribe DAO communities. The relationship was formalized through a 25% token allocation to Tribe DAO, ratified by 94% of participating governance voters. This placed Midas Capital as one of four constituent protocols within Tribe DAO alongside Fei Protocol, Rari Capital, and Volt Protocol. The Tribe DAO ecosystem itself encountered significant turbulence in 2022. Rari Capital's Fuse pools were exploited for approximately $80 million in April 2022, an incident that destabilized the broader Tribe DAO. Tribe DAO subsequently voted to wind down operations in August 2022. Midas Capital continued to operate independently after Tribe DAO's dissolution, but retained the inherited Fuse codebase that would later be the source of its own vulnerabilities. The lineage connecting Midas Capital's exploits to the broader pattern of Fuse/Compound V2 fork vulnerabilities is well-documented in security research from BlockSec and others.","heading":"Relationship to Rari Capital / Tribe DAO Ecosystem","sources":[{"url":"https://medium.com/midas-capital/introducing-midas-capital-bb6ce3a256a3","name":"medium.com","type":"other","credibility":3},{"url":"https://medium.com/midas-capital/future-of-midas-capital-337442511b93","name":"medium.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/tribe-dao-votes-in-favor-of-repaying-victims-of-80m-rari-hack","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://coinjournal.net/news/tribe-dao-finally-votes-to-reimburse-rari-hack-victims/","name":"coinjournal.net","type":"other","credibility":3}],"severity":"medium"},{"content":"ZachXBT, a pseudonymous on-chain investigator with a documented track record of flagging compromised and fraudulent DeFi protocols, has flagged Midas Capital as a risk entity. The specific basis for ZachXBT's flagging is not detailed in publicly available statements at the time of this investigation; however, the protocol's dual exploit history in 2023, use of Tornado Cash to launder exploit proceeds, and repeated deployment of known-vulnerable code in live pools are consistent with patterns ZachXBT has highlighted in other flagged protocols. Community risk monitors including PeckShield and CertiK both published alerts regarding the June 2023 exploit. The laundering of 510+ BNB through Tornado Cash following the June 2023 incident is a significant concern, as Tornado Cash has been sanctioned by the U.S. Office of Foreign Assets Control (OFAC) since August 2022. Whether the laundering was conducted by the attacker or a connected party has not been publicly adjudicated. No public regulatory actions against Midas Capital or its operators have been identified in available sources.","heading":"ZachXBT Flagging and Community Risk Signals","sources":[{"url":"https://beincrypto.com/midas-capital-pool-exploited/","name":"beincrypto.com","type":"other","credibility":3},{"url":"https://medium.com/neptune-mutual/understanding-midas-capital-exploit-759721f031f8","name":"medium.com","type":"other","credibility":3},{"url":"https://www.olympix.ai/blog/midas-capital-lost-600k-due-to-rounding-issue","name":"olympix.ai","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the June 2023 exploit, Midas Capital paused all pools across its deployments. The team's post-mortem announced a pivot toward a more secure, permissioned design restricting interaction to whitelisted users, representing a significant departure from the protocol's original permissionless ethos. No public announcement of a full protocol shutdown has been confirmed in available sources; however, the protocol's activity and social media presence appear significantly diminished following the second exploit. Users who deposited assets into the Ankr-Helio BNB Chain pool at the time of the June 2023 exploit suffered losses with no confirmed recovery. In the January 2023 Jarvis Polygon exploit, Jarvis Network covered the approximately $350,000 shortfall in synthetic fiat token backing, providing partial user relief in that instance. The cumulative losses across both 2023 exploits total approximately $1.26 million. The protocol has not released public updates confirming relaunch, migration, or formal wind-down as of available information.","heading":"Protocol Status and User Impact","sources":[{"url":"https://medium.com/midas-capital/midas-exploit-post-mortem-1ae266222994","name":"medium.com","type":"other","credibility":3},{"url":"https://beincrypto.com/midas-capital-pool-exploited/","name":"beincrypto.com","type":"other","credibility":3},{"url":"https://medium.com/@midascapital/moving-forward-jarvis-polygon-pool-exploit-a532074103f6","name":"medium.com","type":"other","credibility":3},{"url":"https://cryptopanic.com/news/17402093/Midas-Capital-Releases-660000-Exploit-Post-Mortem-DeFi-Attacks-Carry-Into-2023","name":"cryptopanic.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2021-10","event":"Midas Capital conceptualized at LisCon 2021 as a multichain deployment of Rari Capital's Fuse isolated lending protocol.","source":"","date_original":"2021-10-01"},{"date":"2022","event":"Midas Capital launched, offering Tribe DAO a 25% token allocation; proposal passed with 94% governance support.","source":"","date_original":"2022-01-01"},{"date":"2022-04","event":"Parent ecosystem Rari Capital's Fuse pools exploited for approximately $80 million; Tribe DAO destabilized.","source":"","date_original":"2022-04-01"},{"date":"2022-08","event":"Tribe DAO votes to wind down operations. Midas Capital continues independently.","source":"","date_original":"2022-08-01"},{"date":"2022-10","event":"Read-only reentrancy vulnerability in Curve LP tokens exploited against market.xyz for $220,000 — a known precursor to the January 2023 Midas Capital attack.","source":"","date_original":"2022-10-01"},{"date":"2023-01-15","event":"Jarvis Polygon pool exploited via read-only reentrancy on WMATIC-stMATIC Curve LP token collateral. Approximately $660,000 in jCHF, jEUR, jGBP, and agEUR stolen and swapped to MATIC. Jarvis Network covers ~$350,000 shortfall.","source":""},{"date":"2023-01-17","event":"Midas Capital publishes post-mortem on January exploit; attempts to contact attacker regarding bounty; no funds recovered.","source":""},{"date":"2023-04","event":"Hundred Finance exploited for approximately $7 million using the same Compound V2 rounding/inflation attack pattern that would later strike Midas Capital.","source":"","date_original":"2023-04-01"},{"date":"2023-06-17","event":"BNB Chain Ankr-Helio isolated pool exploited via exchange rate inflation attack (rounding vulnerability in Compound V2 fork). Approximately $340,000 drained per team post-mortem; PeckShield reports over $600,000 total. 510+ BNB laundered through Tornado Cash.","source":""},{"date":"2023-06-18","event":"Midas Capital pauses all pools, contacts authorities, and announces pivot toward permissioned protocol design.","source":""},{"date":"2023-06-20","event":"Midas Capital publishes post-mortem on June exploit detailing rounding vulnerability and incomplete fix inherited from Compound V2 / Hundred Finance patch lineage.","source":""}],"sources_used":[{"url":"https://medium.com/midas-capital/introducing-midas-capital-bb6ce3a256a3","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://medium.com/midas-capital/tech-update-open-source-monorepo-and-building-new-primitives-for-defi-1a1ca21cf9ae","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://github.com/Midas-Protocol","name":"github.com","type":"other","archive_url":"https://web.archive.org/web/20260830000940/https://github.com/Midas-Protocol","credibility":3,"archive_timestamp":"2026-08-30T00:09:40+00:00"},{"url":"https://talk.harmony.one/t/midas-capital-permissionless-lending-borrowing-platform-infrastructure-for-daos-treasuries-individuals/11297","name":"talk.harmony.one","type":"other","archive_url":"https://web.archive.org/web/20260829142039/https://talk.harmony.one/t/midas-capital-permissionless-lending-borrowing-platform-infrastructure-for-daos-treasuries-individuals/11297","credibility":3,"archive_timestamp":"2026-08-29T14:20:39+00:00"},{"url":"https://rekt.news/midas-capital-rekt","name":"rekt.news","type":"other","archive_url":"http://web.archive.org/web/20260322055932/https://rekt.news/midas-capital-rekt","credibility":3,"archive_timestamp":"2026-03-22T05:59:32+00:00"},{"url":"https://medium.com/neptune-mutual/how-was-midas-capital-exploited-f9d90926eaf2","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://beincrypto.com/midas-capital-releases-660000-exploit-post-mortem-defi-attacks-carry-into-2023/","name":"beincrypto.com","type":"other","archive_url":"http://web.archive.org/web/20260725134042/https://beincrypto.com/midas-capital-releases-660000-exploit-post-mortem-defi-attacks-carry-into-2023/","credibility":3,"archive_timestamp":"2026-07-25T13:40:42+00:00"},{"url":"https://x.com/peckshield/status/1614774855999844352","name":"x.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://quillaudits.substack.com/p/midas-capital-has-suffered-a-loss","name":"quillaudits.substack.com","type":"other","archive_url":"https://web.archive.org/web/20260829141256/https://quillaudits.substack.com/p/midas-capital-has-suffered-a-loss","credibility":3,"archive_timestamp":"2026-08-29T14:12:56+00:00"},{"url":"https://www.quadrigainitiative.com/hackfraudscam/midascapitalvirtualpricereentrancy.php","name":"quadrigainitiative.com","type":"other","archive_url":"https://web.archive.org/web/20260829152852/https://www.quadrigainitiative.com/hackfraudscam/midascapitalvirtualpricereentrancy.php","credibility":3,"archive_timestamp":"2026-08-29T15:28:52+00:00"},{"url":"https://medium.com/midas-capital/midas-exploit-post-mortem-1ae266222994","name":"medium.com","type":"other","archive_url":"http://web.archive.org/web/20260610104509/https://medium.com/midas-capital/midas-exploit-post-mortem-1ae266222994","credibility":3,"archive_timestamp":"2026-06-10T10:45:09+00:00"},{"url":"https://beincrypto.com/midas-capital-pool-exploited/","name":"beincrypto.com","type":"other","archive_url":"http://web.archive.org/web/20260725134029/https://beincrypto.com/midas-capital-pool-exploited/","credibility":3,"archive_timestamp":"2026-07-25T13:40:29+00:00"},{"url":"https://medium.com/neptune-mutual/understanding-midas-capital-exploit-759721f031f8","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://medium.com/kalos/midas-capital-hack-analysis-6fc9f4a48c92","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.olympix.ai/blog/midas-capital-lost-600k-due-to-rounding-issue","name":"olympix.ai","type":"other","archive_url":"http://web.archive.org/web/20251017134547/https://olympix.ai/blog/midas-capital-lost-600k-due-to-rounding-issue","credibility":3,"archive_timestamp":"2025-10-17T13:45:47+00:00"},{"url":"https://blocksec.com/blog/6-hundred-finance-incident-catalyzing-the-wave-of-precision-related-exploits-in-vulnerable-forked-protocols","name":"blocksec.com","type":"other","archive_url":"http://web.archive.org/web/20260519012533/https://blocksec.com/blog/6-hundred-finance-incident-catalyzing-the-wave-of-precision-related-exploits-in-vulnerable-forked-protocols","credibility":3,"archive_timestamp":"2026-05-19T01:25:33+00:00"},{"url":"https://medium.com/midas-capital/future-of-midas-capital-337442511b93","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://cointelegraph.com/news/tribe-dao-votes-in-favor-of-repaying-victims-of-80m-rari-hack","name":"cointelegraph.com","type":"other","archive_url":"http://web.archive.org/web/20251018115243/https://cointelegraph.com/news/tribe-dao-votes-in-favor-of-repaying-victims-of-80m-rari-hack","credibility":3,"archive_timestamp":"2025-10-18T11:52:43+00:00"},{"url":"https://coinjournal.net/news/tribe-dao-finally-votes-to-reimburse-rari-hack-victims/","name":"coinjournal.net","type":"other","archive_url":"https://web.archive.org/web/20260829125456/https://coinjournal.net/news/when-should-i-buy-tether/?dynamic","credibility":3,"archive_timestamp":"2026-08-29T12:54:56+00:00"},{"url":"https://medium.com/@midascapital/moving-forward-jarvis-polygon-pool-exploit-a532074103f6","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://cryptopanic.com/news/17402093/Midas-Capital-Releases-660000-Exploit-Post-Mortem-DeFi-Attacks-Carry-Into-2023","name":"cryptopanic.com","type":"other","archive_url":"https://web.archive.org/web/20260829131803/https://cryptopanic.com/news/17402093/Midas-Capital-Releases-660000-Exploit-Post-Mortem-DeFi-Attacks-Carry-Into-2023","credibility":3,"archive_timestamp":"2026-08-29T13:18:03+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:45.196301+00:00","updated_at":"2026-08-30T01:16:31.991393+00:00"}}