{"investigation":{"slug":"odinfun","entity_name":"Odin.Fun","trust_score":22,"severity_base":null,"score_modifier":0,"confidence":0.87,"status":"published","content_type":"investigation","summary":"Odin.Fun (ODIN•FUN) is a Bitcoin-based meme coin launchpad and automated market maker launched in January 2025 by Bioniq co-founder Bob Bodily, designed as a Pump.fun analogue for Bitcoin Runes tokens. The platform has suffered at least four confirmed security incidents within its first year of operation, including a critical $7 million (58.2 BTC) AMM liquidity manipulation exploit in August 2025 that left the treasury insolvent and unable to fully compensate affected users. As of the latest available reporting (August–September 2025), the platform remained halted pending security audits, with no committed reopening timeline.","sections":[{"content":"Odin.Fun launched in January 2025 as Bitcoin's first meme coin launchpad modeled after Solana's Pump.fun. It was built and operated by Bob Bodily, co-founder and CEO of Bioniq, a Bitcoin-based NFT and collectibles marketplace. The platform employs a bonding curve pricing model for token launches, transitioning tokens to an automated market maker (AMM) once they reach a market cap of one Bitcoin. Underlying infrastructure uses a proprietary application chain called Valhalla, built on top of the Internet Computer Protocol (ICP), which the team claimed enables two-second transaction finality. A strategic financing round led by Taproot Wizards — the Bitcoin Ordinals project co-founded by Udi Wertheimer — was announced on March 14, 2025, though the investment amount was not disclosed. The platform supported trading in Bitcoin Runes tokens and allowed permissionless token creation.","heading":"Platform Overview","sources":[{"url":"https://decrypt.co/303687/bitcoin-meme-coin-launchpad-odin-fun-runes","name":"decrypt.co","type":"other","credibility":3},{"url":"https://thedefiant.io/news/nfts-and-web3/odin-fun-wants-to-replicate-pump-fun-for-bitcoin-runes","name":"thedefiant.io","type":"other","credibility":3},{"url":"https://www.cryptotimes.io/2025/03/16/taproot-wizard-bankrolls-odin-fun-a-bitcoin-trading-platform/","name":"cryptotimes.io","type":"other","credibility":3}],"severity":"medium"},{"content":"Odin.Fun experienced at least four distinct security incidents within approximately six months of its launch, establishing a pattern of critical infrastructure failures.\n\nIncident 1 — March 7, 2025 (Deposit Synchronization Bug): A bug in the platform's hard deposit synchronization code caused 74 BTC to disappear from apparent on-chain records. The co-founders stated publicly that actual user funds were not lost and attributed the anomaly to a technical accounting error, not an external theft. No independent audit verified this claim.\n\nIncident 2 — April 14, 2025 (Sign-In With Bitcoin Authentication Exploit, $178,700): CEO Bob Bodily's personal Odin.Fun account was compromised, resulting in the liquidation of approximately $178,700 in assets. The root cause was identified as a critical authentication bypass vulnerability in the 'Sign-In With Bitcoin' (SIWB) canister used by the platform. The SIWB library failed to verify that the public key used to validate a wallet signature was actually associated with the claimed Bitcoin address, enabling attackers to impersonate any user account. AstroX subsequently developed and released a patch. Odin.Fun deployed the fix and halted trading pending session expiry. The $ODINDOG flagship token dropped 57.6% within 24 hours of the announcement, with other platform tokens losing 30–70% of their value. The DFINITY developer forum published a detailed post-mortem on the vulnerability.\n\nIncident 3 — August 12–13, 2025 (AMM Liquidity Manipulation Exploit, 58.2 BTC / approximately $7 million): Attackers exploited a design flaw in Odin.Fun's AMM liquidity code. The platform's AMM relied solely on internal supply ratios to price tokens rather than external price feeds, creating a critical single point of failure. Attackers deposited large quantities of worthless tokens — primarily SATOSHI•NAKAMOTO and ODINPEPE — into BTC-paired liquidity pools. Through self-trading and overweighted deposits, they artificially inflated the apparent value of these tokens within the AMM's internal accounting. Once the manipulated valuations were established, the attackers withdrew disproportionate amounts of genuine Bitcoin from the pools. Platform reserves dropped from 291 BTC to 232.8 BTC within two hours. Security analysts identified two coordinated attacker accounts: one 'sleeper cell' wallet dormant since June 20, 2025 that reactivated 23 minutes before the attack, and one freshly created account used the same day. Post-incident analysis by Halborn, QuillAudits, and OKX characterized the vulnerability as 'trivial' and 'well-known,' noting the exploited code was deployed without prior security audit despite CertiK records showing no completed reviews for the platform. Bob Bodily publicly attributed the attack to 'malicious users primarily linked to groups in China.' Odin.Fun contacted U.S. law enforcement and coordinated with Binance and OKX to engage Chinese authorities.","heading":"Security Incident History — Pattern of Repeated Exploits","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-odin-fun-hack-august-2025","name":"halborn.com","type":"other","credibility":3},{"url":"https://www.okx.com/en-eu/learn/bitcoin-hack-odin-fun-price-manipulation","name":"okx.com","type":"other","credibility":3},{"url":"https://crypto.news/bitcoin-memecoin-launchpad-odin-fun-exploited-2025/","name":"crypto.news","type":"other","credibility":3},{"url":"https://www.coindesk.com/markets/2025/08/13/memecoin-launchpad-odin-fun-suffers-usd7m-liquidity-exploit","name":"coindesk.com","type":"other","credibility":3},{"url":"https://decrypt.co/334986/bitcoin-meme-coin-launchpad-7-million-liqudity-attack","name":"decrypt.co","type":"other","credibility":3},{"url":"https://www.theblock.co/post/366704/bitcoin-launchpad-odin-fun-exploit","name":"theblock.co","type":"other","credibility":3},{"url":"https://forum.dfinity.org/t/critical-vulnerability-in-sign-in-with-bitcoin-siwb-used-to-attack-odin-fun-learnings-and-discussion/44721","name":"forum.dfinity.org","type":"other","credibility":3},{"url":"https://mpost.io/odin-fun-halts-platform-activity-following-co-founders-account-breach-and-178k-liquidation/","name":"mpost.io","type":"other","credibility":3},{"url":"https://rekt.news/odin-fun-rekt","name":"rekt.news","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the August 2025 exploit, Odin.Fun co-founder Bob Bodily publicly acknowledged that the platform's treasury held insufficient funds to fully compensate affected users. Bodily stated the team had 'ideas' for compensation but had not finalized any concrete plan. As of August 19, 2025, the team indicated it was working with undisclosed partners to achieve 1:1 backing of user deposits prior to reopening, but could not commit to a timeline. A full security audit was described as a prerequisite for resuming trading, with the audit itself expected to take approximately one week — but subsequent reporting found the platform unable to set any definitive reopening date. The platform stated that funds stolen by the attacker had been 'frozen in various CEXs,' though no formal confirmation from Binance or OKX of specific frozen amounts was publicly reported. The failure to launch with audited code, combined with treasury insolvency after the exploit, represents a critical risk factor for deposited user funds.","heading":"User Fund Insolvency and Compensation Failure","sources":[{"url":"https://www.cryptopolitan.com/odin-fun-not-committed-to-trading-timeline/","name":"cryptopolitan.com","type":"other","credibility":3},{"url":"https://www.mitrade.com/insights/news/live-news/article-3-1051401-20250819","name":"mitrade.com","type":"other","credibility":3},{"url":"https://www.bitget.com/news/detail/12560604919239","name":"bitget.com","type":"other","credibility":3},{"url":"https://quillaudits.medium.com/how-odin-fun-lost-58-2-btc-eb56757c8596","name":"quillaudits.medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Odin.Fun's underlying technology stack, named Valhalla, is built on the Internet Computer Protocol (ICP) and operates as an application chain. The platform employs threshold signature (TSS) mechanisms and multi-party computation (MPC) for asset custody. However, security researchers and community observers noted that the team did not publicly disclose detailed implementation specifics for the Layer 2 architecture, raising transparency concerns. Critically, CertiK records show no completed security audits of the platform's AMM code prior to the August 2025 exploit. The Halborn post-exploit analysis characterized the exploited AMM vulnerability as representing 'trivial, well-known vulnerabilities' that should have been caught by any standard audit, stating that 'vulnerable code was deployed without prior audit.' Multiple separate vulnerability classes — authentication bypass (April 2025) and AMM logic manipulation (August 2025) — suggest systemic deficiencies in the platform's security development practices rather than isolated incidents. The DFINITY developer community subsequently published a detailed forum thread analyzing lessons for other ICP-based projects building on the SIWB library.","heading":"Technical Architecture and Security Transparency Concerns","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-odin-fun-hack-august-2025","name":"halborn.com","type":"other","credibility":3},{"url":"https://forum.dfinity.org/t/critical-vulnerability-in-sign-in-with-bitcoin-siwb-used-to-attack-odin-fun-learnings-and-discussion/44721","name":"forum.dfinity.org","type":"other","credibility":3},{"url":"https://www.panewslab.com/en/articles/lohm2jqx","name":"panewslab.com","type":"other","credibility":3},{"url":"https://forum.dfinity.org/t/lets-learn-from-the-odin-fun-hack-preventing-attack-vectors/43848","name":"forum.dfinity.org","type":"other","credibility":3}],"severity":"medium"},{"content":"The security incidents at Odin.Fun had severe, cascading effects on the tokens launched and traded on the platform. Following the April 2025 account breach, the platform's flagship token ODINDOG dropped 57.6% in 24 hours. Tokens ODINAPE, SATOSHI, ODINGOLD, and ODINSTAS all recorded losses of 30–70% in the same period. The August 2025 AMM exploit caused ODINDOG to decline a further 40% immediately after the breach was disclosed. One report referenced that Odin.Fun's monthly transaction volume had previously exceeded $84 million USD, indicating the platform had achieved material adoption prior to the exploit. The concentration of trading volume in platform-native tokens meant the liquidity crisis from the exploit directly impaired exit paths for holders of all tokens launched through Odin.Fun.","heading":"Market Impact and Token Losses","sources":[{"url":"https://mpost.io/odin-fun-halts-platform-activity-following-co-founders-account-breach-and-178k-liquidation/","name":"mpost.io","type":"other","credibility":3},{"url":"https://crypto.news/odin-fun-memecoins-crash-as-platform-suspends-trading-over-security-breach/","name":"crypto.news","type":"other","credibility":3},{"url":"https://www.panewslab.com/en/articles/lohm2jqx","name":"panewslab.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/markets/2025/08/13/memecoin-launchpad-odin-fun-suffers-usd7m-liquidity-exploit","name":"coindesk.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the August 2025 exploit, Odin.Fun stated it had contacted U.S. law enforcement agencies and was cooperating with major centralized exchanges Binance and OKX in tracing stolen funds. Bodily indicated that OKX and Binance were engaging Chinese authorities, consistent with his attribution of the attack to China-based hacking groups. As of the latest available reporting (August 19, 2025), no arrests had been announced, no stolen BTC had been publicly confirmed as recovered, and no specific amounts from exchange freeze actions had been disclosed. On-chain security firm PeckShield was credited with initially disclosing the breach publicly via X, citing community reports showing the anomalous BTC reserve drop.","heading":"Law Enforcement and Exchange Cooperation","sources":[{"url":"https://www.coindesk.com/markets/2025/08/13/memecoin-launchpad-odin-fun-suffers-usd7m-liquidity-exploit","name":"coindesk.com","type":"other","credibility":3},{"url":"https://decrypt.co/334986/bitcoin-meme-coin-launchpad-7-million-liqudity-attack","name":"decrypt.co","type":"other","credibility":3},{"url":"https://www.cryptopolitan.com/odin-fun-not-committed-to-trading-timeline/","name":"cryptopolitan.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2025","event":"Odin.Fun launches as Bitcoin's first meme coin launchpad, built by Bioniq co-founder Bob Bodily, modeling the Pump.fun bonding curve mechanism for Bitcoin Runes tokens.","source":"","date_original":"2025-01-01"},{"date":"2025-03-07","event":"Community members report 74 BTC disappearing from Odin.Fun's apparent on-chain records. The team attributes this to a deposit synchronization bug and states user funds are safe, with no third-party verification.","source":""},{"date":"2025-03-14","event":"Taproot Wizards leads a strategic investment round in Odin.Fun; investment amount undisclosed.","source":""},{"date":"2025-04-14","event":"CEO Bob Bodily's Odin.Fun account is compromised via a critical vulnerability in the Sign-In With Bitcoin (SIWB) authentication library; $178,700 in assets liquidated. Platform halts trading and withdrawals. ODINDOG drops 57.6% in 24 hours.","source":""},{"date":"2025-04-15","event":"AstroX releases a patch for the SIWB authentication bypass vulnerability. DFINITY developer forum publishes a post-mortem. Odin.Fun deploys the fix.","source":""},{"date":"2025-06-20","event":"One of the eventual August 2025 exploit attacker wallets (the 'sleeper cell') makes its first deposit, acquiring SATOSHI tokens — identified in post-incident forensics as early-stage exploit preparation.","source":""},{"date":"2025-08-12","event":"AMM liquidity manipulation exploit begins. Attackers using coordinated accounts drain 58.2 BTC (approximately $7 million) from Odin.Fun's liquidity pools within two hours by inflating worthless SATOSHI•NAKAMOTO and ODINPEPE token valuations. Platform reserves drop from 291 BTC to 232.8 BTC. Odin.Fun halts all trading and withdrawals.","source":""},{"date":"2025-08-13","event":"PeckShield discloses the breach on X. CoinDesk, Decrypt, and The Block publish initial reports. Bob Bodily confirms treasury cannot fully cover losses and pledges compensation plans.","source":""},{"date":"2025-08-19","event":"Odin.Fun posts a recovery update confirming stolen funds partially frozen at exchanges, stating it cannot commit to a trading resumption timeline. Halborn, QuillAudits, and OKX publish technical post-mortems characterizing the exploit as involving well-known, auditable vulnerability classes deployed without prior audit.","source":""}],"sources_used":[{"url":"https://decrypt.co/303687/bitcoin-meme-coin-launchpad-odin-fun-runes","name":"decrypt.co","type":"other","archive_url":"http://web.archive.org/web/20260121195540/https://decrypt.co/303687/bitcoin-meme-coin-launchpad-odin-fun-runes","credibility":3,"archive_timestamp":"2026-01-21T19:55:40+00:00"},{"url":"https://thedefiant.io/news/nfts-and-web3/odin-fun-wants-to-replicate-pump-fun-for-bitcoin-runes","name":"thedefiant.io","type":"other","archive_url":"http://web.archive.org/web/20250906081830/https://thedefiant.io/news/nfts-and-web3/odin-fun-wants-to-replicate-pump-fun-for-bitcoin-runes","credibility":3,"archive_timestamp":"2025-09-06T08:18:30+00:00"},{"url":"https://www.cryptotimes.io/2025/03/16/taproot-wizard-bankrolls-odin-fun-a-bitcoin-trading-platform/","name":"cryptotimes.io","type":"other","archive_url":"http://web.archive.org/web/20260726044358/https://www.cryptotimes.io/2025/03/16/taproot-wizard-bankrolls-odin-fun-a-bitcoin-trading-platform/","credibility":3,"archive_timestamp":"2026-07-26T04:43:58+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-odin-fun-hack-august-2025","name":"halborn.com","type":"other","archive_url":"http://web.archive.org/web/20260605223709/https://www.halborn.com/blog/post/explained-the-odin-fun-hack-august-2025","credibility":3,"archive_timestamp":"2026-06-05T22:37:09+00:00"},{"url":"https://www.okx.com/en-eu/learn/bitcoin-hack-odin-fun-price-manipulation","name":"okx.com","type":"other","archive_url":"http://web.archive.org/web/20260725162328/https://www.okx.com/en-eu/learn/bitcoin-hack-odin-fun-price-manipulation","credibility":3,"archive_timestamp":"2026-07-25T16:23:28+00:00"},{"url":"https://crypto.news/bitcoin-memecoin-launchpad-odin-fun-exploited-2025/","name":"crypto.news","type":"other","archive_url":"http://web.archive.org/web/20260119060613/https://crypto.news/bitcoin-memecoin-launchpad-odin-fun-exploited-2025/","credibility":3,"archive_timestamp":"2026-01-19T06:06:13+00:00"},{"url":"https://www.coindesk.com/markets/2025/08/13/memecoin-launchpad-odin-fun-suffers-usd7m-liquidity-exploit","name":"coindesk.com","type":"other","archive_url":"http://web.archive.org/web/20260725145019/https://www.coindesk.com/markets/2025/08/13/memecoin-launchpad-odin-fun-suffers-usd7m-liquidity-exploit","credibility":3,"archive_timestamp":"2026-07-25T14:50:19+00:00"},{"url":"https://decrypt.co/334986/bitcoin-meme-coin-launchpad-7-million-liqudity-attack","name":"decrypt.co","type":"other","archive_url":"http://web.archive.org/web/20260420093859/https://decrypt.co/334986/bitcoin-meme-coin-launchpad-7-million-liqudity-attack","credibility":3,"archive_timestamp":"2026-04-20T09:38:59+00:00"},{"url":"https://www.theblock.co/post/366704/bitcoin-launchpad-odin-fun-exploit","name":"theblock.co","type":"other","archive_url":"http://web.archive.org/web/20251002151820/https://www.theblock.co/post/366704/bitcoin-launchpad-odin-fun-exploit","credibility":3,"archive_timestamp":"2025-10-02T15:18:20+00:00"},{"url":"https://forum.dfinity.org/t/critical-vulnerability-in-sign-in-with-bitcoin-siwb-used-to-attack-odin-fun-learnings-and-discussion/44721","name":"forum.dfinity.org","type":"other","archive_url":"https://web.archive.org/web/20260829115114/https://forum.dfinity.org/t/critical-vulnerability-in-sign-in-with-bitcoin-siwb-used-to-attack-odin-fun-learnings-and-discussion/44721","credibility":3,"archive_timestamp":"2026-08-29T11:51:14+00:00"},{"url":"https://mpost.io/odin-fun-halts-platform-activity-following-co-founders-account-breach-and-178k-liquidation/","name":"mpost.io","type":"other","archive_url":"https://web.archive.org/web/20260829081253/https://mpost.io/odin-fun-halts-platform-activity-following-co-founders-account-breach-and-178k-liquidation/","credibility":3,"archive_timestamp":"2026-08-29T08:12:53+00:00"},{"url":"https://rekt.news/odin-fun-rekt","name":"rekt.news","type":"other","archive_url":"http://web.archive.org/web/20260313110952/https://rekt.news/odin-fun-rekt","credibility":3,"archive_timestamp":"2026-03-13T11:09:52+00:00"},{"url":"https://www.cryptopolitan.com/odin-fun-not-committed-to-trading-timeline/","name":"cryptopolitan.com","type":"other","archive_url":"http://web.archive.org/web/20250911114238/https://www.cryptopolitan.com/odin-fun-not-committed-to-trading-timeline/","credibility":3,"archive_timestamp":"2025-09-11T11:42:38+00:00"},{"url":"https://www.mitrade.com/insights/news/live-news/article-3-1051401-20250819","name":"mitrade.com","type":"other","archive_url":"https://web.archive.org/web/20260829051039/https://www.mitrade.com/insights/news/live-news/article-3-1051401-20250819","credibility":3,"archive_timestamp":"2026-08-29T05:10:39+00:00"},{"url":"https://www.bitget.com/news/detail/12560604919239","name":"bitget.com","type":"other","archive_url":"https://web.archive.org/web/20260829044219/https://www.bitget.com/news/detail/12560604919239","credibility":3,"archive_timestamp":"2026-08-29T04:42:19+00:00"},{"url":"https://quillaudits.medium.com/how-odin-fun-lost-58-2-btc-eb56757c8596","name":"quillaudits.medium.com","type":"other","archive_url":"http://web.archive.org/web/20251017173811/https://quillaudits.medium.com/how-odin-fun-lost-58-2-btc-eb56757c8596","credibility":3,"archive_timestamp":"2025-10-17T17:38:11+00:00"},{"url":"https://www.panewslab.com/en/articles/lohm2jqx","name":"panewslab.com","type":"other","archive_url":"http://web.archive.org/web/20251106023643/https://www.panewslab.com/en/articles/lohm2jqx","credibility":3,"archive_timestamp":"2025-11-06T02:36:43+00:00"},{"url":"https://forum.dfinity.org/t/lets-learn-from-the-odin-fun-hack-preventing-attack-vectors/43848","name":"forum.dfinity.org","type":"other","archive_url":"http://web.archive.org/web/20250906072705/https://forum.dfinity.org/t/lets-learn-from-the-odin-fun-hack-preventing-attack-vectors/43848","credibility":3,"archive_timestamp":"2025-09-06T07:27:05+00:00"},{"url":"https://crypto.news/odin-fun-memecoins-crash-as-platform-suspends-trading-over-security-breach/","name":"crypto.news","type":"other","archive_url":"http://web.archive.org/web/20251017172746/https://crypto.news/odin-fun-memecoins-crash-as-platform-suspends-trading-over-security-breach/","credibility":3,"archive_timestamp":"2025-10-17T17:27:46+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:21.878603+00:00","updated_at":"2026-08-29T12:34:18.251457+00:00"}}