{"investigation":{"slug":"revest-finance","entity_name":"Revest Finance","trust_score":28,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"Revest Finance is an Ethereum DeFi protocol that tokenizes ERC-20 assets into Financial NFTs (FNFTs) using the ERC-1155 standard, allowing users to lock and manage assets with programmable release conditions. On March 27, 2022, the protocol suffered a reentrancy attack that resulted in approximately $2 million in user funds stolen, with the team publicly acknowledging it lacked the resources to fully reimburse victims. The protocol remains technically active with extremely low TVL and a token (RVST) that has declined over 99% from its all-time high.","sections":[{"content":"On March 27, 2022, at approximately 1:41 AM UTC, Revest Finance's smart contracts were exploited via a reentrancy attack, resulting in the theft of approximately $2 million in user-deposited tokens. The attacker exploited a flaw in the mintAddressLock function of the ERC-1155 token vault contract. The fnftId state variable was not updated until the end of the minting routine, allowing the attacker to re-enter the contract through the onERC1155Received callback and overwrite the depositAmount of an existing FNFT position with a new, inflated value. The attacker minted two FNFTs with zero token deposits, then minted 360,000 additional FNFTs, re-entering the depositAdditionalToFNFT function via the ERC-1155 callback to overwrite the deposit amount before the lock ID was updated. This resulted in 360,001 FNFTs each carrying a depositAmount of 1e18 tokens, which were then redeemed against protocol reserves. Stolen assets included approximately 715 million BLOCKS DAO tokens (valued at approximately $1.7 million), 7.7 million ECO tokens (approximately $100,000), 352,836 RENA tokens (approximately $120,000), 579 LYXe tokens (approximately $10,000), and minor amounts of ConstitutionDAO tokens. The attacker's address was 0xef967ece5322c0d7d26dab41778acb55ce5bd58b. Following the theft, the attacker swapped all stolen tokens to ETH via decentralized exchanges and deposited the proceeds into Tornado Cash, making on-chain recovery effectively impossible.","heading":"March 2022 Reentrancy Exploit","sources":[{"url":"https://rekt.news/revest-finance-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://therecord.media/2-million-stolen-from-defi-protocol-revest-finance-platform-unable-to-reimburse-victims","name":"therecord.media","type":"other","credibility":3},{"url":"https://slowmist.medium.com/revest-finance-incident-analysis-6fcd9b6be207","name":"slowmist.medium.com","type":"other","credibility":3},{"url":"https://blocksecteam.medium.com/revest-finance-vulnerabilities-more-than-re-entrancy-1609957b742f","name":"blocksecteam.medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Security researchers at BlockSec identified a second, distinct logic vulnerability in the handleMultipleDeposits function that was separate from the reentrancy flaw. This bug allowed the depositAmount of an original FNFT lock to be incorrectly modified when creating a new lock via depositAdditionalToFNFT. Unlike the reentrancy attack, this vulnerability required no callback mechanism and could be exploited in a simpler, more direct manner. BlockSec described it as a 'far more simple' exploitation path. The existence of this second vulnerability suggests that the codebase contained compounding security flaws not identified during the pre-launch Solidity Finance audit.","heading":"Additional Logic Vulnerability Identified Post-Exploit","sources":[{"url":"https://blocksecteam.medium.com/revest-finance-vulnerabilities-more-than-re-entrancy-1609957b742f","name":"blocksecteam.medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Prior to the exploit, Revest Finance's contracts had been audited by Solidity Finance. The critical reentrancy vulnerability went undetected in this audit as well as in multiple peer reviews conducted by the team. Following the exploit, CEO Rob Montgomery described it as a 'highly sophisticated attack on a vulnerability that went unnoticed during our Solidity Finance audit as well as multiple peer-reviews.' Solidity Finance subsequently conducted a follow-up audit free of charge. The recovery plan committed to commissioning additional audits from Trail of Bits and OpenZeppelin, though it is not publicly confirmed whether these were completed. SourceHat (formerly Solidity Finance) published an audit for Revest Finance that is accessible on their website.","heading":"Audit History and Security Oversight","sources":[{"url":"https://revestfinance.medium.com/revest-protocol-exploit-recovery-plan-b06ca33fbdf5","name":"revestfinance.medium.com","type":"other","credibility":3},{"url":"https://therecord.media/2-million-stolen-from-defi-protocol-revest-finance-platform-unable-to-reimburse-victims","name":"therecord.media","type":"other","credibility":3},{"url":"https://sourcehat.com/audits/RevestFinance/","name":"sourcehat.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The Revest team was alerted to the ongoing exploit at 2:24 AM UTC by the BLOCKS DAO development team, approximately 43 minutes after the attack began. Within approximately 70 seconds of receiving the alert, the team halted RVST token transfers, preventing the attacker from draining the RVST-ETH liquidity pool on Uniswap and avoiding an estimated additional $1.15 million in losses. CEO Rob Montgomery publicly acknowledged that the company did not possess sufficient funds for meaningful financial recompense and did not carry DeFi insurance. The stated recovery plan proposed partnering with BLOCKS DAO on an NFT series intended to raise approximately 700 ETH to reimburse the roughly 650 ETH stolen during the exploit. The Medium recovery post acknowledged: 'While we do not possess the funds needed for meaningful financial recompense...we promise to do everything within our power to make things as right as they can possibly be made.' No concrete structured reimbursement plan with specific amounts or timelines for individual victims was publicly detailed. The protocol contracts were patched and reactivated with universal reentrancy guards, and additional security controls including circuit breakers were implemented.","heading":"Team Response and Victim Reimbursement","sources":[{"url":"https://revestfinance.medium.com/revest-protocol-exploit-recovery-plan-b06ca33fbdf5","name":"revestfinance.medium.com","type":"other","credibility":3},{"url":"https://revestfinance.medium.com/revest-finance-contract-reactivation-and-patch-deployment-2054a614bfea","name":"revestfinance.medium.com","type":"other","credibility":3},{"url":"https://therecord.media/2-million-stolen-from-defi-protocol-revest-finance-platform-unable-to-reimburse-victims","name":"therecord.media","type":"other","credibility":3}],"severity":"medium"},{"content":"The RVST token reached its all-time high of approximately $2.04 prior to the exploit and declined sharply thereafter. As of available data, the token trades more than 99% below its all-time high, with a market capitalization under $125,000. The protocol's Total Value Locked (TVL) is reported at approximately $94,000. The GitHub repository for RevestV2-Public shows activity as recently as September 2024, and Medium posts from the team appear through August 2024, indicating continued development activity at a reduced scale. The protocol has pivoted to include the Resonate product for yield tokenization in addition to its original FNFT vault functionality.","heading":"Token Performance and Current Protocol Status","sources":[{"url":"https://defillama.com/protocol/revest-finance","name":"defillama.com","type":"other","credibility":3},{"url":"https://www.coingecko.com/en/coins/revest-finance","name":"coingecko.com","type":"other","credibility":3},{"url":"https://github.com/Revest-Finance","name":"github.com","type":"other","credibility":3},{"url":"https://revestfinance.medium.com/","name":"revestfinance.medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Rob Montgomery is the founder and CEO of Revest Finance. He holds a B.S. and M.S. in Mechanical Engineering from the Georgia Institute of Technology and has described himself as a long-time Ethereum miner and blockchain researcher. He subsequently co-founded InfiniFi Labs according to his Crunchbase profile. No regulatory actions, law enforcement proceedings, or fraud allegations have been identified against Montgomery or other named team members in connection with the exploit or the protocol's operations.","heading":"Founder and Team Background","sources":[{"url":"https://theorg.com/org/revest-finance/org-chart/rob-montgomery","name":"theorg.com","type":"other","credibility":3},{"url":"https://www.crunchbase.com/person/rob-montgomery-296f","name":"crunchbase.com","type":"other","credibility":3},{"url":"https://therecord.media/2-million-stolen-from-defi-protocol-revest-finance-platform-unable-to-reimburse-victims","name":"therecord.media","type":"other","credibility":3}],"severity":"medium"},{"content":"Revest Finance was ranked #67 on the rekt.news leaderboard at the time of reporting, a site that catalogues DeFi exploits by losses. The incident received coverage from The Record (Recorded Future News), SlowMist, BlockSec, EcoFi, and web3isgoinggreat.com. ZachXBT, the on-chain investigator, has flagged this entity in relation to its exploit history, though no specific ZachXBT thread or Mirror post dedicated exclusively to Revest Finance was identified through available search results at the time of this investigation. The BLOCKS DAO token suffered an alleged 76% price decline as a result of the exploit, with collateral damage to holders of protocols that had deposited into the Revest vaults.","heading":"Third-Party Coverage and Community Flagging","sources":[{"url":"https://rekt.news/revest-finance-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://www.web3isgoinggreat.com/single/2022-03-27-0","name":"web3isgoinggreat.com","type":"other","credibility":3},{"url":"https://slowmist.medium.com/revest-finance-incident-analysis-6fcd9b6be207","name":"slowmist.medium.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2021-11-21","event":"RVST token reaches reported all-time high of approximately $2.04","source":""},{"date":"2022-03-27","event":"Reentrancy attack begins at 1:41 AM UTC; attacker exploits ERC-1155 callback vulnerability in the token vault contract to steal approximately $2 million in BLOCKS, ECO, RENA, and other tokens","source":""},{"date":"2022-03-27","event":"Revest team alerted by BLOCKS DAO at 2:24 AM UTC; RVST token transfers halted within approximately 70 seconds, preventing an estimated additional $1.15 million in losses","source":""},{"date":"2022-03-27","event":"Attacker swaps all stolen tokens to ETH and deposits proceeds into Tornado Cash","source":""},{"date":"2022-03-28","event":"Revest Finance publishes exploit recovery plan on Medium, acknowledging inability to fully reimburse victims and outlining patching and reactivation steps","source":""},{"date":"2022-04-30","event":"Follow-up audit by Solidity Finance scheduled for completion by May 19, 2022 per recovery plan","source":""},{"date":"2022-06-18","event":"RVST token reaches its all-time low of approximately $0.009, representing a decline of over 99% from its all-time high","source":""},{"date":"2022-07","event":"Patched contracts reactivated with universal reentrancy guards; Revest Finance Contract Reactivation and Patch Deployment post published on Medium","source":"","date_original":"2022-07-01"},{"date":"2024-09-13","event":"RevestV2-Public GitHub repository last updated, indicating continued but limited development activity","source":""}],"sources_used":[{"url":"https://rekt.news/revest-finance-rekt","name":"Revest Finance - REKT","type":"news_article","archive_url":"http://web.archive.org/web/20260415155855/https://rekt.news/revest-finance-rekt","credibility":2,"archive_timestamp":"2026-04-15T15:58:55+00:00"},{"url":"https://therecord.media/2-million-stolen-from-defi-protocol-revest-finance-platform-unable-to-reimburse-victims","name":"$2 million stolen from DeFi protocol Revest Finance - The Record","type":"news_article","archive_url":"http://web.archive.org/web/20260217045626/https://therecord.media/2-million-stolen-from-defi-protocol-revest-finance-platform-unable-to-reimburse-victims","credibility":1,"archive_timestamp":"2026-02-17T04:56:26+00:00"},{"url":"https://slowmist.medium.com/revest-finance-incident-analysis-6fcd9b6be207","name":"Revest Finance incident analysis - SlowMist","type":"research","archive_url":"http://web.archive.org/web/20250811225410/https://slowmist.medium.com/revest-finance-incident-analysis-6fcd9b6be207","credibility":2,"archive_timestamp":"2025-08-11T22:54:10+00:00"},{"url":"https://blocksecteam.medium.com/revest-finance-vulnerabilities-more-than-re-entrancy-1609957b742f","name":"Revest Finance Vulnerabilities: More than Re-entrancy - BlockSec","type":"research","archive_url":"http://web.archive.org/web/20260319184242/https://blocksecteam.medium.com/revest-finance-vulnerabilities-more-than-re-entrancy-1609957b742f","credibility":2,"archive_timestamp":"2026-03-19T18:42:42+00:00"},{"url":"https://revestfinance.medium.com/revest-protocol-exploit-recovery-plan-b06ca33fbdf5","name":"Revest Protocol Exploit Recovery Plan - Revest Finance Medium","type":"official","archive_url":"http://web.archive.org/web/20251117132058/https://revestfinance.medium.com/revest-protocol-exploit-recovery-plan-b06ca33fbdf5","credibility":2,"archive_timestamp":"2025-11-17T13:20:58+00:00"},{"url":"https://revestfinance.medium.com/revest-finance-contract-reactivation-and-patch-deployment-2054a614bfea","name":"Revest Finance Contract Reactivation and Patch Deployment - Medium","type":"official","archive_url":"https://web.archive.org/web/20260724210852/https://revestfinance.medium.com/revest-finance-contract-reactivation-and-patch-deployment-2054a614bfea","credibility":2,"archive_timestamp":"2026-07-24T21:08:52+00:00"},{"url":"https://www.web3isgoinggreat.com/single/2022-03-27-0","name":"Revest Finance is hacked for $2 million - Web3 Is Going Great","type":"news_article","archive_url":"https://web.archive.org/web/20260724211654/https://www.web3isgoinggreat.com/single/2022-03-27-0","credibility":2,"archive_timestamp":"2026-07-24T21:16:54+00:00"},{"url":"https://sourcehat.com/audits/RevestFinance/","name":"Revest Finance Smart Contract Audit - SourceHat","type":"research","archive_url":"https://web.archive.org/web/20260724172816/https://sourcehat.com/audits/RevestFinance/","credibility":2,"archive_timestamp":"2026-07-24T17:28:16+00:00"},{"url":"https://defillama.com/protocol/revest-finance","name":"Revest Finance TVL Stats - DefiLlama","type":"on_chain","archive_url":null,"credibility":2,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.coingecko.com/en/coins/revest-finance","name":"RVST Token Price - CoinGecko","type":"other","archive_url":"http://web.archive.org/web/20251007051456/https://www.coingecko.com/en/coins/revest-finance","credibility":2,"archive_timestamp":"2025-10-07T05:14:56+00:00"},{"url":"https://theorg.com/org/revest-finance/org-chart/rob-montgomery","name":"Rob Montgomery - Founder at Revest Finance - The Org","type":"other","archive_url":"https://web.archive.org/web/20260724211143/https://theorg.com/org/revest-finance?p=rob-montgomery","credibility":3,"archive_timestamp":"2026-07-24T21:11:43+00:00"},{"url":"https://www.crunchbase.com/person/rob-montgomery-296f","name":"Rob Montgomery - CEO, Co-Founder at InfiniFi - Crunchbase","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:50.419135+00:00","updated_at":"2026-08-29T01:34:44.591+00:00"}}