{"investigation":{"slug":"sharedstake","entity_name":"SharedStake","trust_score":28,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"SharedStake is an Ethereum liquid staking protocol launched in January 2021 that allowed users to deposit ETH in exchange for the vETH2 liquid staking token. In June 2021, a co-founder using the pseudonym 'Kairos' exploited a critical timelock bypass vulnerability in the protocol's vesting contracts — a bug that had been disclosed to the team two months prior — draining approximately $128,000 from liquidity providers and sending 100 ETH through Tornado Cash. The protocol subsequently relaunched as SharedDeposit v2 under remaining team members, though the SGT governance token never recovered.","sections":[{"content":"SharedStake was founded in January 2021 by three pseudonymous co-founders — Kairos, Chimera, and Ice Bear — as an Ethereum 2.0 staking-as-a-service protocol. Users could deposit ETH into the protocol and receive vETH2, a liquid staking derivative, in return, allowing them to earn staking yield while retaining token liquidity. The protocol also issued SGT (SharedStake Governance Token) for community governance and liquidity incentives. At its peak the protocol had approximately $8 million in SGT liquidity and held roughly 16,000 ETH staked across validators. SharedStake was positioned as a decentralized alternative to centralized staking services ahead of the Ethereum Merge. Within the founding team, Kairos was responsible for deploying the SGT token and farming contracts as well as initial marketing, while Chimera built the core deposit contract and managed validators, and Ice Bear created the website and app.","heading":"Background and Protocol Overview","sources":[{"url":"https://medium.com/@chimera_defi/sgt-rugpull-post-mortem-634a527940e0","name":"medium.com","type":"other","credibility":3},{"url":"https://docs.sharedstake.org/","name":"docs.sharedstake.org","type":"other","credibility":3},{"url":"https://cryptobriefing.com/sharedstake-developer-goes-rogue-sgt-price-plummets-95/","name":"cryptobriefing.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On June 19, 2021, a co-founder operating under the pseudonym Kairos began exploiting a vulnerability in SharedStake's vesting and timelock smart contracts. The flaw resided in the SmartTimelock.sol and smartVesting contracts: a call() function could be used to invoke arbitrary external contract methods, allowing a caller to self-approve token transfers and completely bypass vesting schedules and timelock checks without governance approval. Kairos first tested the exploit on June 19, then on June 21 sold over $35,000 worth of SGT from the deployer address without team approval — an action described as initiating a 'slow rug pull.' On June 23, 2021, co-founder Chimera discovered the unauthorized sales. When confronted, Kairos became 'exceptionally hostile.' Fearing a complete rug pull, Chimera executed what was described as a 'defensive drain' of the remaining vulnerable contracts, securing 81 WETH and approximately $54,000 USDC. Kairos, allegedly monitoring on-chain activity, front-ran Chimera's transactions and stole an additional $93,000, then sent 100 ETH to Tornado Cash to obscure the trail. Kairos's total alleged theft amounted to approximately $128,000–$138,000 across multiple transactions. Kairos subsequently went silent and never returned funds. Chimera ultimately returned the defensively drained funds to the community.","heading":"Insider Exploit and Treasury Drain","sources":[{"url":"https://medium.com/@chimera_defi/sgt-rugpull-post-mortem-634a527940e0","name":"medium.com","type":"other","credibility":3},{"url":"https://sharedstake.medium.com/post-mortem-of-the-sharedstake-incident-4625eeacc61f","name":"sharedstake.medium.com","type":"other","credibility":3},{"url":"https://medium.com/immunefi/sharedstake-insider-exploit-postmortem-17fa93d5c90e","name":"medium.com","type":"other","credibility":3},{"url":"https://cryptoslate.com/developer-rug-pulls-ethereum-defi-project-sharedstake-sgt-token-falls-95/","name":"cryptoslate.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The vulnerability exploited in the June 2021 incident had been disclosed to the SharedStake team nearly two months before it was weaponized. On April 26, 2021, a whitehat researcher known as Lucash-dev reported the timelock bypass bug to Immunefi, SharedStake's bug bounty platform. The SharedStake team confirmed the bug on April 29, 2021, and paid a $5,000 bounty. A fix was delivered privately to the team on June 16, 2021, but at that point SharedStake had already granted a new team member access to the full bug report. According to Immunefi's postmortem, the alleged insider who had been given access to the vulnerability report appears to have used that access to understand and execute the exploit on mainnet starting June 19, 2021. Immunefi stated they could not independently verify which specific party exploited the contracts, but expressed hope that funds would be returned. The incident highlighted catastrophic failures in vulnerability disclosure handling: the team did not remediate a known critical bug for nearly two months, and then shared the full technical details of that bug with an untrusted party. Immunefi suspended SharedStake's bug bounty program indefinitely pending investigation.","heading":"Timelock Vulnerability and Disclosure Failures","sources":[{"url":"https://medium.com/immunefi/sharedstake-insider-exploit-postmortem-17fa93d5c90e","name":"medium.com","type":"other","credibility":3},{"url":"https://sharedstake.medium.com/post-mortem-of-the-sharedstake-incident-4625eeacc61f","name":"sharedstake.medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The SGT governance token collapsed approximately 95–96% in price in the immediate aftermath of the June 23, 2021 exploit. The token price fell from approximately $1.60 to under $0.03, and the protocol's market capitalization dropped to approximately $33,000. The vETH2 liquid staking token itself was not directly compromised by the exploit — the 16,000 ETH held in validators continued to operate — however, confidence in the protocol collapsed due to the governance and security failures. Other team members urged users to immediately withdraw all funds from liquidity mining contracts and the Saddle pool ETH-vETH2 pair. SharedStake's Twitter account had also previously been suspended, which community members cited as an additional red flag that had existed prior to the exploit. The SGT token never meaningfully recovered to its pre-exploit price.","heading":"Market Impact and Token Price Collapse","sources":[{"url":"https://cryptobriefing.com/sharedstake-developer-goes-rogue-sgt-price-plummets-95/","name":"cryptobriefing.com","type":"other","credibility":3},{"url":"https://cryptoslate.com/developer-rug-pulls-ethereum-defi-project-sharedstake-sgt-token-falls-95/","name":"cryptoslate.com","type":"other","credibility":3},{"url":"https://micky.com.au/sharedstakes-governance-token-exploited-by-one-of-its-developers/","name":"micky.com.au","type":"other","credibility":3}],"severity":"medium"},{"content":"The exploit exposed deep structural weaknesses in SharedStake's governance and operational security. Kairos held sole control of the project's domain, Google Cloud Platform account, Discord server, and admin email — effectively locking out other team members from critical infrastructure. This centralized control prevented Chimera from maintaining servers or shutting down validators during the crisis. Within the protocol's multisig, Kairos held 2 of the 5 required signing keys for a 3-of-5 threshold arrangement, creating an additional attack vector. Validator withdrawal keys were reportedly stored on the GCP server controlled by Kairos, raising concerns that those keys may have been compromised prior to the rug pull. The incident illustrated a structural contradiction common in early DeFi projects: protocols marketed as decentralized while retaining significant centralized single points of failure and unilateral control by individual founders. The broader DeFi community used the incident as a case study on the dangers of admin keys and inadequate governance structures.","heading":"Governance Failures and Centralization Risks","sources":[{"url":"https://medium.com/@chimera_defi/sgt-rugpull-post-mortem-634a527940e0","name":"medium.com","type":"other","credibility":3},{"url":"https://cryptobriefing.com/sharedstake-developer-goes-rogue-sgt-price-plummets-95/","name":"cryptobriefing.com","type":"other","credibility":3},{"url":"https://sharedstake.medium.com/post-mortem-of-the-sharedstake-incident-4625eeacc61f","name":"sharedstake.medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the exploit, Ice Bear and Chimera reorganized the remaining team and took steps to stabilize the protocol and compensate affected users. A community-controlled 4-of-5 multisig was established to replace the compromised governance structure. On July 24, 2021, the team airdropped reimbursements to affected liquidity providers: approximately 101 vETH2 was returned to SGT-vETH2 pool LPs (representing approximately 90% of losses in that pool), and 30 ETH was distributed to SGT-ETH pool LPs (approximately 35% recovery for that pool). The team declined to pursue formal litigation against Kairos, citing estimated legal costs of approximately $250,000 against actual theft of roughly $128,000. The protocol was redesigned with a zero-trust model and subsequently relaunched as SharedDeposit v2, a new liquid ETH staking derivative platform. V1 ETH deposits and accumulated yield were returned to users ahead of migration to v2. The 16,000 ETH staked through the v1 protocol remained safe throughout the incident and were successfully withdrawn or migrated.","heading":"Recovery Efforts and Protocol Relaunch","sources":[{"url":"https://sharedstake.medium.com/sharedstake-updates-a73780ebd53a","name":"sharedstake.medium.com","type":"other","credibility":3},{"url":"https://medium.com/@chimera_defi/the-future-of-sharedstake-fee7cb9e96d7","name":"medium.com","type":"other","credibility":3},{"url":"https://docs.sharedstake.finance/sharedstake-v2","name":"docs.sharedstake.finance","type":"other","credibility":3}],"severity":"medium"},{"content":"SharedStake has been flagged by ZachXBT, the pseudonymous blockchain investigator known for tracking DeFi exploits, rug pulls, and insider thefts. The protocol's June 2021 insider exploit — in which a co-founder drained treasury funds and routed proceeds through Tornado Cash — aligns with the categories of malicious insider incidents documented by ZachXBT. Community members had raised concerns about the project's developer anonymity and lack of transparency on the protocol's website prior to the exploit. The Twitter account suspension that occurred before the June 2021 events was also cited as a warning sign by community observers. Immunefi's published postmortem further corroborated the insider nature of the attack, providing independent documentation of the disclosure failures and exploitation sequence.","heading":"ZachXBT Flag and Community Warnings","sources":[{"url":"https://medium.com/immunefi/sharedstake-insider-exploit-postmortem-17fa93d5c90e","name":"medium.com","type":"other","credibility":3},{"url":"https://cryptoslate.com/developer-rug-pulls-ethereum-defi-project-sharedstake-sgt-token-falls-95/","name":"cryptoslate.com","type":"other","credibility":3},{"url":"https://micky.com.au/sharedstakes-governance-token-exploited-by-one-of-its-developers/","name":"micky.com.au","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2021","event":"SharedStake founded by pseudonymous co-founders Kairos, Chimera, and Ice Bear as an Ethereum 2.0 staking protocol.","source":"","date_original":"2021-01-01"},{"date":"2021-04-26","event":"Whitehat researcher Lucash-dev reports critical timelock bypass vulnerability in SmartTimelock.sol to Immunefi.","source":""},{"date":"2021-04-29","event":"SharedStake team confirms the bug and pays Lucash-dev a $5,000 bug bounty.","source":""},{"date":"2021-05-20","event":"SharedStake requests a fix from Immunefi for the disclosed vulnerability.","source":""},{"date":"2021-06-16","event":"Fix delivered privately to SharedStake. Team grants a new team member (alleged to be the exploiter) access to the full bug report.","source":""},{"date":"2021-06-19","event":"Kairos tests the timelock exploit on mainnet — first on-chain exploitation of the vesting contract vulnerability.","source":""},{"date":"2021-06-21","event":"Kairos sells over $35,000 worth of SGT from the deployer address without team approval, initiating what Chimera later described as a 'slow rug pull.'","source":""},{"date":"2021-06-23","event":"Chimera discovers unauthorized sales. Kairos becomes hostile when confronted. Chimera defensively drains vulnerable contracts (81 WETH + $54,000 USDC). Kairos front-runs Chimera's transactions to steal an additional $93,000. SGT price collapses ~95%. Team urges all users to exit liquidity positions.","source":""},{"date":"2021-06-24","event":"Kairos sends 100 ETH to Tornado Cash to obscure stolen funds. Recovery negotiations begin. Chimera agrees to return defensively drained funds; Kairos refuses.","source":""},{"date":"2021-06-28","event":"New developers hired to secure the protocol. Community-controlled 4-of-5 multisig established.","source":""},{"date":"2021-07-24","event":"Reimbursement airdrop completed: 101 vETH2 distributed to SGT-vETH2 LPs (~90% recovery) and 30 ETH to SGT-ETH LPs (~35% recovery).","source":""},{"date":"2022","event":"Protocol relaunches as SharedDeposit v2 with redesigned zero-trust architecture and phased rollout. V1 ETH deposits and yield returned to users.","source":"","date_original":"2022-01-01"}],"sources_used":[{"url":"https://medium.com/@chimera_defi/sgt-rugpull-post-mortem-634a527940e0","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://docs.sharedstake.org/","name":"docs.sharedstake.org","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-job","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://cryptobriefing.com/sharedstake-developer-goes-rogue-sgt-price-plummets-95/","name":"cryptobriefing.com","type":"other","archive_url":"http://web.archive.org/web/20260210063113/https://cryptobriefing.com/sharedstake-developer-goes-rogue-sgt-price-plummets-95/","credibility":3,"archive_timestamp":"2026-02-10T06:31:13+00:00"},{"url":"https://sharedstake.medium.com/post-mortem-of-the-sharedstake-incident-4625eeacc61f","name":"sharedstake.medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://medium.com/immunefi/sharedstake-insider-exploit-postmortem-17fa93d5c90e","name":"medium.com","type":"other","archive_url":"http://web.archive.org/web/20250930112952/https://medium.com/immunefi/sharedstake-insider-exploit-postmortem-17fa93d5c90e","credibility":3,"archive_timestamp":"2025-09-30T11:29:52+00:00"},{"url":"https://cryptoslate.com/developer-rug-pulls-ethereum-defi-project-sharedstake-sgt-token-falls-95/","name":"cryptoslate.com","type":"other","archive_url":"https://web.archive.org/web/20260829235942/https://cryptoslate.com/developer-rug-pulls-ethereum-defi-project-sharedstake-sgt-token-falls-95/","credibility":3,"archive_timestamp":"2026-08-29T23:59:42+00:00"},{"url":"https://micky.com.au/sharedstakes-governance-token-exploited-by-one-of-its-developers/","name":"micky.com.au","type":"other","archive_url":"https://web.archive.org/web/20260829140714/https://micky.com.au/sharedstakes-governance-token-exploited-by-one-of-its-developers/","credibility":3,"archive_timestamp":"2026-08-29T14:07:14+00:00"},{"url":"https://sharedstake.medium.com/sharedstake-updates-a73780ebd53a","name":"sharedstake.medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://medium.com/@chimera_defi/the-future-of-sharedstake-fee7cb9e96d7","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://docs.sharedstake.finance/sharedstake-v2","name":"docs.sharedstake.finance","type":"other","archive_url":"http://web.archive.org/web/20260608141842/https://docs.sharedstake.finance/sharedstake-v2","credibility":3,"archive_timestamp":"2026-06-08T14:18:42+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:38.443612+00:00","updated_at":"2026-08-30T01:16:30.142817+00:00"}}