{"investigation":{"slug":"silo-v2","entity_name":"Silo V2","trust_score":44,"severity_base":null,"score_modifier":-8,"confidence":0.78,"status":"published","content_type":"investigation","summary":"Silo V2 is a non-custodial, permissionless isolated lending market protocol operating across Ethereum, Arbitrum, Base, Optimism, and Sonic. On June 25, 2025, an unreleased peripheral leverage contract was exploited for approximately $545,000 (224 ETH) belonging to SiloDAO test funds; the team confirmed that all core markets and user deposits were unaffected. The incident revealed inadequate input validation and absent formal verification on pre-release code that had been deployed to mainnet, and the attacker subsequently laundered the stolen ETH through Tornado Cash.","sections":[{"content":"Silo Finance is a non-custodial DeFi lending protocol that isolates risk by creating separate lending markets for each asset pair, preventing a vulnerability or price collapse in one token from contaminating unrelated markets. Silo V2, announced in 2024 and deployed across Ethereum mainnet, Arbitrum, Base, Optimism, and Sonic, extended this architecture with programmable, permissionless market deployment via an immutable SiloFactory contract. Each market consists of two ERC-4626 vaults sharing a single bridge asset (typically ETH or USDC), with lending logic and collateral management separated per market. Silo V2 introduced Silo Vaults — single-asset yield vaults that allocate idle capital across isolated markets — as well as an xSILO revenue-sharing token that distributes 50% of monthly DAO revenue to stakers. The SILO governance token has a maximum supply of one billion, vested over four years, with 45% allocated to a community treasury managed by SiloDAO. As of mid-2025, Silo V2 was ranked among the top 50 lending protocols by TVL on DeFiLlama.","heading":"Protocol Overview","sources":[{"url":"https://docs.silo.finance/","name":"docs.silo.finance","type":"other","credibility":3},{"url":"https://nansen.ai/post/what-is-silo-finance-defis-risk-isolated-lending-markets","name":"nansen.ai","type":"other","credibility":3},{"url":"https://defillama.com/protocol/silo-v2","name":"defillama.com","type":"other","credibility":3},{"url":"https://silopedia.silo.finance/silodao/usdsilo/token-allocation-and-vesting","name":"silopedia.silo.finance","type":"other","credibility":3}],"severity":"medium"},{"content":"On June 25, 2025, at 14:11:23 UTC, a targeted exploit drained 224 ETH (approximately $545,000) from a peripheral smart contract that the Silo core team had deployed to mainnet for internal testing of an unreleased leverage feature. The affected contract, LeverageUsingSiloFlashloanWithGeneralSwap, exposed an openLeveragePosition function that accepted a user-controlled _swapArgs parameter without adequate whitelisting or validation. The attacker crafted malicious swap arguments that caused the contract to execute a blind external call — (bool success, bytes memory data) = swapArgs.exchangeProxy.call(swapArgs.swapCallData) — which resolved to a call to silo.borrow() rather than a token swap. By setting the borrower to a SiloDAO team wallet that had granted maximum token approvals to the contract, and setting the receiver to the attacker's own address (0x04377cfaf4b4a44bb84042218cdda4cebcf8fd62), the attacker extracted all approved funds. Silo's real-time monitoring partner Hypernative Labs detected malicious activity 3 minutes and 20 seconds before the exploit was executed but was unable to prevent it. The contract was paused on both Ethereum and Sonic networks following the incident. Silo confirmed that all core protocol markets, vaults, and user deposits were unaffected and that the loss was confined to SiloDAO treasury test funds.","heading":"June 2025 Exploit — Unreleased Leverage Contract","sources":[{"url":"https://silofinance.medium.com/post-mortem-unreleased-leverage-contract-exploitd-0ab8f37afcbb","name":"silofinance.medium.com","type":"other","credibility":3},{"url":"https://www.certora.com/blog/silo-incident-report-contract-exploit","name":"certora.com","type":"other","credibility":3},{"url":"https://www.quillaudits.com/blog/hack-analysis/how-silo-finance-lost-500k","name":"quillaudits.com","type":"other","credibility":3},{"url":"https://getfailsafe.com/ongoing-silo-finance-hack-what-you-need-to-know","name":"getfailsafe.com","type":"other","credibility":3},{"url":"https://smartcontractshacking.com/hacks/silo-finance-hack-2025","name":"smartcontractshacking.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The primary attacker wallet identified by on-chain analysts is 0x04377cfaf4b4a44bb84042218cdda4cebcf8fd62. Blockchain security firm PeckShield flagged that the attacker wallet was funded via Tornado Cash prior to the exploit, through a funding transaction traceable to address 0xb8567f70d61c070ac298ae9924bacdaac8bdbec8c7d71fa0e5d2fab030ddf035. Following the exploit, the attacker routed the stolen 224 ETH back through Tornado Cash in multiple transactions, a pattern consistent with deliberate fund obfuscation. Notably, PeckShield further identified that on the same day as the Silo exploit (June 25, 2025), the attacker address was linked to wallets that had previously drained approximately $12 million from Cork Protocol in a separate incident on May 28, 2025. In that incident, the Cork Protocol exploiter stole 3,761 wstETH by targeting the wstETH:weETH market, and subsequently laundered a total of approximately 4,520 ETH (roughly $11 million) through Tornado Cash. The alleged connection between the Silo and Cork exploits implies a sophisticated, repeat threat actor operating across multiple DeFi protocols.","heading":"On-Chain Attribution and Fund Laundering","sources":[{"url":"https://www.quillaudits.com/blog/hack-analysis/how-silo-finance-lost-500k","name":"quillaudits.com","type":"other","credibility":3},{"url":"https://www.cryptopolitan.com/silo-finance-hacked-545k-in-loss-reported/","name":"cryptopolitan.com","type":"other","credibility":3},{"url":"https://cryptorank.io/news/feed/6f977-silo-finance-hacked-545k-in-loss-reported","name":"cryptorank.io","type":"other","credibility":3},{"url":"https://www.bitget.com/news/detail/12560604835357","name":"bitget.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Silo Finance has maintained a multi-layered security program, employing audits from Trail of Bits, ABDK, Quantstamp, and Certora, and running an Immunefi bug bounty program with rewards of up to $350,000 for critical vulnerabilities on V2 and V3. Formal verification via the Certora Prover has been applied to core Silo contracts. However, Certora's own post-mortem on the June 2025 incident acknowledged that their Prover tool was not applied to the exploited leverage contract, despite being applied to simpler Silo contracts. Certora stated that had formal verification been performed on the leverage module, the problematic user-controlled external call would have been identified. The June 2025 exploit therefore represents a gap in security process rather than a failure of core contract auditing: an unreleased feature contract was deployed to production environments with maximum token approvals but without the formal verification and dual-audit requirements applied to the protocol's primary contracts. Following the incident, Silo committed to requiring at least two independent audits and formal verification before any future public release of the leverage feature. The protocol also experienced an earlier security event in May 2023, when a whitehat disclosed via Immunefi a critical interest rate model vulnerability (IRMV1) that could have exposed approximately $3 million in Ethereum-market deposits. The whitehat was awarded 100,000 USDC. A patched model (IRMv2) was deployed by May 1, 2023.","heading":"Security Posture and Audit History","sources":[{"url":"https://www.certora.com/blog/silo-incident-report-contract-exploit","name":"certora.com","type":"other","credibility":3},{"url":"https://immunefi.com/bug-bounty/silofinance-v2/information/","name":"immunefi.com","type":"other","credibility":3},{"url":"https://medium.com/immunefi/silo-finance-logic-error-bugfix-review-35de29bd934a","name":"medium.com","type":"other","credibility":3},{"url":"https://medium.com/silo-protocol/vulnerability-disclosure-2023-06-06-c1dfd4c4dbb8","name":"medium.com","type":"other","credibility":3},{"url":"https://devdocs.silo.finance/security/audits-and-formal-verification","name":"devdocs.silo.finance","type":"other","credibility":3}],"severity":"medium"},{"content":"Following public disclosure of the June 25, 2025 exploit, the SILO governance token dropped approximately 11% within 24 hours, falling to approximately $0.04035 according to CoinGecko data. The 14-day Relative Strength Index fell below 36, indicating oversold conditions. The 50-day moving average at the time of the exploit stood at approximately $0.055, well above the post-exploit spot price. On-chain activity showed traders offloading SILO tokens shortly after the incident became public. The price impact was notable given that the exploit directly affected only SiloDAO treasury funds and not user deposits, suggesting the market assigned meaningful probability to broader protocol risk from the disclosure. The SILO token was not suspended or delisted on any major exchange as a result of the incident.","heading":"Market and Token Impact","sources":[{"url":"https://www.ainvest.com/news/silo-finance-loses-545-000-smart-contract-exploit-silo-price-drops-11-2506/","name":"ainvest.com","type":"other","credibility":3},{"url":"https://www.okx.com/en-us/learn/silo-finance-exploit-smart-contract-breach","name":"okx.com","type":"other","credibility":3},{"url":"https://www.mitrade.com/insights/news/live-news/article-3-915081-20250626","name":"mitrade.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Silo Finance's response to the June 2025 exploit was prompt in terms of containment: the affected contract was paused on both Ethereum and Sonic networks within hours of the incident. The team published a post-mortem on Medium on the day of the exploit acknowledging that SiloDAO test funds were lost and confirming that no user funds were at risk. Silo engaged Certora to conduct a comprehensive audit and formal verification of the leverage module before any future release. The team stated a commitment to requiring at minimum two independent audits prior to deploying any new modules to production. The Silo team also noted that the overly broad token approvals granted to the test contract — which enabled the exploit — represent a process failure that will be corrected. A 2023 vulnerability was handled responsibly through coordinated disclosure via Immunefi, with a patch deployed within days and a public bug bounty payout made to the reporting whitehat. These actions are consistent with an established security culture in core operations, though the 2025 incident exposes gaps in pre-release operational security practices.","heading":"Team Response and Remediation","sources":[{"url":"https://silofinance.medium.com/post-mortem-unreleased-leverage-contract-exploitd-0ab8f37afcbb","name":"silofinance.medium.com","type":"other","credibility":3},{"url":"https://www.certora.com/blog/silo-incident-report-contract-exploit","name":"certora.com","type":"other","credibility":3},{"url":"https://medium.com/silo-protocol/vulnerability-disclosure-2023-06-06-c1dfd4c4dbb8","name":"medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"ZachXBT, an independent on-chain investigator known for tracking DeFi exploits and scams, flagged Silo Finance in connection with the June 2025 exploit. While the specific content of the flag has not been independently verified through a publicly archived primary source at the time of this investigation, ZachXBT's coverage of the incident is consistent with his documented pattern of reporting on DeFi exploits and fund laundering through Tornado Cash. The alleged connection between the Silo exploit and the Cork Protocol attacker — both events involving Tornado Cash funding and fund obfuscation — was surfaced by on-chain security researchers including PeckShield. Community reaction in DeFi forums and social media was mixed: some users expressed concern about the practice of deploying unaudited contracts to mainnet with broad approvals, while others noted that the core protocol remained uncompromised and user funds were safe. The ZachXBT flag should be interpreted in the context that no evidence of fraud, rug pull, or intentional misappropriation by the Silo team has been identified; the incident appears to be an operational security failure rather than deliberate misconduct.","heading":"ZachXBT Flag and Community Scrutiny","sources":[{"url":"https://www.cryptopolitan.com/silo-finance-hacked-545k-in-loss-reported/","name":"cryptopolitan.com","type":"other","credibility":3},{"url":"https://phemex.com/news/article/silo-finance-exploit-results-in-545k-loss-11097","name":"phemex.com","type":"other","credibility":3},{"url":"https://www.ainvest.com/news/silo-finance-loses-545-000-smart-contract-exploit-silo-price-drops-11-2506/","name":"ainvest.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2021","event":"Silo Finance founded and initial protocol design work begun on isolated lending market architecture.","source":"","date_original":"2021-01-01"},{"date":"2023-04-27","event":"Whitehat submits critical vulnerability report via Immunefi disclosing interest rate model (IRMV1) flaw that could have exposed approximately $3 million in Ethereum-market deposits.","source":"Silo Finance vulnerability disclosure (Medium)","source_url":"https://medium.com/silo-protocol/vulnerability-disclosure-2023-06-06-c1dfd4c4dbb8"},{"date":"2023-05","event":"Silo deploys patched interest rate model (IRMv2), fixing the utilization ratio calculation vulnerability.","source":"Certora Silo Finance Post-Mortem","source_url":"https://www.certora.com/blog/silo-finance-post-mortem","date_original":"2023-05-01"},{"date":"2023-06-06","event":"Silo Finance publicly discloses the 2023 vulnerability and awards 100,000 USDC bug bounty to the whitehat reporter.","source":"Silo Finance Medium vulnerability disclosure","source_url":"https://medium.com/silo-protocol/vulnerability-disclosure-2023-06-06-c1dfd4c4dbb8"},{"date":"2024","event":"Silo V2 announced with expanded architecture: multichain deployment, programmable markets, Silo Vaults, and xSILO revenue token.","source":"Silo Finance 2024 Roadmap (Medium)","source_url":"https://medium.com/silo-protocol/silo-finance-2024-roadmap-4c3aadf31348","date_original":"2024-01-01"},{"date":"2025-05-28","event":"Cork Protocol exploited for approximately $12 million (3,761 wstETH); attacker address later linked to Silo Finance exploit.","source":"Bitget News / PeckShield","source_url":"https://www.bitget.com/news/detail/12560604835357"},{"date":"2025-06-25","event":"Silo Finance leverage contract exploit occurs at 14:11:23 UTC; 224 ETH (~$545,000 in SiloDAO test funds) drained via improper input validation in unreleased LeverageUsingSiloFlashloanWithGeneralSwap contract.","source":"Silo Finance post-mortem (Medium)","source_url":"https://silofinance.medium.com/post-mortem-unreleased-leverage-contract-exploitd-0ab8f37afcbb"},{"date":"2025-06-25","event":"Silo Finance pauses the affected contract on Ethereum and Sonic networks; confirms core markets and user funds unaffected.","source":"Silo Finance post-mortem (Medium)","source_url":"https://silofinance.medium.com/post-mortem-unreleased-leverage-contract-exploitd-0ab8f37afcbb"},{"date":"2025-06-25","event":"SILO token price drops approximately 11% following public disclosure of the exploit.","source":"Ainvest","source_url":"https://www.ainvest.com/news/silo-finance-loses-545-000-smart-contract-exploit-silo-price-drops-11-2506/"},{"date":"2025-06-25","event":"PeckShield flags attacker wallet as linked to the Cork Protocol exploit; both incidents involve Tornado Cash fund laundering.","source":"Cryptopolitan","source_url":"https://www.cryptopolitan.com/silo-finance-hacked-545k-in-loss-reported/"},{"date":"2025-06-25","event":"Attacker routes stolen 224 ETH through Tornado Cash in multiple transactions to obfuscate fund trail.","source":"QuillAudits hack analysis","source_url":"https://www.quillaudits.com/blog/hack-analysis/how-silo-finance-lost-500k"},{"date":"2025-06-26","event":"Certora publishes incident post-mortem acknowledging that Certora Prover was not applied to the exploited leverage contract, and that formal verification would have detected the user-controlled external call vulnerability.","source":"Certora incident report","source_url":"https://www.certora.com/blog/silo-incident-report-contract-exploit"}],"sources_used":[{"url":"https://docs.silo.finance/","name":"docs.silo.finance","type":"other","archive_url":"http://web.archive.org/web/20260612144305/https://docs.silo.finance/","credibility":3,"archive_timestamp":"2026-06-12T14:43:05+00:00"},{"url":"https://nansen.ai/post/what-is-silo-finance-defis-risk-isolated-lending-markets","name":"nansen.ai","type":"other","archive_url":"http://web.archive.org/web/20260513132855/https://nansen.ai/post/what-is-silo-finance-defis-risk-isolated-lending-markets","credibility":3,"archive_timestamp":"2026-05-13T13:28:55+00:00"},{"url":"https://defillama.com/protocol/silo-v2","name":"defillama.com","type":"other","archive_url":"http://web.archive.org/web/20250906202810/https://defillama.com/protocol/silo-v2","credibility":3,"archive_timestamp":"2025-09-06T20:28:10+00:00"},{"url":"https://silopedia.silo.finance/silodao/usdsilo/token-allocation-and-vesting","name":"silopedia.silo.finance","type":"other","archive_url":"http://web.archive.org/web/20251012173003/https://silopedia.silo.finance/silodao/usdsilo/token-allocation-and-vesting","credibility":3,"archive_timestamp":"2025-10-12T17:30:03+00:00"},{"url":"https://silofinance.medium.com/post-mortem-unreleased-leverage-contract-exploitd-0ab8f37afcbb","name":"silofinance.medium.com","type":"other","archive_url":"http://web.archive.org/web/20251122223907/https://silofinance.medium.com/post-mortem-unreleased-leverage-contract-exploitd-0ab8f37afcbb","credibility":3,"archive_timestamp":"2025-11-22T22:39:07+00:00"},{"url":"https://www.certora.com/blog/silo-incident-report-contract-exploit","name":"certora.com","type":"other","archive_url":"https://web.archive.org/web/20260829044540/https://www.certora.com/blog/silo-incident-report-contract-exploit","credibility":3,"archive_timestamp":"2026-08-29T04:45:40+00:00"},{"url":"https://www.quillaudits.com/blog/hack-analysis/how-silo-finance-lost-500k","name":"quillaudits.com","type":"other","archive_url":"http://web.archive.org/web/20260515101351/https://www.quillaudits.com/blog/hack-analysis/how-silo-finance-lost-500k","credibility":3,"archive_timestamp":"2026-05-15T10:13:51+00:00"},{"url":"https://getfailsafe.com/ongoing-silo-finance-hack-what-you-need-to-know","name":"getfailsafe.com","type":"other","archive_url":"http://web.archive.org/web/20260521162400/https://getfailsafe.com/ongoing-silo-finance-hack-what-you-need-to-know","credibility":3,"archive_timestamp":"2026-05-21T16:24:00+00:00"},{"url":"https://smartcontractshacking.com/hacks/silo-finance-hack-2025","name":"smartcontractshacking.com","type":"other","archive_url":"https://web.archive.org/web/20260829041407/https://smartcontractshacking.com/hacks/silo-finance-hack-2025","credibility":3,"archive_timestamp":"2026-08-29T04:14:07+00:00"},{"url":"https://www.cryptopolitan.com/silo-finance-hacked-545k-in-loss-reported/","name":"cryptopolitan.com","type":"other","archive_url":"http://web.archive.org/web/20251010041004/https://www.cryptopolitan.com/silo-finance-hacked-545k-in-loss-reported/","credibility":3,"archive_timestamp":"2025-10-10T04:10:04+00:00"},{"url":"https://cryptorank.io/news/feed/6f977-silo-finance-hacked-545k-in-loss-reported","name":"cryptorank.io","type":"other","archive_url":"https://web.archive.org/web/20260830032739/https://cryptorank.io/news/feed/6f977-silo-finance-hacked-545k-in-loss-reported","credibility":3,"archive_timestamp":"2026-08-30T03:27:39+00:00"},{"url":"https://www.bitget.com/news/detail/12560604835357","name":"bitget.com","type":"other","archive_url":"https://web.archive.org/web/20260829044216/https://www.bitget.com/news/detail/12560604835357","credibility":3,"archive_timestamp":"2026-08-29T04:42:16+00:00"},{"url":"https://immunefi.com/bug-bounty/silofinance-v2/information/","name":"immunefi.com","type":"other","archive_url":"http://web.archive.org/web/20260718035729/https://immunefi.com/bug-bounty/silofinance-v2/information/","credibility":3,"archive_timestamp":"2026-07-18T03:57:29+00:00"},{"url":"https://medium.com/immunefi/silo-finance-logic-error-bugfix-review-35de29bd934a","name":"medium.com","type":"other","archive_url":"http://web.archive.org/web/20260610104509/https://medium.com/immunefi/silo-finance-logic-error-bugfix-review-35de29bd934a","credibility":3,"archive_timestamp":"2026-06-10T10:45:09+00:00"},{"url":"https://medium.com/silo-protocol/vulnerability-disclosure-2023-06-06-c1dfd4c4dbb8","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://devdocs.silo.finance/security/audits-and-formal-verification","name":"devdocs.silo.finance","type":"other","archive_url":"http://web.archive.org/web/20260511235638/https://devdocs.silo.finance/security/audits-and-formal-verification","credibility":3,"archive_timestamp":"2026-05-11T23:56:38+00:00"},{"url":"https://www.ainvest.com/news/silo-finance-loses-545-000-smart-contract-exploit-silo-price-drops-11-2506/","name":"ainvest.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.okx.com/en-us/learn/silo-finance-exploit-smart-contract-breach","name":"okx.com","type":"other","archive_url":"http://web.archive.org/web/20260521012609/https://www.okx.com/en-us/learn/silo-finance-exploit-smart-contract-breach","credibility":3,"archive_timestamp":"2026-05-21T01:26:09+00:00"},{"url":"https://www.mitrade.com/insights/news/live-news/article-3-915081-20250626","name":"mitrade.com","type":"other","archive_url":"https://web.archive.org/web/20260829051316/https://www.mitrade.com/insights/news/live-news/article-3-915081-20250626","credibility":3,"archive_timestamp":"2026-08-29T05:13:16+00:00"},{"url":"https://phemex.com/news/article/silo-finance-exploit-results-in-545k-loss-11097","name":"phemex.com","type":"other","archive_url":"http://web.archive.org/web/20260829115920/https://phemex.com/news/article/silo-finance-exploit-results-in-545k-loss-11097","credibility":3,"archive_timestamp":"2026-08-29T11:59:20+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:17.760153+00:00","updated_at":"2026-08-30T03:54:58.359426+00:00"}}