{"investigation":{"slug":"steadefi","entity_name":"Steadefi","trust_score":35,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"Steadefi is a decentralized leveraged yield farming protocol operating on Arbitrum and Avalanche. On August 7, 2023, an attacker exploited a compromised deployer private key to drain approximately $1.14 million from the protocol's lending vaults across both chains. The protocol subsequently relaunched with enhanced security measures and issued a token-based compensation plan for affected users, though roughly 70% of stolen funds were never recovered.","sections":[{"content":"Steadefi is an undercollateralized leveraged yield protocol that allows DeFi users to earn yield across various market conditions via automated strategy and risk management vaults. The protocol operates on Arbitrum and Avalanche and offers two primary vault types: Lending Vaults and Strategy Vaults. Strategy Vaults borrow assets from Lending Vaults to execute leveraged yield strategies, typically involving exposure to GMX v2 GM pools. As of mid-2025, DefiLlama reports the protocol carrying a significant TVL, predominantly on Arbitrum. The protocol's native token is SDY (formerly STEADY), with a planned token generation event following the 2023 exploit.","heading":"Protocol Overview","sources":[{"url":"https://defillama.com/protocol/steadefi","name":"defillama.com","type":"other","credibility":3},{"url":"https://blog.steadefi.com/intro-to-steadefi","name":"blog.steadefi.com","type":"other","credibility":3},{"url":"https://pexx.com/chaindebrief/heres-how-steadefi-will-make-yield-farming-simple-yet-effective/","name":"pexx.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On August 7, 2023, Steadefi suffered a critical security breach resulting in the loss of approximately $1.14 million in user funds. The attack vector was a compromised deployer wallet private key. The attacker used the deployer account — which held owner-level permissions across all smart contracts — to transfer ownership of Steadefi's lending and strategy vaults on both Arbitrum and Avalanche to attacker-controlled address 0x9cf71F2ff126B9743319B60d2D873F0E508810dc at approximately 4:06 PM UTC. The attacker then approved their own wallet as a borrower and drained all available lending liquidity between 4:22 PM and 4:44 PM UTC. Additional assets were moved from the deployer wallet at 5:10 PM UTC. The stolen assets, comprising USDC, USDT, BTC.b, wBTC, wETH, ARB, and AVAX, were swapped for approximately 624 ETH in total (440 ETH from Arbitrum, 184 ETH from Avalanche) and bridged to Ethereum mainnet via the Synapse bridge between 5:39 PM and 5:56 PM UTC. According to Steadefi's own post-mortem, the root cause was traced to a malware infection originating from a suspicious file downloaded on June 17, 2023, during a Telegram conversation with an entity calling itself 'Spirit Blockchain Group,' which allegedly contained malware. On June 28, 2023, the deployer's MetaMask seed phrases were subsequently compromised. Steadefi's post-mortem also cited the absence of a multi-signature wallet and timelocks as a key operational security failure that allowed the attack to proceed without friction.","heading":"August 2023 Private Key Exploit","sources":[{"url":"https://blog.steadefi.com/exploit-analysis-and-reimbursement-plan","name":"blog.steadefi.com","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-steadefi-hack-august-2023","name":"halborn.com","type":"other","credibility":3},{"url":"https://www.merklescience.com/blog/hack-track-steadefi-flow-of-funds-analysis","name":"merklescience.com","type":"other","credibility":3},{"url":"https://www.web3isgoinggreat.com/single/steadefi-exploit","name":"web3isgoinggreat.com","type":"other","credibility":3},{"url":"https://beincrypto.com/steadefi-exploit-hack-funds-lost/","name":"beincrypto.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the exploit, the approximately 624 ETH transferred to Ethereum mainnet were alleged to have been sent through Tornado Cash in 100 ETH deposits. On-chain analysis indicates that by October 2023, addresses associated with the attacker began distributing funds through exchanges, with transfers reportedly made to Paxful and Noones deposit addresses. No formal attribution to a known threat actor group has been confirmed by Steadefi or by any Tier 1 or Tier 2 investigative source reviewed for this report.","heading":"Fund Laundering via Tornado Cash","sources":[{"url":"https://blog.steadefi.com/exploit-analysis-and-reimbursement-plan","name":"blog.steadefi.com","type":"other","credibility":3},{"url":"https://www.merklescience.com/blog/hack-track-steadefi-flow-of-funds-analysis","name":"merklescience.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following public disclosure on August 9, 2023, Steadefi offered the attacker a 10% bounty — approximately $114,000 — in exchange for the return of the remaining 90% of stolen funds by 0800 UTC on August 10, 2023. The offer included a promise not to pursue legal action. The team simultaneously warned that if the offer was refused, a corresponding 10% bounty would be offered to any party who could identify the attacker in a manner leading to conviction. The bounty offer was not accepted. The protocol team independently recovered approximately $540,000 from the compromised vaults prior to full exploitation, and users were able to withdraw an additional $300,000 before the attack was contained. Total unrecovered funds amounted to approximately $1.14 million. Recovered funds were distributed proportionally to affected wallets in USDC through a claims portal at steadefi.com/claim.","heading":"Bounty Offer and Recovery Efforts","sources":[{"url":"https://blog.steadefi.com/exploit-analysis-and-reimbursement-plan","name":"blog.steadefi.com","type":"other","credibility":3},{"url":"https://beincrypto.com/steadefi-exploit-hack-funds-lost/","name":"beincrypto.com","type":"other","credibility":3},{"url":"https://crypto.news/hacked-protocol-steadefi-offers-33k-bounty-to-hacker/","name":"crypto.news","type":"other","credibility":3}],"severity":"medium"},{"content":"Steadefi announced a full protocol relaunch in late September 2023, accompanied by a security overhaul that included multi-signature permissions and timelocks for all owner functions, integration of Hypernative's real-time security monitoring across all vaults, and enhanced smart contract design. The protocol rebranded its native token from STEADY to SDY and adjusted tokenomics to fund user recovery. A compensation allocation of 12% of total token supply (24 million tokens) was designated for affected users, distributed as esSDY (escrow tokens) claimable over 12 months at a $10 million fully diluted valuation — the same valuation offered to original seed investors. The esSDY redemption schedule ranged from 20% to 100% SDY conversion over one to six months, with full redemption taking up to 18 months. The team allocation was reduced from 20% to 10% to fund this compensation. A subsequent v3 vault migration and liquid restaking strategy expansion was announced in 2024. Approximately 70% of stolen funds remained uncompensated from cash reserves, with users depending on the future realized value of SDY tokens for full recovery.","heading":"Relaunch and Token Compensation Plan","sources":[{"url":"https://blog.steadefi.com/steadefi-relaunch-and-compensation-plan","name":"blog.steadefi.com","type":"other","credibility":3},{"url":"https://blog.steadefi.com/steadefi-v2-secure-relaunch-and-compensation-details","name":"blog.steadefi.com","type":"other","credibility":3},{"url":"https://blog.steadefi.com/exploit-analysis-and-reimbursement-plan","name":"blog.steadefi.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Steadefi's own post-mortem identified two primary operational security failures that enabled the exploit. First, the protocol's entire permission model was concentrated in a single deployer account with no multisig safeguards, meaning compromise of one private key granted full administrative control over all contracts across both chains simultaneously. Second, there were no timelocks or time-delayed ownership transfer mechanisms in place, allowing the attacker to transfer ownership and drain funds within minutes of gaining access. Security researchers at Halborn noted that implementation of a multi-signature wallet for owner functions would have prevented this class of attack. The protocol's audited status — confirmed by its own documentation — did not cover operational key management practices.","heading":"Operational Security Failures","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-steadefi-hack-august-2023","name":"halborn.com","type":"other","credibility":3},{"url":"https://blog.steadefi.com/exploit-analysis-and-reimbursement-plan","name":"blog.steadefi.com","type":"other","credibility":3},{"url":"https://docs.steadefi.com/security/audits","name":"docs.steadefi.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2023-06-17","event":"A team member allegedly downloaded a malware-laden file during a Telegram conversation with an entity identifying itself as 'Spirit Blockchain Group', according to Steadefi's post-mortem.","source":""},{"date":"2023-06-28","event":"The deployer wallet's MetaMask seed phrases were compromised, allegedly as a result of the June 17 malware infection.","source":""},{"date":"2023-08-07","event":"Attacker exploited the compromised deployer private key at approximately 4:06 PM UTC to transfer ownership of all lending and strategy vaults on Arbitrum and Avalanche to address 0x9cf71F2ff126B9743319B60d2D873F0E508810dc. Approximately $1.14 million in assets drained and bridged to Ethereum mainnet via Synapse bridge.","source":""},{"date":"2023-08-09","event":"Steadefi publicly disclosed the exploit via Twitter, warning all funds were at risk.","source":""},{"date":"2023-08-10","event":"Deadline passed for Steadefi's bounty offer of 10% of stolen funds in exchange for the return of 90%. Offer was not accepted by the attacker.","source":""},{"date":"2023-08-23","event":"Steadefi published full exploit analysis and reimbursement plan. Recovery portal opened at steadefi.com/claim for proportional USDC distribution to affected wallets.","source":""},{"date":"2023-09","event":"Steadefi published relaunch and compensation plan, announcing security upgrades including multisig permissions, timelocks, and Hypernative real-time monitoring.","source":"","date_original":"2023-09-01"},{"date":"2023-10","event":"On-chain analysis indicated attacker addresses began distributing funds through exchanges after alleged Tornado Cash mixing, per Merkle Science flow-of-funds analysis.","source":"","date_original":"2023-10-01"},{"date":"2023-12","event":"Protocol relaunched as Steadefi v2 with SDY token (replacing STEADY), enhanced security architecture, and compensation tokenomics targeting affected users.","source":"","date_original":"2023-12-01"},{"date":"2024","event":"Steadefi v3 vault migration announced, adding liquid restaking token (LRT) vault strategies and continued GMX v2 integration.","source":"","date_original":"2024-01-01"}],"sources_used":[{"url":"https://defillama.com/protocol/steadefi","name":"defillama.com","type":"other","archive_url":"http://web.archive.org/web/20250914051923/https://defillama.com/protocol/steadefi","credibility":3,"archive_timestamp":"2025-09-14T05:19:23+00:00"},{"url":"https://blog.steadefi.com/intro-to-steadefi","name":"blog.steadefi.com","type":"other","archive_url":"http://web.archive.org/web/20260214012621/https://blog.steadefi.com/intro-to-steadefi","credibility":3,"archive_timestamp":"2026-02-14T01:26:21+00:00"},{"url":"https://pexx.com/chaindebrief/heres-how-steadefi-will-make-yield-farming-simple-yet-effective/","name":"pexx.com","type":"other","archive_url":"http://web.archive.org/web/20251212064126/https://pexx.com/chaindebrief/heres-how-steadefi-will-make-yield-farming-simple-yet-effective/","credibility":3,"archive_timestamp":"2025-12-12T06:41:26+00:00"},{"url":"https://blog.steadefi.com/exploit-analysis-and-reimbursement-plan","name":"blog.steadefi.com","type":"other","archive_url":"https://web.archive.org/web/20260830040550/https://blog.steadefi.com/exploit-analysis-and-reimbursement-plan","credibility":3,"archive_timestamp":"2026-08-30T04:05:50+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-steadefi-hack-august-2023","name":"halborn.com","type":"other","archive_url":"http://web.archive.org/web/20260121032553/https://www.halborn.com/blog/post/explained-the-steadefi-hack-august-2023","credibility":3,"archive_timestamp":"2026-01-21T03:25:53+00:00"},{"url":"https://www.merklescience.com/blog/hack-track-steadefi-flow-of-funds-analysis","name":"merklescience.com","type":"other","archive_url":"http://web.archive.org/web/20260423023502/https://www.merklescience.com/blog/hack-track-steadefi-flow-of-funds-analysis","credibility":3,"archive_timestamp":"2026-04-23T02:35:02+00:00"},{"url":"https://www.web3isgoinggreat.com/single/steadefi-exploit","name":"web3isgoinggreat.com","type":"other","archive_url":"https://web.archive.org/web/20260830051349/https://www.web3isgoinggreat.com/single/steadefi-exploit","credibility":3,"archive_timestamp":"2026-08-30T05:13:49+00:00"},{"url":"https://beincrypto.com/steadefi-exploit-hack-funds-lost/","name":"beincrypto.com","type":"other","archive_url":"http://web.archive.org/web/20250831120528/https://beincrypto.com/steadefi-exploit-hack-funds-lost//","credibility":3,"archive_timestamp":"2025-08-31T12:05:28+00:00"},{"url":"https://crypto.news/hacked-protocol-steadefi-offers-33k-bounty-to-hacker/","name":"crypto.news","type":"other","archive_url":"http://web.archive.org/web/20260516205423/https://crypto.news/hacked-protocol-steadefi-offers-33k-bounty-to-hacker/","credibility":3,"archive_timestamp":"2026-05-16T20:54:23+00:00"},{"url":"https://blog.steadefi.com/steadefi-relaunch-and-compensation-plan","name":"blog.steadefi.com","type":"other","archive_url":"http://web.archive.org/web/20260512120441/https://blog.steadefi.com/steadefi-relaunch-and-compensation-plan","credibility":3,"archive_timestamp":"2026-05-12T12:04:41+00:00"},{"url":"https://blog.steadefi.com/steadefi-v2-secure-relaunch-and-compensation-details","name":"blog.steadefi.com","type":"other","archive_url":"http://web.archive.org/web/20260512131609/https://blog.steadefi.com/steadefi-v2-secure-relaunch-and-compensation-details","credibility":3,"archive_timestamp":"2026-05-12T13:16:09+00:00"},{"url":"https://docs.steadefi.com/security/audits","name":"docs.steadefi.com","type":"other","archive_url":"http://web.archive.org/web/20260514163516/https://docs.steadefi.com/security/audits","credibility":3,"archive_timestamp":"2026-05-14T16:35:16+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:39.262424+00:00","updated_at":"2026-08-30T05:14:10.253197+00:00"}}