{"investigation":{"slug":"team-finance","entity_name":"Team Finance","trust_score":28,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"Team Finance is a DeFi token-locking and vesting platform operated by TrustSwap Inc. that suffered a critical $14.5 million exploit on October 27, 2022, when an attacker abused a validation flaw in its Uniswap V2-to-V3 migration function. The attacker ultimately returned approximately $7 million, retaining roughly 10% as a self-declared bug bounty; Team Finance subsequently switched auditors to CertiK and reported full user reimbursement by June 2023.","sections":[{"content":"Team Finance is a decentralized application (dApp) that allows blockchain projects to lock team tokens and liquidity-provider (LP) tokens in time-released smart contract vaults, create vesting schedules, and manage token distributions. It was founded in 2020 as part of TrustSwap Inc., whose CEO and co-founder Jeff Kirdeikis also served as Team Finance's public face until stepping down as CEO and transitioning to Board Chairman in July 2023. According to TrustSwap's April 2022 press release, the platform had secured more than $6.5 billion in total value and served over 21,000 projects at the time. By 2024, DeFiLlama reported the platform remained active across 17 chains with a TVL of approximately $55 million. The platform's core value proposition is trust-signaling to retail investors: locking liquidity proves that project teams cannot perform rug pulls during lock periods.","heading":"Background","sources":[{"url":"https://www.businesswire.com/news/home/20220429005583/en/TrustSwaps-Team.Finance-Continues-to-Be-the-Industry-Leader-in-Cryptocurrency-Token-Locks-and-Management","name":"","type":"other","credibility":3},{"url":"https://defillama.com/protocol/team-finance","name":"","type":"other","credibility":3},{"url":"https://www.crunchbase.com/person/jeff-kirdeikis","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"On October 27, 2022, Team Finance's Liquidity Locks smart contract was exploited for approximately $14.5 million through a critical input-validation flaw in its migrate() function, which was responsible for moving locked liquidity positions from Uniswap V2 pools to Uniswap V3. The attacker deployed a malicious contract and locked fraudulent tokens to the Team Finance contract for a cost of approximately $2,700 in initial funding (sourced from FixedFloat). The vulnerability resided in the migrate() function's failure to verify that the pair parameter and the token0/token1 parameters referred to the same underlying pool. Because amount0V2/amount1V2 were calculated from the pair parameter while amount0V3/amount1V3 were derived from the attacker-supplied token0/token1 values, the attacker could pass a legitimate pool's address as pair while substituting attacker-controlled fake token addresses for token0 and token1. The Uniswap V3 migrator burned legitimate LP tokens from the referenced V2 pool and minted V3 positions using the fake token addresses; the refund mechanism then returned legitimate WETH and USDC to the attacker's recipient address based on the skewed accounting. The exploit was executed in four separate attack transactions targeting four token pairs: FEG/WETH (approximately $2.55 million), USDC/CAW (approximately $4.89 million plus USDC), USDC/TSUKA (approximately $1.46 million), and WETH/KNDX (approximately $658,000). Total drained value across the four pools reached approximately $15.8 million at the time of the attack, though the figure cited in most reports is $14.5 million after accounting for token pricing. Team Finance paused all protocol activity immediately upon detection. The Zokyo audit conducted in August 2022 had flagged two critical issues in the migrate() function — including the use of arbitrary token addresses — but Team Finance dismissed the finding, stating that 'this is an intended logic and users should be able to use arbitrary token addresses.' An earlier Hacken audit from January-February 2022 did not cover the migrate() function because the functionality had not yet been added to the codebase at that time.","heading":"The Exploit","sources":[{"url":"https://medium.com/haechi-audit/team-finance-incident-analysis-537656284ed0","name":"","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-team-finance-hack-october-2022","name":"","type":"other","credibility":3},{"url":"https://hacken.io/insights/why-team-finance-was-exploited-for-14-5-million-despite-its-audit/","name":"","type":"other","credibility":3},{"url":"https://www.theblock.co/post/180369/hacker-uses-2700-to-drain-15-8-million-from-team-finance","name":"","type":"other","credibility":3},{"url":"https://blockworks.co/news/defi-platform-exploited-for-14-5m-despite-security-audits","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"On-chain records confirm the following attacker infrastructure and transactions. The primary attacker address is 0x161cebB807Ac181d5303A4cCec2FC580CC5899Fd. The attacker deployed an intermediate exploit contract at 0xCFF07C4e6aa9E2fEc04DAaF5f41d1b10f3adAdF4. Funds were subsequently transferred via 0xba399a2580785a2ded740f5e30ec89fb3e617e6e. The main exploit transaction hash is 0xb2e3ea72d353da43a2ac9a8f1670fd16463ab370e563b9b5b26119b2601277ce. The initial lock transaction establishing fraudulent positions is 0xe8f17ee00906cd0cfb61671937f11bd3d26cdc47c1534fedc43163a7e89edc6f. Initial funding of 1.76 ETH was sourced from the FixedFloat exchange. Stolen assets included USDC, FEG, CAW (A Hunters Dream), TSUKA (Dejitaru Tsuka), and KNDX (Kondux) tokens, drawn from LP pools that had been locked on Team Finance by those projects. The Team Finance Liquidity Lock contract address on Ethereum is 0xe2fe530c047f2d85298b07d9333c05737f1435fb. All on-chain data is verifiable via Etherscan.","heading":"On-Chain Evidence","sources":[{"url":"https://slowmist.medium.com/analysis-review-of-team-finance-exploit-f439c2f63e2","name":"","type":"other","credibility":3},{"url":"https://medium.com/haechi-audit/team-finance-incident-analysis-537656284ed0","name":"","type":"other","credibility":3},{"url":"https://etherscan.io/address/0xe2fe530c047f2d85298b07d9333c05737f1435fb","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Team Finance is operated by TrustSwap Inc. Jeff Kirdeikis, the company's founder and then-CEO, served as the primary public spokesperson following the incident. Following the exploit, Team Finance publicly appealed to the attacker to return funds in exchange for a bounty. On October 29-31, 2022, the attacker sent on-chain messages identifying themselves as a 'whitehat' and returned funds in stages to the four affected projects. Kondux received approximately 209 ETH (approximately 95% of stolen funds). Dejitaru Tsuka received over $765,000 in DAI and 11.8 million TSUKA tokens. FEG Token received approximately 548 ETH. CAW (A Hunters Dream) received over $5 million in DAI and 74.6 billion CAW tokens. The attacker retained approximately 10% of stolen value, equivalent to roughly $1.5 million, as a self-declared bug bounty. Total returned funds were approximately $7 million at October 2022 token prices, with SlowMist later reporting the figure closer to $13.4 million when accounting for additional returned assets. Team Finance subsequently replaced Zokyo as its auditor with CertiK, engaged multiple additional audit firms, and reported enhanced internal QA and backend security processes. As of June 2023, a Team Finance representative stated that all affected users had received the vast majority of their funds back. The migrate() function remains the focal point of post-incident remediation; developers recommended pre-execution validation using Uniswap V3's PoolAddress.computeAddress() to verify parameter integrity.","heading":"Team & Recovery","sources":[{"url":"https://www.coindesk.com/tech/2022/10/31/attacker-behind-145m-team-finance-exploit-returns-7m","name":"","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/team-finance-hacker-returns-7m-to-associated-projects-after-exploit","name":"","type":"other","credibility":3},{"url":"https://beincrypto.com/another-white-hat-hacker-returns-funds-from-platform-exploit/","name":"","type":"other","credibility":3},{"url":"https://slowmist.medium.com/analysis-review-of-team-finance-exploit-f439c2f63e2","name":"","type":"other","credibility":3},{"url":"https://www.cryptopolitan.com/team-finance-exploited-for-15-million/","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Team Finance presents a mixed risk profile. The October 2022 exploit demonstrated a critical failure in pre-deployment security practices: a Zokyo audit raised the exact vulnerability as a critical finding, yet Team Finance leadership dismissed it as intended behavior. This response to a critical audit finding represents a significant governance and risk management failure. The platform does not have a history of exit fraud or deliberate malice; the exploit was a technical vulnerability exploited by a third party who subsequently returned the majority of funds. Post-incident, Team Finance undertook remediation steps including a new CertiK audit, multi-firm audit engagement, and backend security improvements, and reported full user reimbursement by mid-2023. However, several risk factors persist. First, the platform's pre-exploit conduct — deploying unvalidated migration logic despite audit warnings — demonstrates a pattern of prioritizing feature velocity over security. Second, the platform's role as a liquidity locker means downstream project communities are collaterally harmed when Team Finance itself is exploited, as was the case with the FEG, CAW, TSUKA, and KNDX communities. Third, the attacker retained approximately 10% of stolen funds, meaning not all losses were recovered. Fourth, while the attacker's self-description as a whitehat is consistent with returning funds, the initial act of draining $14.5 million remains an unauthorized exploit regardless of subsequent fund returns. Users should verify that any current Team Finance contracts have received fresh, comprehensive audits and should monitor whether the migrate() function or any similar cross-protocol migration functionality has been re-introduced since the exploit.","heading":"Risk Assessment","sources":[{"url":"https://hacken.io/insights/why-team-finance-was-exploited-for-14-5-million-despite-its-audit/","name":"","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-team-finance-hack-october-2022","name":"","type":"other","credibility":3},{"url":"https://immunebytes.com/blog/team-finance-exploit-oct-27-2022-detailed-analysis/","name":"","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2020","event":"Team Finance founded as part of TrustSwap Inc., offering token locking and vesting smart contracts for DeFi projects.","source":"","date_original":"2020-01-01"},{"date":"2022-01-19","event":"Hacken conducts smart contract audit of Team Finance's LockToken.sol and related contracts; migrate() function not yet in scope as it had not been added to the codebase.","source":""},{"date":"2022-04-29","event":"TrustSwap publishes press release stating Team Finance has secured over $6.5 billion in total value and serves more than 21,000 projects.","source":""},{"date":"2022-08","event":"Zokyo conducts audit of Team Finance contracts including the migrate() function, flagging two critical vulnerabilities related to arbitrary token address use and reentrancy. Team Finance dismisses findings as 'intended logic.'","source":"","date_original":"2022-08-01"},{"date":"2022-10-27","event":"Exploit executed: attacker drains approximately $14.5–15.8 million from four LP pools (FEG, CAW, TSUKA, KNDX) locked on Team Finance via a manipulated Uniswap V2-to-V3 migration call. Team Finance immediately pauses all protocol activity.","source":""},{"date":"2022-10-28","event":"Team Finance publicly appeals to the attacker to return funds in exchange for a bounty. SlowMist, KALOS Security, and other firms publish on-chain analysis of the exploit.","source":""},{"date":"2022-10-29","event":"Attacker begins returning funds to affected projects via on-chain transactions, identifying themselves as a 'whitehat' hacker in embedded transaction messages.","source":""},{"date":"2022-10-31","event":"Approximately $7 million in tokens returned to the four affected project communities (Kondux, Tsuka, FEG, CAW). Attacker retains roughly 10% as a self-declared bug bounty. CoinDesk and CoinTelegraph report on the partial recovery.","source":""},{"date":"2023-06","event":"Team Finance representative states that all affected users have received the vast majority of their funds back. Platform reports CertiK engaged as new auditor and multiple security enhancements implemented.","source":"","date_original":"2023-06-01"},{"date":"2023-07","event":"Jeff Kirdeikis transitions from CEO to Board Chairman of TrustSwap.","source":"","date_original":"2023-07-01"}],"sources_used":[{"url":"https://www.businesswire.com/news/home/20220429005583/en/TrustSwaps-Team.Finance-Continues-to-Be-the-Industry-Leader-in-Cryptocurrency-Token-Locks-and-Management","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://defillama.com/protocol/team-finance","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.crunchbase.com/person/jeff-kirdeikis","name":"","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://medium.com/haechi-audit/team-finance-incident-analysis-537656284ed0","name":"","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://www.halborn.com/blog/post/explained-the-team-finance-hack-october-2022","name":"","type":"other","archive_url":"http://web.archive.org/web/20260317023753/https://www.halborn.com/blog/post/explained-the-team-finance-hack-october-2022","credibility":3,"archive_timestamp":"2026-03-17T02:37:53+00:00"},{"url":"https://hacken.io/insights/why-team-finance-was-exploited-for-14-5-million-despite-its-audit/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260516020056/https://hacken.io/insights/why-team-finance-was-exploited-for-14-5-million-despite-its-audit/","credibility":3,"archive_timestamp":"2026-05-16T02:00:56+00:00"},{"url":"https://www.theblock.co/post/180369/hacker-uses-2700-to-drain-15-8-million-from-team-finance","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://blockworks.co/news/defi-platform-exploited-for-14-5m-despite-security-audits","name":"","type":"other","archive_url":"http://web.archive.org/web/20260210154112/https://blockworks.co/news/defi-platform-exploited-for-14-5m-despite-security-audits","credibility":3,"archive_timestamp":"2026-02-10T15:41:12+00:00"},{"url":"https://slowmist.medium.com/analysis-review-of-team-finance-exploit-f439c2f63e2","name":"","type":"other","archive_url":"http://web.archive.org/web/20250919131534/https://slowmist.medium.com/analysis-review-of-team-finance-exploit-f439c2f63e2","credibility":3,"archive_timestamp":"2025-09-19T13:15:34+00:00"},{"url":"https://etherscan.io/address/0xe2fe530c047f2d85298b07d9333c05737f1435fb","name":"","type":"other","archive_url":"http://web.archive.org/web/20260720154945/https://etherscan.io/address/0xE2fE530C047f2d85298b07D9333C05737f1435fB","credibility":3,"archive_timestamp":"2026-07-20T15:49:45+00:00"},{"url":"https://www.coindesk.com/tech/2022/10/31/attacker-behind-145m-team-finance-exploit-returns-7m","name":"","type":"other","archive_url":"http://web.archive.org/web/20251025013009/https://www.coindesk.com/tech/2022/10/31/attacker-behind-145m-team-finance-exploit-returns-7m","credibility":3,"archive_timestamp":"2025-10-25T01:30:09+00:00"},{"url":"https://cointelegraph.com/news/team-finance-hacker-returns-7m-to-associated-projects-after-exploit","name":"","type":"other","archive_url":"https://web.archive.org/web/20260829182748/https://cointelegraph.com/news/team-finance-hacker-returns-7m-to-associated-projects-after-exploit","credibility":3,"archive_timestamp":"2026-08-29T18:27:48+00:00"},{"url":"https://beincrypto.com/another-white-hat-hacker-returns-funds-from-platform-exploit/","name":"","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://www.cryptopolitan.com/team-finance-exploited-for-15-million/","name":"","type":"other","archive_url":"https://web.archive.org/web/20260830005015/https://www.cryptopolitan.com/team-finance-exploited-for-15-million/","credibility":3,"archive_timestamp":"2026-08-30T00:50:15+00:00"},{"url":"https://immunebytes.com/blog/team-finance-exploit-oct-27-2022-detailed-analysis/","name":"","type":"other","archive_url":"http://web.archive.org/web/20251216160240/https://immunebytes.com/blog/team-finance-exploit-oct-27-2022-detailed-analysis/","credibility":3,"archive_timestamp":"2025-12-16T16:02:40+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:47.037204+00:00","updated_at":"2026-08-30T05:14:12.403799+00:00"}}