{"investigation":{"slug":"thalaswap","entity_name":"ThalaSwap","trust_score":62,"severity_base":null,"score_modifier":20,"confidence":1,"status":"published","content_type":"investigation","summary":"ThalaSwap is the decentralized exchange component of Thala Labs, an Aptos-based DeFi protocol offering an AMM, the Move Dollar (MOD) overcollateralized stablecoin, liquid staking, and a launchpad. On November 15, 2024, an input-validation bug introduced in a two-line patch to the v1 farming contract allowed an attacker to drain $25.5 million in liquidity pool tokens; funds were fully recovered within hours after SEAL 911 identified the exploiter via on-chain evidence and the attacker returned assets in exchange for a $300,000 bounty.","sections":[{"content":"Thala Labs was founded to build a native DeFi stack on the Aptos blockchain using the Move programming language. The protocol bundles four products: ThalaSwap (an AMM-based DEX), Move Dollar (MOD, an overcollateralized CDP stablecoin backed by APT, liquid staking tokens, and stablecoins), a liquid staking module, and ThalaLaunch (a project launchpad). ThalaSwap describes its AMM as a 'rebalancing AMM' designed for capital-efficient liquidity provisioning. The protocol launched on Aptos mainnet in April 2023 and within days accumulated $10 million in total value locked (TVL) with nearly $1 million in daily swap volume. At peak, Thala reached approximately $250 million in TVL and consistently accounted for more than 30% of spot trading volume on Aptos. The native governance token is THL, with a fixed supply of 100,000,000. Thala Labs raised a $6 million seed round on October 25, 2022, co-led by ParaFi Capital, White Star Capital, and Shima Capital, with additional participation from BECO Capital, LedgerPrime, Saison Capital, and Infinity Ventures Crypto. The team comprises approximately 13 members with stated backgrounds from Google, Dapper Labs, BitGo, Terraform Labs, and ParaFi Capital. ThalaSwap V2 and V3 (concentrated liquidity / CLMM) were subsequently released, with V3 becoming the primary liquidity venue as of 2025.","heading":"Background","sources":[{"url":"https://www.theblock.co/post/177279/parafi-backs-thala-labs-6-million-raise-to-build-defi-stack-on-aptos-exclusive","name":"","type":"other","credibility":3},{"url":"https://defillama.com/protocol/thalaswap","name":"","type":"other","credibility":3},{"url":"https://www.signum.capital/blog/why-we-invested-in-thala-labs/","name":"","type":"other","credibility":3},{"url":"https://aptosnetwork.com/currents/ecosystem-spotlight-thala-building-defi-primitives-on-aptos","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"On November 15, 2024, beginning at 4:46 AM PST, an attacker exploited a critical input-validation vulnerability in Thala's v1 farming contract. The vulnerability was introduced on November 1, 2024, by a two-line patch that bypassed the standard security review process due to its perceived simplicity. The bug failed to validate that a user's requested withdrawal of staked tokens did not exceed their actual staked balance — a missing sanity check on the unstake function. The attack proceeded in two phases. The initial phase began at 4:46 AM PST from attacker address 0xf7…, with a second, larger drain completed at 7:10 AM PST by a related address 0x80…. The attacker added liquidity to receive THALA-LP tokens, staked and then fully unstaked them to reduce their balance to zero, and subsequently submitted an unstake request for a large quantity of THALA-LP tokens they no longer held. The farming contract honored the request without verifying the staker's balance. Affected liquidity pools included MOD/USDC, MOD/THL, and THAPT/APT. Total liquidity pool tokens drained amounted to $25.5 million. TVL alerts within the protocol triggered at 5:12 AM PST, and the vulnerability was identified by 7:30 AM PST. All relevant smart contracts were paused and $11.5 million in Thala-related assets — comprising approximately $9 million in MOD tokens and $2.5 million in THL tokens — were frozen by the team. The THL token dropped nearly 40% in value in the hours following the announcement. Security firm Halborn noted that Move's decompilability facilitated the attacker's ability to locate the vulnerability, though it also aided post-incident analysis.","heading":"The Exploit","sources":[{"url":"https://thalalabs.medium.com/thala-nov-15-post-mortem-5aea82bb3916","name":"","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-thala-hack-november-2024","name":"","type":"other","credibility":3},{"url":"https://x.com/ThalaLabs/status/1857703541089120541","name":"","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/thala-recovers-25-million-exploiter-hacker-caught","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"The on-chain footprint of the attack was described by blockchain security group SEAL 911 as providing obvious links to the exploiter's real-world identity. SEAL 911 and researcher Ogle identified the attacker within minutes of the breach based on on-chain wallet connections, without needing extended forensic analysis. The initial attacker address is partially identified in the Thala post-mortem as beginning 0xf7…, with a second address beginning 0x80… completing the majority of the drain. The attacked pools — MOD/USDC, MOD/THL, and THAPT/APT — were all part of the v1 farming contract set. The protocol team communicated with the attacker via an on-chain message at 9:34 AM PST on November 15. The attacker agreed to return all funds by 10:13 AM PST and full recovery was confirmed by 11:13 AM PST, approximately six hours after the initial exploit transaction. Full transaction hashes were not publicly released in post-mortem documentation reviewed for this investigation. The Quadriga Initiative case study noted the absence of a bug bounty program prior to the exploit as a contributing factor that may have discouraged responsible disclosure.","heading":"On-Chain Evidence","sources":[{"url":"https://thalalabs.medium.com/thala-nov-15-post-mortem-5aea82bb3916","name":"","type":"other","credibility":3},{"url":"https://quadrigainitiative.com/casestudy/thalalabsv1farmingcontractvulnerability.php","name":"","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/thala-recovers-25-million-exploiter-hacker-caught","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Recovery of exploited funds was achieved within approximately six hours of the initial exploit. Thala Labs, assisted by SEAL 911, researcher Ogle, and law enforcement contacts, identified the exploiter through on-chain analysis. The attacker, described as a white hat actor in some reporting, subsequently reached out voluntarily and agreed to return all stolen assets. Thala negotiated a $300,000 protocol bounty payment plus an additional $40,000 personal payment to the founding team in exchange for the full return of $25.5 million. Full recovery was confirmed by 11:13 AM PST on November 15, 2024. Thala stated that all affected user positions would be made 100% whole and that users did not need to take further action. Following recovery, the protocol implemented several security improvements: mandatory comprehensive test coverage for all code changes; an end-to-end re-audit of contracts by OtterSec; protocol-wide withdrawal rate limits capping withdrawals from farming pools, LSD redemptions, and select ThalaSwap pools within defined timeframes; elimination of emergency patches in favor of full release cycles; enhanced alerting and incident response protocols; capability-based access control models; and self-custody receipts replacing asset escrow. CoinTelegraph and The Block both confirmed the successful recovery via statements from the Thala team.","heading":"Recovery","sources":[{"url":"https://thalalabs.medium.com/thala-nov-15-post-mortem-5aea82bb3916","name":"","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/thala-recovers-25-million-exploiter-hacker-caught","name":"","type":"other","credibility":3},{"url":"https://www.theblock.co/post/326937/defi-protocol-thala-recovers-25-million-following-successful-hacker-negotiation","name":"","type":"other","credibility":3},{"url":"https://cybernews.com/crypto/hacked-crypto-project-thala-paid-to-recover-millions/","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Thala Labs operates with approximately 13 team members. The organization states that contributors hold backgrounds from Google, Dapper Labs, BitGo, Terraform Labs, ParaFi Capital, MakerDAO, NEAR, Twitter, Apple, and Amazon. Individual founder names are not prominently disclosed in official materials or the major press coverage reviewed for this investigation, which limits independent verification of specific claimed credentials. The team raised a $6 million seed round in October 2022 co-led by ParaFi Capital, White Star Capital, and Shima Capital. The protocol is headquartered without a disclosed jurisdiction. No regulatory actions, OFAC designations, or law enforcement proceedings against Thala Labs or named team members were identified in the sources reviewed for this investigation.","heading":"Team","sources":[{"url":"https://www.theblock.co/post/177279/parafi-backs-thala-labs-6-million-raise-to-build-defi-stack-on-aptos-exclusive","name":"","type":"other","credibility":3},{"url":"https://www.signum.capital/blog/why-we-invested-in-thala-labs/","name":"","type":"other","credibility":3},{"url":"https://whitestarcapital.com/companies/thala-labs/","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"ThalaSwap presents a mixed risk profile. On the negative side: the protocol suffered a $25.5 million exploit in November 2024 caused by an insufficiently reviewed two-line code patch, indicating a process failure in change management and pre-deployment security review. The bug was a basic input-validation error — a class of vulnerability that thorough auditing and code review should catch. The lack of a bug bounty program prior to the exploit removed an important layer of community-based security discovery. TVL as of mid-2026 stands at approximately $2.23 million, a significant decline from the pre-hack peak of approximately $250 million, suggesting sustained user trust erosion. The THL token lost approximately 40% of its value immediately following the hack announcement; full recovery to prior price levels has not been confirmed in reviewed sources. On the positive side: the team responded quickly (contracts paused within hours), recovered 100% of user funds, paid a $300,000 bounty rather than litigating or blaming third parties, and engaged SEAL 911 and law enforcement effectively. The post-mortem was transparent and included a concrete list of remediation steps. A full re-audit by OtterSec was commissioned. Protocol-wide withdrawal rate limits were implemented as a structural safeguard. No regulatory actions have been filed against the protocol or its team. The protocol remains operational with ThalaSwap V2 and V3 (CLMM) live on Aptos. Overall, the exploit reveals meaningful operational security weaknesses that have been partially addressed; the protocol is not an exit scam or rug pull, but the trust damage from a nine-figure exploit on a protocol of this size represents an elevated risk for users considering significant capital deployment.","heading":"Risk Assessment","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-thala-hack-november-2024","name":"","type":"other","credibility":3},{"url":"https://quadrigainitiative.com/casestudy/thalalabsv1farmingcontractvulnerability.php","name":"","type":"other","credibility":3},{"url":"https://defillama.com/protocol/thalaswap","name":"","type":"other","credibility":3},{"url":"https://thalalabs.medium.com/thala-nov-15-post-mortem-5aea82bb3916","name":"","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2022-10-25","event":"Thala Labs raises $6 million seed round co-led by ParaFi Capital, White Star Capital, and Shima Capital","source":""},{"date":"2023-04-06","event":"Thala protocol launches on Aptos mainnet; reaches $10M TVL within days","source":""},{"date":"2024-11","event":"Two-line patch deployed to v1 farming contract, introducing the unstake_max input-validation bug that bypassed standard security review","source":"","date_original":"2024-11-01"},{"date":"2024-11-15","event":"Exploit begins at 4:46 AM PST from address 0xf7…; second larger drain completed at 7:10 AM PST from address 0x80…; total $25.5M in LP tokens stolen","source":""},{"date":"2024-11-15","event":"TVL alerts trigger at 5:12 AM PST; vulnerability identified by 7:30 AM PST; all relevant contracts paused; $11.5M in Thala assets frozen","source":""},{"date":"2024-11-15","event":"SEAL 911 and Ogle identify attacker via on-chain evidence within minutes; on-chain message sent to attacker at 9:34 AM PST","source":""},{"date":"2024-11-15","event":"Attacker agrees to return all funds by 10:13 AM PST in exchange for $300,000 protocol bounty and $40,000 personal payment; full recovery confirmed by 11:13 AM PST","source":""},{"date":"2024-11-16","event":"Thala Labs publishes post-mortem on Medium detailing root cause, timeline, and remediation steps including OtterSec re-audit and withdrawal rate limits","source":""},{"date":"2025","event":"ThalaSwap V3 (CLMM concentrated liquidity) becomes primary liquidity venue; protocol remains operational with $2.23M TVL as of mid-2026","source":"","date_original":"2025-01-01"}],"sources_used":[{"url":"https://www.theblock.co/post/177279/parafi-backs-thala-labs-6-million-raise-to-build-defi-stack-on-aptos-exclusive","name":"","type":"other","archive_url":"http://web.archive.org/web/20251221004707/https://www.theblock.co/post/177279/parafi-backs-thala-labs-6-million-raise-to-build-defi-stack-on-aptos-exclusive","credibility":3,"archive_timestamp":"2025-12-21T00:47:07+00:00"},{"url":"https://defillama.com/protocol/thalaswap","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.signum.capital/blog/why-we-invested-in-thala-labs/","name":"","type":"other","archive_url":"https://web.archive.org/web/20260829091543/https://www.signum.capital/blog/why-we-invested-in-thala-labs/","credibility":3,"archive_timestamp":"2026-08-29T09:15:43+00:00"},{"url":"https://aptosnetwork.com/currents/ecosystem-spotlight-thala-building-defi-primitives-on-aptos","name":"","type":"other","archive_url":"http://web.archive.org/web/20260412172607/https://aptosnetwork.com/currents/ecosystem-spotlight-thala-building-defi-primitives-on-aptos","credibility":3,"archive_timestamp":"2026-04-12T17:26:07+00:00"},{"url":"https://thalalabs.medium.com/thala-nov-15-post-mortem-5aea82bb3916","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.halborn.com/blog/post/explained-the-thala-hack-november-2024","name":"","type":"other","archive_url":"http://web.archive.org/web/20260414133233/https://www.halborn.com/blog/post/explained-the-thala-hack-november-2024","credibility":3,"archive_timestamp":"2026-04-14T13:32:33+00:00"},{"url":"https://x.com/ThalaLabs/status/1857703541089120541","name":"","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://cointelegraph.com/news/thala-recovers-25-million-exploiter-hacker-caught","name":"","type":"other","archive_url":"http://web.archive.org/web/20260417003625/https://cointelegraph.com/news/thala-recovers-25-million-exploiter-hacker-caught","credibility":3,"archive_timestamp":"2026-04-17T00:36:25+00:00"},{"url":"https://quadrigainitiative.com/casestudy/thalalabsv1farmingcontractvulnerability.php","name":"","type":"other","archive_url":"https://web.archive.org/web/20260829230741/https://quadrigainitiative.com/casestudy/thalalabsv1farmingcontractvulnerability.php","credibility":3,"archive_timestamp":"2026-08-29T23:07:41+00:00"},{"url":"https://www.theblock.co/post/326937/defi-protocol-thala-recovers-25-million-following-successful-hacker-negotiation","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://cybernews.com/crypto/hacked-crypto-project-thala-paid-to-recover-millions/","name":"","type":"other","archive_url":"http://web.archive.org/web/20251010032340/https://cybernews.com/crypto/hacked-crypto-project-thala-paid-to-recover-millions/","credibility":3,"archive_timestamp":"2025-10-10T03:23:40+00:00"},{"url":"https://whitestarcapital.com/companies/thala-labs/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260610063431/https://whitestarcapital.com/companies/thala-labs/","credibility":3,"archive_timestamp":"2026-06-10T06:34:31+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":true,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:27.754558+00:00","updated_at":"2026-08-29T23:26:13.79702+00:00"}}