{"investigation":{"slug":"tinyman","entity_name":"Tinyman","trust_score":47,"severity_base":null,"score_modifier":-5,"confidence":0.82,"status":"published","content_type":"investigation","summary":"Tinyman is an automated market maker (AMM) and decentralized exchange (DEX) built on the Algorand blockchain, launched on mainnet in October 2021. On January 1, 2022, attackers exploited a logic flaw in the protocol's pool-token burn function to drain approximately $3 million in wrapped Bitcoin and Ethereum assets across 43 pools. Tinyman subsequently patched the contracts, launched a compensation program covering all affected liquidity providers, and released a fully re-audited v2.0 protocol in early 2023.","sections":[{"content":"Tinyman is an Algorand-native automated market maker that operates as a constant-product AMM, enabling permissionless token swaps between Algorand Standard Assets (ASAs). The protocol launched on Algorand mainnet in October 2021, positioning itself as the first fully operational DEX on the network. Prior to the January 2022 exploit, Tinyman held approximately $43 million in total value locked, making it the dominant liquidity venue on Algorand. The project raised $2.5 million in a pre-launch funding round with investors including Borderless Capital, Arrington Capital, Digital Currency Group, BlockTower Capital, and GoldenTree Asset Management. Founder Kaan Eryilmaz described the platform as a gateway DeFi primitive for the Algorand ecosystem.","heading":"Protocol Overview","sources":[{"url":"https://www.coindesk.com/business/2021/10/07/defi-for-the-small-guy-algorand-based-tinyman-raises-25m-ahead-of-dex-launch","name":"DeFi for the Small Guy: Algorand-Based Tinyman Raises $2.5M Ahead of DEX Launch — CoinDesk","type":"news_article","credibility":1},{"url":"https://tinyman.org/","name":"Tinyman official site","type":"official","credibility":1}],"severity":"low"},{"content":"Beginning at approximately 19:03 UTC on January 1, 2022, a group of 13 unique wallet addresses exploited a previously unknown logic flaw in Tinyman's pool smart contracts. The vulnerability resided in the burn function, which is invoked when a liquidity provider redeems pool tokens to withdraw their proportional share of a pool's two underlying assets. Due to an error in the TEAL contract code, an attacker could manipulate the burn operation to receive two units of the same higher-value asset rather than one unit of each of the two assets in the pair. In the primary attack vector, the perpetrator targeted ALGO/goBTC and ALGO/goETH pools: by exploiting the burn logic, they received double the amount of goBTC or goETH without surrendering the corresponding ALGO value. This was not a flash-loan attack; it was a smart contract logic error that any account could exploit by calling the standard burn transaction with a specially crafted transaction group. The first attacker completed approximately 16 transactions within one hour; subsequent attackers detected and replicated the exploit roughly six hours later. Across all perpetrators, 360 malicious transactions were executed against 43 separate pools.","heading":"January 2022 Exploit: Attack Mechanism","sources":[{"url":"https://tinymanorg.medium.com/official-announcement-about-the-incidents-of-01-01-2022-56abb19d8b19","name":"Official Announcement About the Incidents of 01.01.2022 — Tinyman Medium","type":"official","credibility":1},{"url":"https://tinymanorg.medium.com/technical-report-1-first-insights-cbc12109ef08","name":"Technical Report 1: First Insights — Tinyman Medium","type":"official","credibility":1},{"url":"https://www.halborn.com/blog/post/explained-the-tinyman-hack-january-2022","name":"Explained: The Tinyman Hack (January 2022) — Halborn","type":"research","credibility":2},{"url":"https://www.trmlabs.com/resources/blog/first-defi-liquidity-pool-exploited-in-2022","name":"Tinyman: The First DeFi Exploit of 2022? — TRM Labs","type":"research","credibility":2}],"severity":"critical"},{"content":"The primary attacker (Account 1) extracted 13,576 ALGO, 29.218 goBTC, and 137.656 goETH across 16 transactions, totalling approximately $1.8 million at attack-time prices. Account 1 was responsible for roughly 70% of total damage. Secondary perpetrators collectively extracted an additional estimated $210,000 across a further 12 wallets. Total direct losses across all attackers amounted to approximately $3 million in goBTC and goETH. Approximately 250 liquidity providers held positions in the affected goBTC and goETH pools. The broader TVL impact was significant: total value locked dropped from approximately $43 million to $21 million within 12 hours of the initial attack, though the majority of that decline reflected users withdrawing their own liquidity in response to Tinyman's public warning rather than direct theft. The Tinyman team estimated that community reaction saved between 90 and 95 percent of total protocol liquidity. Separately, arbitrageurs extracted an estimated additional 1.2 million ALGO-equivalent value from the disrupted pool ratios during the attack period, bringing the aggregate ecosystem loss to approximately 3 million ALGO-equivalent.","heading":"Financial Losses and Affected Users","sources":[{"url":"https://tinymanorg.medium.com/technical-report-1-first-insights-cbc12109ef08","name":"Technical Report 1: First Insights — Tinyman Medium","type":"official","credibility":1},{"url":"https://tinymanorg.medium.com/tinyman-compensation-program-683dd2bd872b","name":"Tinyman Compensation Program — Tinyman Medium","type":"official","credibility":1},{"url":"https://cryptopotato.com/3-million-lost-as-an-algorand-based-decentralized-trading-platform-exploited/","name":"$3 Million Lost as an Algorand-Based Decentralized Trading Platform Exploited — CryptoPotato","type":"news_article","credibility":2},{"url":"https://beincrypto.com/algorand-based-tinyman-amm-exploited-for-3-million/","name":"Algorand-Based Tinyman AMM Exploited for $3 Million — BeInCrypto","type":"news_article","credibility":2}],"severity":"critical"},{"content":"Runtime Verification completed an initial security audit of Tinyman's v1 smart contracts on September 21, 2021, approximately ten weeks before the exploit. The audit covered the Pool Logic Signature Template (a stateless TEAL contract template) and the Validator Application (a stateful TEAL contract). The audit identified several issues requiring remediation, and a second-round review was conducted to verify corrections. Runtime Verification specifically noted that TEAL, the low-level stack language of the Algorand Virtual Machine, is complex to audit because verifying that compiled bytecode matches intended business logic is non-trivial. Despite this audit having been performed, the burn-function vulnerability that was exploited in January 2022 was not identified during that review process. The Halborn post-mortem attributed this to the difficulty of verifying control-flow correctness in low-level TEAL code. It is therefore accurate to state that a formal third-party audit was conducted prior to launch, but that audit did not catch the vulnerability that was subsequently exploited.","heading":"Audit History and Security Posture Prior to Exploit","sources":[{"url":"https://tinymanorg.medium.com/tinymans-audit-by-runtime-verification-eef1e7f8f824","name":"Tinyman's Smart Contract Audit is Completed by Runtime Verification — Tinyman Medium","type":"official","credibility":1},{"url":"https://runtimeverification.com/blog/runtime-verification-audits-tinyman","name":"Runtime Verification Audits Tinyman — Runtime Verification blog","type":"research","credibility":2},{"url":"https://www.halborn.com/blog/post/explained-the-tinyman-hack-january-2022","name":"Explained: The Tinyman Hack (January 2022) — Halborn","type":"research","credibility":2}],"severity":"high"},{"content":"Within hours of detecting the attack, Tinyman published a public advisory urging all liquidity providers to remove funds from every pool. The team disabled liquidity-adding routes on the web application and replaced them with warning notices. Law enforcement was contacted. On January 19, 2022, Tinyman relaunched with patched v1.1 contracts; the updated contracts had been reviewed by two audit firms and had also passed an internal bug-bounty process that surfaced a minor separate issue before relaunch. Tinyman announced a full compensation program, with distribution beginning on March 24, 2022. The program covered: directly stolen amounts (valued at pre-attack prices), stuck LP tokens remaining in v1 pools, and arbitraged amounts extracted during the attack. Funding came 10% from the protocol's transaction-fee treasury and 90% from investor capital drawn from Borderless Capital, Meld Ventures, and Jump Capital. Wallets with losses under 1 ALGO and wallets that added liquidity after block 18,403,162 (approximately 36 hours post-attack) were excluded. Payments were made in ALGO regardless of the original asset type lost.","heading":"Incident Response and Compensation","sources":[{"url":"https://tinymanorg.medium.com/official-announcement-about-the-incidents-of-01-01-2022-56abb19d8b19","name":"Official Announcement About the Incidents of 01.01.2022 — Tinyman Medium","type":"official","credibility":1},{"url":"https://tinymanorg.medium.com/tinyman-compensation-program-683dd2bd872b","name":"Tinyman Compensation Program — Tinyman Medium","type":"official","credibility":1},{"url":"https://coin.fyi/news/algorand/tinyman-re-launch-on-mainnet-and-next-steps-snrs1f","name":"Tinyman: Re-launch on Mainnet and Next Steps — coin.fyi","type":"news_article","credibility":3}],"severity":"medium"},{"content":"Tinyman announced v2.0 at the Algorand Decipher event in Dubai on November 30, 2022, with mainnet launch targeted for January 2023. A central security improvement was the rewrite of all smart contracts in Tealish, a higher-level, human-readable language that compiles to TEAL, addressing the auditing complexity cited as a contributing factor in the original exploit. Runtime Verification audited the v2.0 contracts with a multi-level methodology covering the protocol specification, the Tealish source code, and the generated TEAL bytecode. Tinyman also launched a public bug bounty program on Immunefi, with up to $250,000 in rewards funded with support from the Algorand Foundation. V2.0 introduced additional features including flash loans, flash swaps, flexible liquidity management, and composable calls. The combination of a higher-level contract language, multi-stage independent audit, and continuous incentivised bug disclosure represents a materially more robust security posture than existed at v1 launch.","heading":"V2.0 Protocol and Post-Exploit Security Improvements","sources":[{"url":"https://www.prnewswire.com/news-releases/decentralized-trading-platform-tinyman-introduces-version-2-0-and-new-readable-programming-language-tealish-at-algorand-decipher-event-in-dubai-301689634.html","name":"Decentralized Trading Platform Tinyman Introduces Version 2.0 — PR Newswire","type":"official","credibility":1},{"url":"https://runtimeverification.com/blog/runtime-verification-audits-tinyman-amm-v2","name":"Runtime Verification Audits Tinyman AMM V2 — Runtime Verification blog","type":"research","credibility":2},{"url":"https://tinymanorg.medium.com/tinyman-amm-v2-0-protocol-201e0f32f58d","name":"Tinyman AMM V2.0 Protocol — Tinyman Medium","type":"official","credibility":1},{"url":"https://docs.tinyman.org/audits-and-security","name":"Audits and Security — Tinyman Docs","type":"official","credibility":1}],"severity":"low"},{"content":"TRM Labs conducted on-chain forensic analysis of the attack and confirmed that the primary attacker's wallet was pre-funded from a centralized exchange prior to the exploit. As of January 6, 2022, the primary wallet still held approximately 21 goBTC that had not been moved. TRM's cross-chain analysis linked the funding wallet to the receiving wallet for the stolen goBTC and goETH, establishing a clear chain of custody. The Tinyman technical report confirmed 13 unique addresses were involved across 360 malicious transactions targeting 43 pools, with the primary attacker (Account 1) responsible for approximately 70% of losses. No public attribution to named individuals or groups had been made as of available reporting, and it is not publicly known whether law enforcement actions resulted in any recoveries or prosecutions.","heading":"On-Chain Forensics and Attacker Tracing","sources":[{"url":"https://www.trmlabs.com/resources/blog/first-defi-liquidity-pool-exploited-in-2022","name":"Tinyman: The First DeFi Exploit of 2022? — TRM Labs","type":"research","credibility":2},{"url":"https://tinymanorg.medium.com/technical-report-1-first-insights-cbc12109ef08","name":"Technical Report 1: First Insights — Tinyman Medium","type":"official","credibility":1}],"severity":"high"}],"timeline":[{"date":"2021-08","event":"Tinyman launches on Algorand testnet","source":"CoinDesk","source_url":"https://www.coindesk.com/business/2021/10/07/defi-for-the-small-guy-algorand-based-tinyman-raises-25m-ahead-of-dex-launch","date_original":"2021-08-01"},{"date":"2021-09-21","event":"Runtime Verification completes initial audit of Tinyman v1 smart contracts","source":"Tinyman Medium","source_url":"https://tinymanorg.medium.com/tinymans-audit-by-runtime-verification-eef1e7f8f824"},{"date":"2021-10-07","event":"Tinyman launches on Algorand mainnet; raises $2.5M from investors including Borderless Capital, DCG, and BlockTower","source":"CoinDesk","source_url":"https://www.coindesk.com/business/2021/10/07/defi-for-the-small-guy-algorand-based-tinyman-raises-25m-ahead-of-dex-launch"},{"date":"2022","event":"Exploit begins at 19:03 UTC; primary attacker executes 16 transactions exploiting burn function logic flaw, stealing approximately $1.8M in goBTC and goETH","source":"Tinyman Technical Report 1","source_url":"https://tinymanorg.medium.com/technical-report-1-first-insights-cbc12109ef08","date_original":"2022-01-01"},{"date":"2022-01-02","event":"Tinyman publishes official incident announcement; warns all liquidity providers to withdraw funds; disables liquidity routes on web app; contacts law enforcement","source":"Tinyman Medium","source_url":"https://tinymanorg.medium.com/official-announcement-about-the-incidents-of-01-01-2022-56abb19d8b19"},{"date":"2022-01-02","event":"Total attack scope confirmed: 13 unique attacker addresses, 43 pools drained, 360 malicious transactions, approximately $3M total losses including arbitrage","source":"Tinyman Technical Report 1","source_url":"https://tinymanorg.medium.com/technical-report-1-first-insights-cbc12109ef08"},{"date":"2022-01-19","event":"Tinyman v1.1 relaunches on mainnet with patched contracts; two audit firms reviewed the updated contracts; bug bounty program extended","source":"coin.fyi / Tinyman","source_url":"https://coin.fyi/news/algorand/tinyman-re-launch-on-mainnet-and-next-steps-snrs1f"},{"date":"2022-03-24","event":"Tinyman begins distributing compensation payments to affected liquidity providers; program covers stolen amounts, stuck LP tokens, and arbitraged losses","source":"Tinyman Compensation Program Medium","source_url":"https://tinymanorg.medium.com/tinyman-compensation-program-683dd2bd872b"},{"date":"2022-11-30","event":"Tinyman announces v2.0 at Algorand Decipher event in Dubai, featuring Tealish-written contracts, multi-level audit, and Immunefi bug bounty up to $250,000","source":"PR Newswire","source_url":"https://www.prnewswire.com/news-releases/decentralized-trading-platform-tinyman-introduces-version-2-0-and-new-readable-programming-language-tealish-at-algorand-decipher-event-in-dubai-301689634.html"},{"date":"2023","event":"Tinyman v2.0 mainnet launch (approximate); audited by Runtime Verification at specification, Tealish, and TEAL bytecode levels","source":"Runtime Verification blog","source_url":"https://runtimeverification.com/blog/runtime-verification-audits-tinyman-amm-v2","date_original":"2023-01-01"}],"sources_used":[{"url":"https://tinymanorg.medium.com/official-announcement-about-the-incidents-of-01-01-2022-56abb19d8b19","name":"Official Announcement About the Incidents of 01.01.2022 — Tinyman Medium","type":"official","archive_url":"http://web.archive.org/web/20260420091308/https://tinymanorg.medium.com/official-announcement-about-the-incidents-of-01-01-2022-56abb19d8b19","credibility":1,"archive_timestamp":"2026-04-20T09:13:08+00:00"},{"url":"https://tinymanorg.medium.com/technical-report-1-first-insights-cbc12109ef08","name":"Technical Report 1: First Insights — Tinyman Medium","type":"official","archive_url":"https://web.archive.org/web/20260726034810/https://tinymanorg.medium.com/technical-report-1-first-insights-cbc12109ef08","credibility":1,"archive_timestamp":"2026-07-26T03:48:10+00:00"},{"url":"https://tinymanorg.medium.com/tinyman-compensation-program-683dd2bd872b","name":"Tinyman Compensation Program — Tinyman Medium","type":"official","archive_url":"https://web.archive.org/web/20260726034843/https://tinymanorg.medium.com/tinyman-compensation-program-683dd2bd872b","credibility":1,"archive_timestamp":"2026-07-26T03:48:43+00:00"},{"url":"https://tinymanorg.medium.com/tinymans-audit-by-runtime-verification-eef1e7f8f824","name":"Tinyman's Smart Contract Audit is Completed by Runtime Verification — Tinyman Medium","type":"official","archive_url":"https://web.archive.org/web/20260724232448/https://tinymanorg.medium.com/tinymans-audit-by-runtime-verification-eef1e7f8f824","credibility":1,"archive_timestamp":"2026-07-24T23:24:48+00:00"},{"url":"https://tinymanorg.medium.com/tinyman-amm-v2-0-protocol-201e0f32f58d","name":"Tinyman AMM V2.0 Protocol — Tinyman Medium","type":"official","archive_url":"http://web.archive.org/web/20260724232456/https://tinymanorg.medium.com/tinyman-amm-v2-0-protocol-201e0f32f58d","credibility":1,"archive_timestamp":"2026-07-24T23:24:56+00:00"},{"url":"https://tinymanorg.medium.com/tinyman-updates-2022-and-beyond-e2457bed608e","name":"Tinyman Updates, 2022 and Beyond — Tinyman Medium","type":"official","archive_url":"https://web.archive.org/web/20260724232425/https://tinymanorg.medium.com/tinyman-updates-2022-and-beyond-e2457bed608e","credibility":1,"archive_timestamp":"2026-07-24T23:24:25+00:00"},{"url":"https://www.coindesk.com/business/2021/10/07/defi-for-the-small-guy-algorand-based-tinyman-raises-25m-ahead-of-dex-launch","name":"DeFi for the Small Guy: Algorand-Based Tinyman Raises $2.5M Ahead of DEX Launch — CoinDesk","type":"news_article","archive_url":"http://web.archive.org/web/20251106082046/https://www.coindesk.com/business/2021/10/07/defi-for-the-small-guy-algorand-based-tinyman-raises-25m-ahead-of-dex-launch","credibility":1,"archive_timestamp":"2025-11-06T08:20:46+00:00"},{"url":"https://www.prnewswire.com/news-releases/decentralized-trading-platform-tinyman-introduces-version-2-0-and-new-readable-programming-language-tealish-at-algorand-decipher-event-in-dubai-301689634.html","name":"Decentralized Trading Platform Tinyman Introduces Version 2.0 — PR Newswire","type":"official","archive_url":"https://web.archive.org/web/20260725061112/https://www.prnewswire.com/news-releases/decentralized-trading-platform-tinyman-introduces-version-2-0-and-new-readable-programming-language-tealish-at-algorand-decipher-event-in-dubai-301689634.html","credibility":1,"archive_timestamp":"2026-07-25T06:11:12+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-tinyman-hack-january-2022","name":"Explained: The Tinyman Hack (January 2022) — Halborn","type":"research","archive_url":"http://web.archive.org/web/20260516233122/https://www.halborn.com/blog/post/explained-the-tinyman-hack-january-2022","credibility":2,"archive_timestamp":"2026-05-16T23:31:22+00:00"},{"url":"https://www.trmlabs.com/resources/blog/first-defi-liquidity-pool-exploited-in-2022","name":"Tinyman: The First DeFi Exploit of 2022? — TRM Labs","type":"research","archive_url":"http://web.archive.org/web/20260216025320/https://www.trmlabs.com/resources/blog/first-defi-liquidity-pool-exploited-in-2022","credibility":2,"archive_timestamp":"2026-02-16T02:53:20+00:00"},{"url":"https://runtimeverification.com/blog/runtime-verification-audits-tinyman","name":"Runtime Verification Audits Tinyman — Runtime Verification blog","type":"research","archive_url":"http://web.archive.org/web/20260419090529/https://runtimeverification.com/blog/runtime-verification-audits-tinyman","credibility":2,"archive_timestamp":"2026-04-19T09:05:29+00:00"},{"url":"https://runtimeverification.com/blog/runtime-verification-audits-tinyman-amm-v2","name":"Runtime Verification Audits Tinyman AMM V2 — Runtime Verification blog","type":"research","archive_url":"http://web.archive.org/web/20260103041826/https://runtimeverification.com/blog/runtime-verification-audits-tinyman-amm-v2","credibility":2,"archive_timestamp":"2026-01-03T04:18:26+00:00"},{"url":"https://docs.tinyman.org/audits-and-security","name":"Audits and Security — Tinyman Docs","type":"official","archive_url":"http://web.archive.org/web/20260512030618/https://docs.tinyman.org/audits-and-security","credibility":1,"archive_timestamp":"2026-05-12T03:06:18+00:00"},{"url":"https://cryptopotato.com/3-million-lost-as-an-algorand-based-decentralized-trading-platform-exploited/","name":"$3 Million Lost as an Algorand-Based Decentralized Trading Platform Exploited — CryptoPotato","type":"news_article","archive_url":"https://web.archive.org/web/20260725235239/https://cryptopotato.com/3-million-lost-as-an-algorand-based-decentralized-trading-platform-exploited/","credibility":2,"archive_timestamp":"2026-07-25T23:52:39+00:00"},{"url":"https://ambcrypto.com/another-year-another-hack-algorands-defi-platform-tinyman-exploited-for-3m/","name":"Another year, another hack: Algorand's DeFi platform Tinyman exploited for $3m — AMBCrypto","type":"news_article","archive_url":"https://web.archive.org/web/20260724215500/https://ambcrypto.com/another-year-another-hack-algorands-defi-platform-tinyman-exploited-for-3m/","credibility":2,"archive_timestamp":"2026-07-24T21:55:00+00:00"},{"url":"https://beincrypto.com/algorand-based-tinyman-amm-exploited-for-3-million/","name":"Algorand-Based Tinyman AMM Exploited for $3 Million — BeInCrypto","type":"news_article","archive_url":null,"credibility":2,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://blockshake.substack.com/p/tinyman-vulnerability","name":"Tinyman Vulnerability — Blockshake Substack","type":"research","archive_url":"https://web.archive.org/web/20260725192010/https://blockshake.substack.com/p/tinyman-vulnerability","credibility":2,"archive_timestamp":"2026-07-25T19:20:10+00:00"},{"url":"https://coin.fyi/news/algorand/tinyman-re-launch-on-mainnet-and-next-steps-snrs1f","name":"Tinyman: Re-launch on Mainnet and Next Steps — coin.fyi","type":"news_article","archive_url":null,"credibility":3,"archive_error":"error:no-job","archive_status":"unarchivable","archive_timestamp":null}],"source_tags":[],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-5","created_at":"2026-05-30T13:00:19.651529+00:00","updated_at":"2026-08-29T01:33:00.583+00:00"}}