{"investigation":{"slug":"uwulend","entity_name":"UwuLend","trust_score":8,"severity_base":null,"score_modifier":0,"confidence":0.91,"status":"published","content_type":"investigation","summary":"UwU Lend is an Ethereum-based DeFi lending protocol forked from Aave, founded in September 2022 by Michael Patryn (pseudonym 0xSifu), co-founder of the collapsed Canadian crypto exchange QuadrigaCX. In June 2024, the protocol suffered two successive exploits totaling approximately $23 million — a $19.3 million oracle manipulation attack on June 10 followed by a $3.7 million secondary drain on June 13 by the same attacker — rendering it one of the largest DeFi hacks of 2024. The protocol's association with a founder carrying prior criminal convictions and a history of involvement in failed or scandal-ridden crypto ventures constitutes a persistent and material reputational and risk concern.","sections":[{"content":"UwU Lend is a decentralized lending and borrowing protocol on the Ethereum mainnet, launched on September 21, 2022. It is a direct fork of the Aave v2 codebase, allowing users to deposit crypto assets to earn yield and borrow against collateral, including the algorithmic stablecoin Magic Internet Money (MIM). At its peak, the protocol held approximately $91 million in Total Value Locked (TVL), according to DefiLlama data cited by multiple outlets. UwU Lend distributes protocol fees to liquidity providers and operates through standard ERC-20 lending pool mechanics inherited from Aave. The protocol had undergone a security audit by PeckShield prior to launch, which characterized it as well-designed with no high-severity issues — an assessment that would later prove incomplete given the June 2024 oracle exploit.","heading":"Protocol Overview","sources":[{"url":"https://www.coindesk.com/business/2022/09/26/founder-of-failed-crypto-exchange-quadrigacx-starts-defi-protocol-uwu-lend","name":"coindesk.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/defi-lending-protocol-created-by-ex-quadrigacx-co-founder-surpassed-50m-in-tvl","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://www.quillaudits.com/blog/hack-analysis/uwu-lend-hack","name":"quillaudits.com","type":"other","credibility":3}],"severity":"medium"},{"content":"UwU Lend was founded by Michael Patryn, who operates under the pseudonym '0xSifu' or 'Sifu' in the DeFi space. Patryn was born Omar Dhanani, legally changing his name to Omar Patryn in 2003 and then to Michael Patryn in 2008. As Omar Dhanani, he was a member of Shadowcrew.com, an online marketplace that trafficked in stolen credit card numbers and identities. He pleaded guilty in 2005 to one count of conspiracy to transfer identification documents and was sentenced to 18 months in U.S. federal prison. He subsequently pleaded guilty to separate charges of burglary, grand larceny, and computer fraud in 2007. After serving his sentence he was deported to Canada, where he co-founded the crypto exchange QuadrigaCX alongside Gerald Cotten. Patryn publicly denied that the identities Michael Patryn and Omar Dhanani are the same person; however, an investigation by The Globe and Mail confirmed the name changes with Canadian government records.","heading":"Founder Background: Michael Patryn (0xSifu)","sources":[{"url":"https://www.theglobeandmail.com/business/article-quadriga-co-founder-served-time-in-us-for-role-in-identity-theft/","name":"theglobeandmail.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/quadrigacx-co-founder-michael-patryn-is-actually-convicted-criminal-omar-dhanani-report","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://en.wikipedia.org/wiki/Michael_Patryn","name":"en.wikipedia.org","type":"other","credibility":3},{"url":"https://news.bitcoin.com/quadrigacx-co-founder-michael-patryn-is-actually-convicted-fraudster-omar-dhanani/","name":"news.bitcoin.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Michael Patryn co-founded QuadrigaCX with Gerald Cotten, which operated as Canada's largest cryptocurrency exchange before its collapse in early 2019 following the reported death of Cotten. The Ontario Securities Commission (OSC) issued an investigative report in June 2020 concluding that QuadrigaCX was a Ponzi scheme operated by Cotten, who credited himself with fictitious balances and traded against unsuspecting clients. Over 76,000 customers were owed a combined $215 million, with at least $169 million in confirmed losses. The OSC's report notes that Patryn left the exchange in 2016 and that a majority of the lost funds were deposited after his departure; the report did not implicate Patryn in Cotten's specific fraudulent trading activities. Nevertheless, Patryn's co-founding role in a platform later deemed a Ponzi scheme remains a significant element of his background that the DeFi community has consistently cited when evaluating his subsequent ventures.","heading":"QuadrigaCX Connection","sources":[{"url":"https://www.osc.gov.on.ca/quadrigacxreport/","name":"osc.gov.on.ca","type":"other","credibility":3},{"url":"https://www.cbc.ca/news/business/osc-quadriga-gerald-cotten-1.5607990","name":"cbc.ca","type":"other","credibility":3},{"url":"https://www.coindesk.com/markets/2020/06/11/quadriga-was-a-ponzi-scheme-ontario-securities-regulator-says","name":"coindesk.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Prior to founding UwU Lend, Patryn served as the pseudonymous treasury manager '0xSifu' for Wonderland DAO, a DeFi protocol that at its peak held over $1 billion in assets. On January 27, 2022, blockchain investigator ZachXBT publicly revealed that 0xSifu was Michael Patryn, the convicted fraudster and QuadrigaCX co-founder. The disclosure triggered a community crisis: a DAO vote resulted in 87.56% of participating tokens voting to remove Sifu from his treasury role. Additionally, approximately 4,250 TIME tokens valued at roughly $8.4 million were transferred from the Wonderland treasury to a wallet associated with Sifu shortly before the revelation, raising allegations of self-dealing, though no legal charges were filed in connection with this transfer. Following his removal, Patryn transferred millions of dollars' worth of ETH through Tornado Cash, which he claimed was his own capital. These events materially damaged the value of Wonderland (TIME), Popsicle Finance, and Abracadabra tokens. Wonderland's founder, Daniele Sestagalli, stated he had known of Sifu's identity for approximately a month before the public disclosure but chose to continue working with him.","heading":"Wonderland DAO Treasury Scandal (2022)","sources":[{"url":"https://cryptobriefing.com/wonderland-treasury-manager-outed-quadrigacx-cofounder/","name":"cryptobriefing.com","type":"other","credibility":3},{"url":"https://cryptoslate.com/scandal-at-wonderland-time-as-treasury-head-uncovered-as-quadrigacx-co-founder/","name":"cryptoslate.com","type":"other","credibility":3},{"url":"https://rekt.news/sifu-scandal","name":"rekt.news","type":"other","credibility":3},{"url":"https://www.cryptotimes.io/2022/01/31/wonderland-dao-voted-out-treasury-manager-sifu/","name":"cryptotimes.io","type":"other","credibility":3}],"severity":"medium"},{"content":"On June 10, 2024, UwU Lend was exploited for approximately $19.3 million in a sophisticated oracle manipulation attack. The attacker's address (0x841ddf093f5188989fa1524e7b893de64b421f47) initially funded operations with 0.98 ETH sourced from Tornado Cash. The attack exploited a critical flaw in the protocol's price oracle for the Ethena Staked USDe (sUSDe) token: UwU Lend calculated the sUSDe price using the median of 11 price sources, five of which drew from Curve Finance spot price feeds using the `get_p()` function — a mechanism Curve Finance itself explicitly advises against using as an oracle due to its susceptibility to within-block manipulation. Using a 40,000 ETH flash loan, the attacker executed three transactions within approximately six minutes: first suppressing the sUSDe spot price on Curve pools by roughly 4% (to approximately $0.99), then borrowing a disproportionate quantity of sUSDe and other assets using manipulated collateral valuations, and finally reversing the price manipulation to approximately $1.03 to trigger profitable liquidations. Assets drained included ETH, crvUSD, bLUSD, and USDC. Security firm Cyvers detected the breach when losses reached $14 million; the protocol was paused within minutes of the detection. The attack was identified and analyzed by SlowMist and multiple other blockchain security firms.","heading":"June 10, 2024 Exploit — Oracle Manipulation ($19.3M)","sources":[{"url":"https://slowmist.medium.com/analysis-of-the-uwu-lend-hack-9502b2c06dbe","name":"slowmist.medium.com","type":"other","credibility":3},{"url":"https://www.quillaudits.com/blog/hack-analysis/uwu-lend-hack","name":"quillaudits.com","type":"other","credibility":3},{"url":"https://cyvers.ai/blog/uwu-lend-23m-exploit-oracle-vulnerabilities-exposed","name":"cyvers.ai","type":"other","credibility":3},{"url":"https://cryptobriefing.com/uwu-lend-exploit/","name":"cryptobriefing.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On June 13, 2024, the same attacker returned to UwU Lend and drained an additional $3.7 million — just three days after the protocol had announced it had identified and fixed the original vulnerability, and while it was actively reimbursing victims of the first hack (approximately $9.7 million had been repaid by the time of the second attack). The second exploit did not involve a new oracle manipulation. Instead, the attacker leveraged uUSDE tokens accumulated during the first hack; because UwU Lend still recognized these as valid collateral despite the protocol pause, the attacker was able to drain liquidity pools including uDAI, uWETH, uLUSD, uFRAX, uCRVUSD, and uUSDT. B.Protocol CEO Yaron Velner stated: 'The operation today did not entail any manipulation. Just a malicious intent, and erroneous configuration on UwU side.' All stolen assets were converted to ETH and held at the attacker's address. The second attack was reported by The Block, Unchained, and DL News.","heading":"June 13, 2024 Exploit — Secondary Drain ($3.7M)","sources":[{"url":"https://www.dlnews.com/articles/defi/0xsifu-protocol-uwu-lend-hacked-again-amid-payback-plan/","name":"dlnews.com","type":"other","credibility":3},{"url":"https://unchainedcrypto.com/uwu-lend-hacker-steals-another-3-7-million-from-protocol/","name":"unchainedcrypto.com","type":"other","credibility":3},{"url":"https://cryptobriefing.com/uwu-lend-second-hack-update/","name":"cryptobriefing.com","type":"other","credibility":3},{"url":"https://cryptonews.com/news/breaking-uwu-lend-suffers-another-hack-losing-3-7m/","name":"cryptonews.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the first exploit, 0xSifu sent an on-chain message to the attacker offering a 20% white-hat bounty (approximately $4 million) to return 80% of the stolen assets, a higher-than-standard bounty relative to the typical 10% industry benchmark. The protocol also committed to reimbursing all victims from its own reserves, and by June 13 had repaid approximately $9.7 million. The second hack disrupted these repayment efforts. The protocol stated it had conducted additional security reviews between the two attacks, but the secondary drain revealed that the configuration of uUSDE as recognized collateral had not been addressed. As of June 2024, the combined losses from both attacks stood at approximately $23 million. The attacker did not respond to the bounty offer and did not return any funds. The protocol was paused but not permanently shut down following the attacks.","heading":"Protocol Response and Reimbursement","sources":[{"url":"https://unchainedcrypto.com/0xsifu-offers-20-bounty-to-hackers-after-19-million-uwu-lend-exploit/","name":"unchainedcrypto.com","type":"other","credibility":3},{"url":"https://www.dlnews.com/articles/defi/uwu-founder-offers-bounty-to-settle-flash-loan-exploit/","name":"dlnews.com","type":"other","credibility":3},{"url":"https://cryptonews.com/news/uwu-lend-reacts-to-23-million-hack-pauses-protocol-and-negotiates-with-hacker/","name":"cryptonews.com","type":"other","credibility":3},{"url":"https://therecord.media/uwu-lend-reimbursing-crypto-theft-customers","name":"therecord.media","type":"other","credibility":3}],"severity":"medium"},{"content":"UwU Lend had received a security audit from PeckShield prior to launch, which reportedly did not identify high-severity issues and described the protocol as 'well-designed and engineered.' The June 2024 oracle manipulation exploit revealed a design flaw that went undetected: the use of Curve Finance spot price feeds (`get_p()`) as oracle sources, a pattern that Curve Finance's own documentation explicitly warns against. The exploit demonstrated that even a formally audited DeFi fork can contain critical vulnerabilities when the audit scope does not include adversarial oracle stress-testing or when developers adopt implementation patterns that deviate from best practices documented by the underlying infrastructure. The secondary attack further revealed that the initial patch was insufficient, leaving uUSDE token positions in a state that could be exploited without any additional oracle manipulation.","heading":"Security Audit Failures","sources":[{"url":"https://www.quillaudits.com/blog/hack-analysis/uwu-lend-hack","name":"quillaudits.com","type":"other","credibility":3},{"url":"https://slowmist.medium.com/analysis-of-the-uwu-lend-hack-9502b2c06dbe","name":"slowmist.medium.com","type":"other","credibility":3},{"url":"https://cryptobriefing.com/uwu-lend-second-hack-update/","name":"cryptobriefing.com","type":"other","credibility":3}],"severity":"medium"},{"content":"UwU Lend represents at least the third major crypto venture associated with Michael Patryn following QuadrigaCX (collapsed 2019, deemed a Ponzi scheme by the OSC) and Wonderland DAO (collapsed following scandal in January 2022). Each venture attracted substantial user capital before encountering serious failures. The pattern of a pseudonymous founder with a verified criminal history for financial fraud repeatedly launching DeFi products that attract tens of millions in user deposits constitutes a structural governance risk that no technical audit can fully address. ZachXBT's January 2022 investigation into Sifu's identity at Wonderland is widely cited as the foundational disclosure connecting these identities. The use of Tornado Cash to obfuscate fund flows is an additional risk signal documented across multiple incidents involving Patryn-linked wallets.","heading":"Reputational Risk and Founder History Pattern","sources":[{"url":"https://www.coindesk.com/tech/2022/01/27/how-did-a-former-quadriga-exec-end-up-running-a-defi-protocol-wonderland-founder-explains","name":"coindesk.com","type":"other","credibility":3},{"url":"https://rekt.news/sifu-scandal","name":"rekt.news","type":"other","credibility":3},{"url":"https://protos.com/patryn-wonderland-sifu-quadriga-founder-crypto-treasury/","name":"protos.com","type":"other","credibility":3},{"url":"https://info.arkm.com/research/visualize-sifu-defi","name":"info.arkm.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2005","event":"Omar Dhanani (later Michael Patryn) pleads guilty to conspiracy to transfer identification documents in connection with the Shadowcrew online fraud marketplace; sentenced to 18 months in U.S. federal prison.","source":"","date_original":"2005-01-01"},{"date":"2007","event":"Dhanani pleads guilty to separate charges of burglary, grand larceny, and computer fraud. Subsequently deported to Canada after serving his sentence.","source":"","date_original":"2007-01-01"},{"date":"2013","event":"Michael Patryn co-founds QuadrigaCX with Gerald Cotten. The exchange would grow to become Canada's largest crypto exchange.","source":"","date_original":"2013-01-01"},{"date":"2016","event":"Patryn departs QuadrigaCX.","source":"","date_original":"2016-01-01"},{"date":"2019","event":"QuadrigaCX collapses following the reported death of CEO Gerald Cotten; over 76,000 users lose access to approximately $169 million in assets.","source":"","date_original":"2019-01-01"},{"date":"2020-06-11","event":"Ontario Securities Commission publishes investigative report concluding QuadrigaCX operated as a Ponzi scheme under Cotten's direction.","source":""},{"date":"2022-01-27","event":"Blockchain investigator ZachXBT reveals that Wonderland DAO treasury manager '0xSifu' is Michael Patryn, co-founder of QuadrigaCX. The disclosure triggers a community crisis and a DAO vote to remove Sifu.","source":""},{"date":"2022-01-31","event":"Wonderland DAO community vote results in 87.56% of tokens voting to remove 0xSifu as treasury manager.","source":""},{"date":"2022-02-18","event":"Patryn launches the SIFU token on Uniswap V3.","source":""},{"date":"2022-09-21","event":"UwU Lend launches on Ethereum mainnet as an Aave fork, quickly attracting $57.5 million in TVL.","source":""},{"date":"2024-06-10","event":"UwU Lend exploited for approximately $19.3 million via oracle manipulation of the sUSDe price feed using Curve Finance spot price sources. Attacker address: 0x841ddf093f5188989fa1524e7b893de64b421f47. Protocol paused within minutes. 0xSifu offers 20% white-hat bounty.","source":""},{"date":"2024-06-13","event":"Same attacker returns and drains an additional $3.7 million from UwU Lend using uUSDE collateral from the first attack, while the protocol was mid-reimbursement of first hack victims (~$9.7M repaid). Combined losses reach approximately $23 million.","source":""}],"sources_used":[{"url":"https://www.coindesk.com/business/2022/09/26/founder-of-failed-crypto-exchange-quadrigacx-starts-defi-protocol-uwu-lend","name":"coindesk.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/defi-lending-protocol-created-by-ex-quadrigacx-co-founder-surpassed-50m-in-tvl","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://www.quillaudits.com/blog/hack-analysis/uwu-lend-hack","name":"quillaudits.com","type":"other","credibility":3},{"url":"https://www.theglobeandmail.com/business/article-quadriga-co-founder-served-time-in-us-for-role-in-identity-theft/","name":"theglobeandmail.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/quadrigacx-co-founder-michael-patryn-is-actually-convicted-criminal-omar-dhanani-report","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://en.wikipedia.org/wiki/Michael_Patryn","name":"en.wikipedia.org","type":"other","credibility":3},{"url":"https://news.bitcoin.com/quadrigacx-co-founder-michael-patryn-is-actually-convicted-fraudster-omar-dhanani/","name":"news.bitcoin.com","type":"other","credibility":3},{"url":"https://www.osc.gov.on.ca/quadrigacxreport/","name":"osc.gov.on.ca","type":"other","credibility":3},{"url":"https://www.cbc.ca/news/business/osc-quadriga-gerald-cotten-1.5607990","name":"cbc.ca","type":"other","credibility":3},{"url":"https://www.coindesk.com/markets/2020/06/11/quadriga-was-a-ponzi-scheme-ontario-securities-regulator-says","name":"coindesk.com","type":"other","credibility":3},{"url":"https://cryptobriefing.com/wonderland-treasury-manager-outed-quadrigacx-cofounder/","name":"cryptobriefing.com","type":"other","credibility":3},{"url":"https://cryptoslate.com/scandal-at-wonderland-time-as-treasury-head-uncovered-as-quadrigacx-co-founder/","name":"cryptoslate.com","type":"other","credibility":3},{"url":"https://rekt.news/sifu-scandal","name":"rekt.news","type":"other","credibility":3},{"url":"https://www.cryptotimes.io/2022/01/31/wonderland-dao-voted-out-treasury-manager-sifu/","name":"cryptotimes.io","type":"other","credibility":3},{"url":"https://slowmist.medium.com/analysis-of-the-uwu-lend-hack-9502b2c06dbe","name":"slowmist.medium.com","type":"other","credibility":3},{"url":"https://cyvers.ai/blog/uwu-lend-23m-exploit-oracle-vulnerabilities-exposed","name":"cyvers.ai","type":"other","credibility":3},{"url":"https://cryptobriefing.com/uwu-lend-exploit/","name":"cryptobriefing.com","type":"other","credibility":3},{"url":"https://www.dlnews.com/articles/defi/0xsifu-protocol-uwu-lend-hacked-again-amid-payback-plan/","name":"dlnews.com","type":"other","credibility":3},{"url":"https://unchainedcrypto.com/uwu-lend-hacker-steals-another-3-7-million-from-protocol/","name":"unchainedcrypto.com","type":"other","credibility":3},{"url":"https://cryptobriefing.com/uwu-lend-second-hack-update/","name":"cryptobriefing.com","type":"other","credibility":3},{"url":"https://cryptonews.com/news/breaking-uwu-lend-suffers-another-hack-losing-3-7m/","name":"cryptonews.com","type":"other","credibility":3},{"url":"https://unchainedcrypto.com/0xsifu-offers-20-bounty-to-hackers-after-19-million-uwu-lend-exploit/","name":"unchainedcrypto.com","type":"other","credibility":3},{"url":"https://www.dlnews.com/articles/defi/uwu-founder-offers-bounty-to-settle-flash-loan-exploit/","name":"dlnews.com","type":"other","credibility":3},{"url":"https://cryptonews.com/news/uwu-lend-reacts-to-23-million-hack-pauses-protocol-and-negotiates-with-hacker/","name":"cryptonews.com","type":"other","credibility":3},{"url":"https://therecord.media/uwu-lend-reimbursing-crypto-theft-customers","name":"therecord.media","type":"other","credibility":3},{"url":"https://www.coindesk.com/tech/2022/01/27/how-did-a-former-quadriga-exec-end-up-running-a-defi-protocol-wonderland-founder-explains","name":"coindesk.com","type":"other","credibility":3},{"url":"https://protos.com/patryn-wonderland-sifu-quadriga-founder-crypto-treasury/","name":"protos.com","type":"other","credibility":3},{"url":"https://info.arkm.com/research/visualize-sifu-defi","name":"info.arkm.com","type":"other","credibility":3}],"source_tags":[],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-30T19:10:44.706701+00:00","updated_at":"2026-08-29T01:34:36.502+00:00"}}