{"investigation":{"slug":"vee-finance","entity_name":"Vee Finance","trust_score":12,"severity_base":null,"score_modifier":0,"confidence":0.88,"status":"published","content_type":"investigation","summary":"Vee Finance is a decentralized lending and leveraged trading protocol deployed on the Avalanche blockchain that launched its mainnet on September 14, 2021. Within one week of launch, on September 20-21, 2021, an attacker exploited price oracle manipulation and a decimal calculation error in the protocol's smart contracts, draining approximately $35 million in ETH and BTC — a hack that ranks among the largest DeFi exploits on Avalanche. The protocol relaunched as V2 with improved security measures including Chainlink oracle integration, but the stolen funds were never recovered, and activity and token value have declined precipitously since the incident.","sections":[{"content":"On September 20-21, 2021, Vee Finance was exploited for approximately $35 million, comprising 8,804.7 ETH (approximately $26 million) and 213.93 BTC (approximately $9 million). The attack occurred less than one week after the protocol's mainnet launch on September 14, 2021, at a time when total value locked had just surpassed $300 million. This was the second major exploit on the Avalanche ecosystem that month, following a $3.2 million hack of Zabu Finance. The attacker used TornadoCash-funded ETH to bridge assets to Avalanche and executed the exploit through repeated leveraged trades using three custom-built contracts. Stolen assets were subsequently bridged back to Ethereum (214 WBTC and 8,804 WETH). The attacker then moved funds into multiple wallets and sent a portion of the bitcoin through CoinJoin, a mixing service. The stablecoin sector of the platform was reportedly not affected. The native VEE token crashed from over $0.25 to approximately $0.085 in the immediate aftermath. Vee Finance filed a police report and the case was later escalated to the FBI due to the magnitude of the loss and alleged links to other attacks. The team offered a $500,000 USD bounty for identification of the attacker. No response was received and the stolen funds were not recovered.","heading":"September 2021 Exploit — $35 Million Drained","sources":[{"url":"https://www.coindesk.com/tech/2021/09/21/vee-finance-hit-for-35m-in-second-major-exploit-on-avalanche","name":"coindesk.com","type":"other","credibility":3},{"url":"https://decrypt.co/81400/avalanche-defi-platform-vee-finance-suffers-35m-hack","name":"decrypt.co","type":"other","credibility":3},{"url":"https://rekt.news/veefinance-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://fullycrypto.com/vee-finance-35-million-hack-passed-to-fbi","name":"fullycrypto.com","type":"other","credibility":3},{"url":"https://cryptoslate.com/another-hit-on-avalanche-as-vee-finance-exploited-for-35-million/","name":"cryptoslate.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Security analysis by SlowMist, Halborn, and ImmunBytes identified two root causes enabling the exploit. First, Vee Finance relied on a single price oracle — the Pangolin DEX liquidity pool — for all leveraged trading price feeds. The protocol only refreshed prices when Pangolin's pool price fluctuated by more than 3%, creating a manipulable threshold. The attacker created artificial trading pairs on Pangolin and executed trades between them to artificially distort token prices. Because Vee Finance referenced only Pangolin for pricing, these manipulated prices bypassed the protocol's slippage protections. Second, a mathematical error in the smart contract failed to properly account for decimal place differences between token pairs when calculating swap amounts. The formula used — amountFromOracle = priceA * swapAmountA / priceB — produced systematically underestimated expected token amounts when Token B had significantly higher decimal precision than Token A. This underestimation allowed transactions that should have been rejected by slippage checks to pass. Additional vulnerabilities included inadequate contract call verification (allowing bypass) and no whitelist restrictions on margin trading pairs, which enabled the creation of arbitrary trading pairs. The attacker also allegedly forged cToken addresses, exploiting mismatches between token addresses used in price queries and those used in underlying asset retrieval.","heading":"Technical Vulnerabilities — Oracle Manipulation and Decimal Error","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-vee-finance-hack-september-2021","name":"halborn.com","type":"other","credibility":3},{"url":"https://slowmist.medium.com/the-main-cause-of-vee-finance-attack-52fc8e5fb13d","name":"slowmist.medium.com","type":"other","credibility":3},{"url":"https://immunebytes.com/blog/vee-finance-exploit-sep-21-2021-detailed-analysis/","name":"immunebytes.com","type":"other","credibility":3},{"url":"https://www.quadrigainitiative.com/casestudy/veefinancepriceoraclemanipulation.php","name":"quadrigainitiative.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Vee Finance underwent security audits by both SlowMist (completed September 9, 2021 — five days before the mainnet launch) and CertiK (delivered May 26, 2021). Despite passing these audits, multiple security firms noted that the protocol did not adequately address oracle-related recommendations raised during the review process. According to analysis by Halborn, SlowMist's audit raised multiple concerns about the protocol's use of price oracles; Vee Finance allegedly did not implement the recommended fixes before going live. Rekt.news noted that both Slowmist and CertiK had identified concerns that were not acted upon. The CertiK security leaderboard lists Vee Finance as a high-risk project. The failure to remediate known audit findings before launch is considered a critical governance failure and a direct contributing cause of the exploit.","heading":"Pre-Launch Audit Warnings Ignored","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-vee-finance-hack-september-2021","name":"halborn.com","type":"other","credibility":3},{"url":"https://rekt.news/veefinance-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://www.certik.com/projects/veefinance","name":"certik.com","type":"other","credibility":3},{"url":"https://github.com/VeeFinance/audit/blob/main/2021-9-09_SlowMist%20Security%20Audit%20Vee%20Finance/Smart%20Contract%20Security%20Audit%20Report%20-%20Vee%20Finance.pdf","name":"github.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Vee Finance's core product is a leveraged trading facility offering up to 3x leverage on crypto positions, allowing users to go long or short. The leveraged trading module was specifically the attack vector through which the September 2021 exploit was executed. Leveraged trading protocols by design amplify both potential gains and potential losses for users, and carry elevated smart contract risk because they require complex interactions between price oracles, collateral valuations, and position management. The protocol's reliance on a single DEX pool as its price oracle for the leveraged trading system — rather than a time-weighted average price or multi-source aggregation — made it uniquely susceptible to spot manipulation. The leveraged trading function was suspended in the V2 relaunch pending further security review.","heading":"Leveraged Trading Product — Inherent Risk Amplification","sources":[{"url":"https://veefi.medium.com/leveraging-defi-market-with-leveraged-transactions-7a95c4c0b9e4","name":"veefi.medium.com","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-vee-finance-hack-september-2021","name":"halborn.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/defi-platform-vee-finance-exploited-for-35m-on-avalanche-blockchain","name":"cointelegraph.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the exploit, Vee Finance suspended all smart contracts, filed a police report, and published a series of compensation and recovery plans. The team established a compensation pool from which affected users could withdraw pro-rata shares in AVAX, WBTC, WETH, LINK, and USDT. The team committed to allocating 100% of platform revenue toward debt repayment. As of December 28, 2021, accumulated platform revenue equivalent to 24,475 USDT had been deposited into the compensation pool — a small fraction of the $35 million lost. The CEO allegedly personally funded repayments of QI, PNG, and XAVA assets lost in the hack. Vee Finance subsequently relaunched as V2 with security improvements including: integration of Chainlink Price Feeds as the oracle for the money market, suspension of the leveraged trading (Trade) function pending further review, a new SlowMist audit of V2 code, and on-chain and off-chain activity monitoring. Despite these stated improvements, the protocol's total value locked and user base declined sharply after the incident and has not recovered.","heading":"Post-Exploit Response and V2 Relaunch","sources":[{"url":"https://veefi.medium.com/vee-finance-restart-plan-sept-28-314cb2dd734d","name":"veefi.medium.com","type":"other","credibility":3},{"url":"https://veefi.medium.com/latest-update-october-2-a547aa853744","name":"veefi.medium.com","type":"other","credibility":3},{"url":"https://veefi.medium.com/5-ways-how-vee-finance-v2-makes-funds-secure-f17caf306607","name":"veefi.medium.com","type":"other","credibility":3},{"url":"https://veefi.medium.com/vee-finance-integrates-chainlink-price-feeds-to-secure-vee-finance-money-market-335b4bed261a","name":"veefi.medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The native VEE token suffered severe price decline following the September 2021 exploit. In the immediate aftermath, VEE dropped from over $0.25 to approximately $0.085 before partially recovering to around $0.11. As of 2025, VEE is trading at approximately $0.00001 USD, representing a decline of over 99.99% from its pre-hack levels. The 24-hour trading volume is minimal (reported as approximately $57 at some data points). The token's CoinMarketCap ranking has fallen to approximately #5599 with effectively no reported market capitalization from circulating supply. The extremely low liquidity and near-zero volume suggest the token is largely illiquid and carries substantial risk of total loss for any holder.","heading":"VEE Token — Near-Total Value Collapse","sources":[{"url":"https://coinmarketcap.com/currencies/vee-finance/","name":"coinmarketcap.com","type":"other","credibility":3},{"url":"https://www.coingecko.com/en/coins/vee-finance","name":"coingecko.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/tech/2021/09/21/vee-finance-hit-for-35m-in-second-major-exploit-on-avalanche","name":"coindesk.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Rekt.news noted the presence of Vee Finance in alleged 'pump groups' prior to the hack as a reputational concern, though this claim is sourced only from Rekt.news commentary and should be treated as low confidence without corroborating evidence. The protocol launched its mainnet on September 14, 2021 and was exploited within seven days — a pattern consistent with protocols that rush to production without adequately implementing security audit recommendations. Vee Finance is flagged by AVOID.NET's ZachXBT-sourced intelligence. No regulatory actions by the SEC, CFTC, or other government bodies have been identified in connection with Vee Finance. The team's identity has not been publicly confirmed with verifiable real-world identities in available sources.","heading":"Context and Reputation Flags","sources":[{"url":"https://rekt.news/veefinance-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://decrypt.co/81400/avalanche-defi-platform-vee-finance-suffers-35m-hack","name":"decrypt.co","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2021-05-26","event":"CertiK completes smart contract security audit of Vee Finance. CertiK lists the project as high-risk.","source":""},{"date":"2021-09-09","event":"SlowMist completes pre-launch security audit of Vee Finance smart contracts, identifying oracle-related concerns.","source":""},{"date":"2021-09-14","event":"Vee Finance mainnet launches on Avalanche. Total value locked surpasses $300 million within days.","source":""},{"date":"2021-09-20","event":"Vee Finance team identifies abnormal transfers. Exploit begins; attacker drains 8,804.7 ETH (~$26M) and 213.93 BTC (~$9M) via oracle manipulation and decimal calculation error.","source":""},{"date":"2021-09-21","event":"Exploit confirmed publicly. VEE token crashes from $0.25 to $0.085. Protocol suspends all smart contracts. SlowMist publishes technical post-mortem. Rekt.news ranks exploit #7 on its DeFi leaderboard.","source":""},{"date":"2021-09-21","event":"Vee Finance files police report and offers $500,000 USD bounty for attacker identification. Attacker begins moving funds through CoinJoin mixer.","source":""},{"date":"2021-09-24","event":"Vee Finance publishes initial compensation plan, establishing a pool for affected users payable in AVAX, WBTC, WETH, LINK, and USDT.","source":""},{"date":"2021-09-25","event":"Case escalated to the FBI due to scale of loss and alleged links to other attacks.","source":""},{"date":"2021-09-28","event":"Vee Finance publishes formal restart plan for V2 with security improvements.","source":""},{"date":"2021-10-02","event":"Vee Finance publishes updated compensation pool and relaunch plan details. Compensation pool opens.","source":""},{"date":"2021-10-04","event":"SlowMist completes Phase 2 security audit of Vee Finance V2 contracts.","source":""},{"date":"2021-12-28","event":"Vee Finance reports 24,475 USDT deposited into compensation pool from platform revenue — a small fraction of the $35M lost.","source":""},{"date":"2022","event":"V2 relaunches with Chainlink oracle integration for money market; leveraged trading function remains suspended.","source":"","date_original":"2022-01-01"},{"date":"2025","event":"VEE token trading near $0.00001 USD with 24-hour volume below $100, representing over 99.99% decline from pre-hack levels.","source":"","date_original":"2025-01-01"}],"sources_used":[{"url":"https://www.coindesk.com/tech/2021/09/21/vee-finance-hit-for-35m-in-second-major-exploit-on-avalanche","name":"coindesk.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://decrypt.co/81400/avalanche-defi-platform-vee-finance-suffers-35m-hack","name":"decrypt.co","type":"other","archive_url":"http://web.archive.org/web/20260725165823/https://decrypt.co/81400/avalanche-defi-platform-vee-finance-suffers-35m-hack","credibility":3,"archive_timestamp":"2026-07-25T16:58:23+00:00"},{"url":"https://rekt.news/veefinance-rekt","name":"rekt.news","type":"other","archive_url":"http://web.archive.org/web/20260118083910/https://rekt.news/veefinance-rekt","credibility":3,"archive_timestamp":"2026-01-18T08:39:10+00:00"},{"url":"https://fullycrypto.com/vee-finance-35-million-hack-passed-to-fbi","name":"fullycrypto.com","type":"other","archive_url":"http://web.archive.org/web/20260123015506/https://fullycrypto.com/vee-finance-35-million-hack-passed-to-fbi","credibility":3,"archive_timestamp":"2026-01-23T01:55:06+00:00"},{"url":"https://cryptoslate.com/another-hit-on-avalanche-as-vee-finance-exploited-for-35-million/","name":"cryptoslate.com","type":"other","archive_url":"http://web.archive.org/web/20251110074835/https://cryptoslate.com/another-hit-on-avalanche-as-vee-finance-exploited-for-35-million/","credibility":3,"archive_timestamp":"2025-11-10T07:48:35+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-vee-finance-hack-september-2021","name":"halborn.com","type":"other","archive_url":"http://web.archive.org/web/20260605232956/https://www.halborn.com/blog/post/explained-the-vee-finance-hack-september-2021","credibility":3,"archive_timestamp":"2026-06-05T23:29:56+00:00"},{"url":"https://slowmist.medium.com/the-main-cause-of-vee-finance-attack-52fc8e5fb13d","name":"slowmist.medium.com","type":"other","archive_url":"http://web.archive.org/web/20250906072823/https://slowmist.medium.com/the-main-cause-of-vee-finance-attack-52fc8e5fb13d","credibility":3,"archive_timestamp":"2025-09-06T07:28:23+00:00"},{"url":"https://immunebytes.com/blog/vee-finance-exploit-sep-21-2021-detailed-analysis/","name":"immunebytes.com","type":"other","archive_url":"http://web.archive.org/web/20260114205641/https://immunebytes.com/blog/vee-finance-exploit-sep-21-2021-detailed-analysis/","credibility":3,"archive_timestamp":"2026-01-14T20:56:41+00:00"},{"url":"https://www.quadrigainitiative.com/casestudy/veefinancepriceoraclemanipulation.php","name":"quadrigainitiative.com","type":"other","archive_url":"http://web.archive.org/web/20260511082328/https://quadrigainitiative.com/casestudy/veefinancepriceoraclemanipulation.php","credibility":3,"archive_timestamp":"2026-05-11T08:23:28+00:00"},{"url":"https://www.certik.com/projects/veefinance","name":"certik.com","type":"other","archive_url":"https://web.archive.org/web/20260830092145/https://skynet.certik.com/projects/veefinance","credibility":3,"archive_timestamp":"2026-08-30T09:21:45+00:00"},{"url":"https://github.com/VeeFinance/audit/blob/main/2021-9-09_SlowMist%20Security%20Audit%20Vee%20Finance/Smart%20Contract%20Security%20Audit%20Report%20-%20Vee%20Finance.pdf","name":"github.com","type":"other","archive_url":"https://web.archive.org/web/20260901100231/https://github.com/VeeFinance/audit/blob/main/2021-9-09_SlowMist%20Security%20Audit%20Vee%20Finance/Smart%20Contract%20Security%20Audit%20Report%20-%20Vee%20Finance.pdf","credibility":3,"archive_timestamp":"2026-09-01T10:02:31+00:00"},{"url":"https://veefi.medium.com/leveraging-defi-market-with-leveraged-transactions-7a95c4c0b9e4","name":"veefi.medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://cointelegraph.com/news/defi-platform-vee-finance-exploited-for-35m-on-avalanche-blockchain","name":"cointelegraph.com","type":"other","archive_url":"http://web.archive.org/web/20260830125227/https://cointelegraph.com/news/defi-platform-vee-finance-exploited-for-35m-on-avalanche-blockchain","credibility":3,"archive_timestamp":"2026-08-30T12:52:27+00:00"},{"url":"https://veefi.medium.com/vee-finance-restart-plan-sept-28-314cb2dd734d","name":"veefi.medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://veefi.medium.com/latest-update-october-2-a547aa853744","name":"veefi.medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://veefi.medium.com/5-ways-how-vee-finance-v2-makes-funds-secure-f17caf306607","name":"veefi.medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://veefi.medium.com/vee-finance-integrates-chainlink-price-feeds-to-secure-vee-finance-money-market-335b4bed261a","name":"veefi.medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://coinmarketcap.com/currencies/vee-finance/","name":"coinmarketcap.com","type":"other","archive_url":"http://web.archive.org/web/20260312141636/https://coinmarketcap.com/currencies/vee-finance/","credibility":3,"archive_timestamp":"2026-03-12T14:16:36+00:00"},{"url":"https://www.coingecko.com/en/coins/vee-finance","name":"coingecko.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:54.102632+00:00","updated_at":"2026-09-01T10:06:41.733336+00:00"}}