{"investigation":{"slug":"veil-cash","entity_name":"Veil Cash","trust_score":38,"severity_base":null,"score_modifier":-10,"confidence":0.72,"status":"published","content_type":"investigation","summary":"Veil Cash is a zero-knowledge privacy protocol deployed on Coinbase's Base L2 network, enabling anonymous ETH and USDC transfers via zk-SNARK proofs and a UTXO model. In February 2026 the protocol's legacy pools were exploited due to an incomplete Groth16 trusted-setup ceremony, resulting in 2.9 ETH being drained before funds were returned by the exploiter. The incident attracted industry attention because the same misconfiguration pattern was subsequently replicated in a larger $2.26 million exploit of FoomCash, raising broader questions about cryptographic setup hygiene across ZK DeFi protocols.","sections":[{"content":"Veil Cash is a non-custodial privacy protocol operating on the Base L2 blockchain. It allows users to deposit ETH or USDC into shielded pools and withdraw to different addresses without creating a traceable on-chain link. The protocol uses a UTXO model secured by Groth16 zero-knowledge proofs and Poseidon hashing. Shielded balances are stored as encrypted UTXOs on-chain, readable only by the owner. Transaction relay infrastructure means depositors do not need to hold gas tokens to transact privately. The protocol charges a 0.5% fee on deposits, with revenue eventually distributed to stakers of the native VEIL token. A token-gating mechanism requires users of verified pools to hold at least 2,500 VEIL tokens. As of May 2026 the protocol's total value locked stood at approximately $20,736 according to DefiLlama, placing it 13th in the privacy protocol category. The project is distinct from the earlier Veil (veil-project.com), a standalone privacy coin launched in 2019.","heading":"Protocol Overview","sources":[{"url":"https://defillama.com/protocol/veil-cash","name":"defillama.com","type":"other","credibility":3},{"url":"https://docs.veil.cash/","name":"docs.veil.cash","type":"other","credibility":3},{"url":"https://www.bankless.com/read/getting-started-with-veils-privacy-protocol-on-base","name":"bankless.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On approximately February 21, 2026, an attacker exploited a critical cryptographic misconfiguration in Veil Cash's legacy privacy pool on Base. The Groth16 zk-SNARK verifier contract at address 0x1E65C075989189E607ddaFA30fa1a0001c376cfd had its delta and gamma parameters set identically to the BN254 G2 generator — the default placeholder value produced by the snarkjs Phase 2 toolchain — because the CLI command required to generate distinct random values for these constants was never executed before deployment. This broke the mathematical soundness guarantee of the Groth16 pairing check: with delta equal to gamma, the pairing equation reduces to a tautology, allowing any party to fabricate a valid proof without possessing a legitimate witness or having deposited funds. The attacker contract at 0x5F68aD46F500949FA7E94971441F279A85cB3354 executed 29 sequential fraudulent withdrawals in a single transaction on Base block 42,410,815, identified by the exploit transaction 0x5ff6dbc33e77fab8dc086bb9ea3c88f1ba81df198d24ec9fc0c5b50fb1a4a17d, using nullifier hashes that followed the pattern 0xdead0000 through 0xdead001c. The attacker drained 2.9 ETH from the 0.1 ETH denomination pool at contract 0xD3560eF60Dd06E27b699372c3da1b741c80B7D90, with recipient address 0x49A7CA88094B59b15EaA28C8c6d9BFAb78d5F903. Security monitoring firm DefimonAlerts (Decurity) intervened and rescued the remaining pool funds. The exploiter subsequently returned all drained assets unprompted at approximately 22:05 UTC, and 100% of user funds were ultimately recovered. A public proof-of-concept was released on GitHub following the incident. Separately, the Halborn February 2026 DeFi hacks recap estimated the Veil Cash incident at approximately $427,000 in notional exposure, though the final net loss to users was zero given the return of funds. Rekt.news covered the incident under the title 'The Unfinished Proof,' characterizing it as the direct template for the subsequent $2.26 million FoomCash exploit.","heading":"Protocol Logic Incident — Groth16 Misconfiguration (February 2026)","sources":[{"url":"https://github.com/DK27ss/VeilCash-5K-PoC","name":"github.com","type":"other","credibility":3},{"url":"https://rekt.news/the-unfinished-proof","name":"rekt.news","type":"other","credibility":3},{"url":"https://coinsbench.com/forging-zksnark-proofs-via-misconfigured-verification-keys-the-veil-01-eth-exploit-2a6bb7d0078b","name":"coinsbench.com","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/month-in-review-top-defi-hacks-of-february-2026","name":"halborn.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Veil Cash contracted the Pashov Audit Group for a security review prior to the February 2026 incident. Pashov publicly confirmed on X (post ID 2025598503255167195) that the misconfigured Groth16 verifier contract was explicitly listed as out of scope in their engagement, meaning the critical vulnerability was never reviewed. The protocol had no bug bounty program as of the date of the incident, a gap highlighted in CertiK Skynet's assessment of the project. CertiK Skynet assigned Veil Cash a score of 71.36 (BBB rating) as of early 2026, noting zero CertiK audit coverage, unverified team identity, and no bug bounty. The protocol's operational resilience score was rated at 30%. The verifier contract's owner address appeared as a null/renounced address (0x000000...000), limiting the ability to execute emergency upgrades. New protocol pools deployed after the incident were stated by the team to not be vulnerable to the Groth16 misconfiguration. No independent post-incident audit of the new verifier setup was publicly documented at the time of this investigation.","heading":"Audit History and Security Posture","sources":[{"url":"https://x.com/PashovAuditGrp/status/2025598503255167195","name":"x.com","type":"other","credibility":3},{"url":"https://skynet.certik.com/projects/veil-cash","name":"skynet.certik.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The Veil Cash incident directly preceded and allegedly enabled a substantially larger exploit of FoomCash, a separate protocol that used an identical Groth16 verifier misconfiguration. On February 26, 2026, an attacker used the technique documented in the Veil Cash post-mortem to drain approximately $2.26 million from FoomCash across Ethereum and Base. Rekt.news noted that the Veil Cash incident served as a public template: 'someone read that post-mortem, identified a larger target, and scaled it up by several orders of magnitude.' Decurity's whitehat entity rescued approximately $1.84 million on Ethereum; the Base-side attacker retained approximately $320,000–$330,000 under the protocol's own stated 'code is law' bounty rules. The FoomCash incident resulted in a net user loss of approximately $420,000. The broader pattern — zkSNARK verifiers deployed with default placeholder parameters — has been flagged by security researchers as a systemic risk in ZK DeFi protocols that rely on the snarkjs Phase 2 ceremony toolchain.","heading":"Systemic Risk: FoomCash Copycat Exploit","sources":[{"url":"https://www.cryptotimes.io/2026/02/26/foomcash-loses-2-26m-in-copycat-zksnark-exploit/","name":"cryptotimes.io","type":"other","credibility":3},{"url":"https://rekt.news/the-unfinished-proof","name":"rekt.news","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/month-in-review-top-defi-hacks-of-february-2026","name":"halborn.com","type":"other","credibility":3},{"url":"https://dev.to/ohmygod/when-zero-knowledge-proofs-break-how-groth16-verification-key-misconfigs-drained-3m-from-defi-47i9","name":"dev.to","type":"other","credibility":3}],"severity":"medium"},{"content":"Veil Cash differentiates itself from fully permissionless privacy mixers through an integrated compliance layer. Every deposit is screened before entering the shielded pool. Users with a Coinbase EAS (Ethereum Attestation Service) attestation, a Binance BABT token, or a positive Ethos reputation score are automatically approved. Deposits not meeting those criteria are forwarded to 0xbow, a compliance provider co-founded by Ameen Soleimani, Nathaniel Fried, and Zak Cole, which implements Privacy Pools research originally described by Vitalik Buterin. Deposits declined by 0xbow are refunded to the sender. The protocol claims backing from Coinbase Ventures and the Base Ecosystem Fund, giving it institutional credibility within the Coinbase ecosystem, though no formal press release from Coinbase Ventures confirming an investment was independently verified by this investigation. Despite the compliance screening layer, the protocol remains a privacy-enhancing technology and is subject to the same evolving regulatory environment that resulted in OFAC sanctioning Tornado Cash in 2022. No enforcement action against Veil Cash has been documented as of May 2026.","heading":"Compliance Framework and Regulatory Risk","sources":[{"url":"https://docs.veil.cash/intro/verified-users/coinbase-onchain-verification","name":"docs.veil.cash","type":"other","credibility":3},{"url":"https://www.bankless.com/read/getting-started-with-veils-privacy-protocol-on-base","name":"bankless.com","type":"other","credibility":3},{"url":"https://0xbow.io/","name":"0xbow.io","type":"other","credibility":3},{"url":"https://www.theblock.co/post/348959/0xbow-privacy-pools-new-cypherpunk-tool-inspired-research-ethereum-founder-vitalik-buterin","name":"theblock.co","type":"other","credibility":3}],"severity":"medium"},{"content":"The VEIL token is deployed on Base at address 0x767a739d1a152639e9ea1d8c1bd55fdc5b217d7f. As of late May 2026, the token traded at approximately $0.026–$0.086 with a market capitalization between $1.85 million and $2.1 million fully diluted. Its all-time high was $0.31 and all-time low was $0.015, indicating significant drawdown from peak. 24-hour trading volume was approximately $61,199, with 98.29% sourced from decentralized exchanges. Approximately 110,617 token holders exist with very low concentration risk (0.89% held by major wallets). Staked VEIL amounted to approximately $292,930, representing 15.7% of market cap. The token functions as an access credential — access to verified pools requires holding at least 2,500 VEIL — and as a future yield-sharing instrument, with 0.5% deposit fees eventually distributed to stakers. Points earned through depositing are convertible into VEIL tokens. The protocol's owner contract appears to have renounced ownership (null address), reducing admin key risk but also limiting incident response capability.","heading":"Token Economics and Market Data","sources":[{"url":"https://defillama.com/protocol/veil-cash","name":"defillama.com","type":"other","credibility":3},{"url":"https://www.coingecko.com/en/coins/veil-token","name":"coingecko.com","type":"other","credibility":3},{"url":"https://cryptorank.io/price/veil-cash","name":"cryptorank.io","type":"other","credibility":3},{"url":"https://skynet.certik.com/projects/veil-cash","name":"skynet.certik.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The founding team of Veil Cash (the Base L2 protocol, not the 2019 Veil privacy coin) has not been publicly identified in major crypto media as of May 2026. CertiK Skynet's assessment notes that team identity has not been verified by CertiK or any known third party. The project's GitHub organization at github.com/veildotcash hosts the protocol's smart contract code. The project's website and documentation do not disclose team member names or professional backgrounds. The use of pseudonymous or anonymous development is common in DeFi privacy protocols, but it represents an elevated counterparty risk factor. The lack of public team information was a contributing factor to ZachXBT flagging the entity, consistent with his investigative focus on unverified teams operating financial protocols. No corporate registration, legal entity, or physical jurisdiction for the project has been publicly identified.","heading":"Team and Transparency","sources":[{"url":"https://skynet.certik.com/projects/veil-cash","name":"skynet.certik.com","type":"other","credibility":3},{"url":"https://github.com/veildotcash","name":"github.com","type":"other","credibility":3},{"url":"https://www.veil.cash/","name":"veil.cash","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2024","event":"Veil Cash protocol launches on Base L2 with zk-SNARK privacy pools for ETH and USDC.","source":"","date_original":"2024-01-01"},{"date":"2024-06","event":"Coinbase EAS (Ethereum Attestation Service) integration introduced, allowing Coinbase-verified users auto-approval into verified pools.","source":"","date_original":"2024-06-01"},{"date":"2025","event":"Pashov Audit Group completes a security review of Veil Cash smart contracts; the Groth16 verifier contract is explicitly listed out of scope.","source":"","date_original":"2025-01-01"},{"date":"2026-02-21","event":"Attacker exploits the Groth16 verifier misconfiguration (delta == gamma) in Veil Cash's legacy Base pool, executing 29 fraudulent withdrawals and draining 2.9 ETH in a single transaction.","source":""},{"date":"2026-02-21","event":"DefimonAlerts (Decurity security firm) intervenes and rescues remaining pool funds from the legacy pools.","source":""},{"date":"2026-02-21","event":"Exploiter returns all drained funds unprompted at approximately 22:05 UTC; 100% of Veil Cash user funds recovered.","source":""},{"date":"2026-02-22","event":"Public proof-of-concept for the Veil Cash Groth16 exploit published on GitHub by researcher DK27ss. Rekt.news covers incident as 'The Unfinished Proof'.","source":""},{"date":"2026-02-22","event":"Pashov Audit Group publicly confirms on X that the verifier was out of scope for their audit engagement.","source":""},{"date":"2026-02-26","event":"FoomCash suffers a $2.26 million exploit using the identical Groth16 misconfiguration pattern first publicly documented in the Veil Cash incident.","source":""},{"date":"2026-03","event":"CryptoTimes and Halborn publish post-mortems linking the FoomCash exploit directly to the Veil Cash incident as the originating template.","source":"","date_original":"2026-03-01"}],"sources_used":[{"url":"https://defillama.com/protocol/veil-cash","name":"defillama.com","type":"other","archive_url":"http://web.archive.org/web/20250906130846/https://defillama.com/protocol/veil-cash","credibility":3,"archive_timestamp":"2025-09-06T13:08:46+00:00"},{"url":"https://docs.veil.cash/","name":"docs.veil.cash","type":"other","archive_url":"http://web.archive.org/web/20260608012315/https://docs.veil.cash/","credibility":3,"archive_timestamp":"2026-06-08T01:23:15+00:00"},{"url":"https://www.bankless.com/read/getting-started-with-veils-privacy-protocol-on-base","name":"bankless.com","type":"other","archive_url":"http://web.archive.org/web/20260520155334/https://www.bankless.com/read/getting-started-with-veils-privacy-protocol-on-base","credibility":3,"archive_timestamp":"2026-05-20T15:53:34+00:00"},{"url":"https://github.com/DK27ss/VeilCash-5K-PoC","name":"github.com","type":"other","archive_url":"https://web.archive.org/web/20260829033131/https://github.com/DK27ss/VeilCash-5K-PoC","credibility":3,"archive_timestamp":"2026-08-29T03:31:31+00:00"},{"url":"https://rekt.news/the-unfinished-proof","name":"rekt.news","type":"other","archive_url":"http://web.archive.org/web/20260414185742/https://rekt.news/the-unfinished-proof","credibility":3,"archive_timestamp":"2026-04-14T18:57:42+00:00"},{"url":"https://coinsbench.com/forging-zksnark-proofs-via-misconfigured-verification-keys-the-veil-01-eth-exploit-2a6bb7d0078b","name":"coinsbench.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.halborn.com/blog/post/month-in-review-top-defi-hacks-of-february-2026","name":"halborn.com","type":"other","archive_url":"http://web.archive.org/web/20260609215207/https://www.halborn.com/blog/post/month-in-review-top-defi-hacks-of-february-2026","credibility":3,"archive_timestamp":"2026-06-09T21:52:07+00:00"},{"url":"https://x.com/PashovAuditGrp/status/2025598503255167195","name":"x.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://skynet.certik.com/projects/veil-cash","name":"skynet.certik.com","type":"other","archive_url":"https://web.archive.org/web/20260829041104/https://skynet.certik.com/projects/veil-cash","credibility":3,"archive_timestamp":"2026-08-29T04:11:04+00:00"},{"url":"https://www.cryptotimes.io/2026/02/26/foomcash-loses-2-26m-in-copycat-zksnark-exploit/","name":"cryptotimes.io","type":"other","archive_url":"https://web.archive.org/web/20260829122127/https://www.cryptotimes.io/2026/02/26/foomcash-loses-2-26m-in-copycat-zksnark-exploit/","credibility":3,"archive_timestamp":"2026-08-29T12:21:27+00:00"},{"url":"https://dev.to/ohmygod/when-zero-knowledge-proofs-break-how-groth16-verification-key-misconfigs-drained-3m-from-defi-47i9","name":"dev.to","type":"other","archive_url":null,"credibility":3,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://docs.veil.cash/intro/verified-users/coinbase-onchain-verification","name":"docs.veil.cash","type":"other","archive_url":"http://web.archive.org/web/20260510173930/https://docs.veil.cash/intro/verified-users/coinbase-onchain-verification","credibility":3,"archive_timestamp":"2026-05-10T17:39:30+00:00"},{"url":"https://0xbow.io/","name":"0xbow.io","type":"other","archive_url":"http://web.archive.org/web/20260816070030/https://0xbow.io/","credibility":3,"archive_timestamp":"2026-08-16T07:00:30+00:00"},{"url":"https://www.theblock.co/post/348959/0xbow-privacy-pools-new-cypherpunk-tool-inspired-research-ethereum-founder-vitalik-buterin","name":"theblock.co","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.coingecko.com/en/coins/veil-token","name":"coingecko.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://cryptorank.io/price/veil-cash","name":"cryptorank.io","type":"other","archive_url":"https://web.archive.org/web/20260829075015/https://cryptorank.io/price/veil-cash","credibility":3,"archive_timestamp":"2026-08-29T07:50:15+00:00"},{"url":"https://github.com/veildotcash","name":"github.com","type":"other","archive_url":"http://web.archive.org/web/20260809215937/https://github.com/veildotcash","credibility":3,"archive_timestamp":"2026-08-09T21:59:37+00:00"},{"url":"https://www.veil.cash/","name":"veil.cash","type":"other","archive_url":"http://web.archive.org/web/20260610063929/https://www.veil.cash/","credibility":3,"archive_timestamp":"2026-06-10T06:39:29+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:13.481328+00:00","updated_at":"2026-09-11T00:56:57.634686+00:00"}}