{"investigation":{"slug":"vestra-dao","entity_name":"Vestra DAO","trust_score":32,"severity_base":null,"score_modifier":0,"confidence":0.72,"status":"published","content_type":"investigation","summary":"Vestra DAO is an Ethereum-based DeFi and SocialFi protocol operating the VSTR token, launched in late 2024. On December 4, 2024, the protocol suffered a critical smart contract exploit in its staking contract that drained approximately $480,000–$500,000 worth of VSTR tokens — an attack that occurred less than one month after the token began trading. Stolen funds were laundered through Tornado Cash, the token price collapsed by roughly 50%, and the project's ability to fully compensate affected users remains unresolved.","sections":[{"content":"Vestra DAO is a decentralized autonomous organization built on the Ethereum blockchain that describes itself as pioneering the future of SocialFi by integrating social engagement with decentralized finance. The project centers on the VSTR ERC-20 token (contract address: 0x92D5942f468447f1F21c2092580F15544923b434) and a companion NFT collection called CMLE (Crypto Monster Limited Edition), capped at 250 pairs, which grants holders community perks and platform access. The protocol's flagship product is Brolyz, a social media platform aimed at financial market participants — traders, brokers, and analysts — combining elements of SocialFi with crypto, stocks, and commodities market analysis. Governance is conducted through token-weighted voting whereby holders can propose and vote on predefined protocol operations by locking VSTR. CertiK records list the project's inception as March 1, 2023, though the VSTR token did not begin trading until approximately November 2024. As of mid-2026 the token trades at approximately $0.007 with a market capitalization near $11.6 million and roughly 2,711 on-chain holders. Liquidity is approximately $1.35 million, concentrated on Uniswap V3.","heading":"Protocol Overview","sources":[{"url":"https://www.coingecko.com/en/coins/vestra-dao","name":"coingecko.com","type":"other","credibility":3},{"url":"https://etherscan.io/token/0x92d5942f468447f1f21c2092580f15544923b434","name":"etherscan.io","type":"other","credibility":3},{"url":"https://skynet.certik.com/projects/vestradao","name":"skynet.certik.com","type":"other","credibility":3},{"url":"https://docs.vestradao.com/cmle-nft-community/brolyz","name":"docs.vestradao.com","type":"other","credibility":3},{"url":"https://app.uniswap.org/explore/tokens/ethereum/0x92d5942f468447f1f21c2092580f15544923b434","name":"app.uniswap.org","type":"other","credibility":3}],"severity":"medium"},{"content":"On December 4–5, 2024, Vestra DAO's locked staking contract was exploited due to a critical logic error in the unStake() function. The flaw allowed an attacker to repeatedly claim yield from a staking position that had already been marked inactive (isActive = false), because the function did not validate the active status of a position before processing an unstake call. The attacker prepared the attack approximately one month in advance by staking 500,000 VSTR tokens and waiting for the lock period to expire. After calling unStake() legitimately and receiving the 500,000 VSTR principal plus 20,000 VSTR in yield, the attacker continued calling the same function on the now-inactive position, extracting an additional 20,000 VSTR per call. To prevent arithmetic underflow errors in the contract's tracking variables (data.totalStaked and data.countUser), the attacker created auxiliary accounts that staked fresh tokens between rounds of exploitation. The attacker spent approximately $40,000 in Ethereum gas fees to prioritize transactions and briefly became one of the largest gas consumers on the Ethereum network during the attack window. Reported attack-related addresses include attacker address 0x954386 and attacker contract 0x81AD99, with vulnerable staking contract at 0x8A30d6. The total tokens extracted were reported as approximately 73,720,000 VSTR, worth roughly $480,000–$500,000 at the time. Stolen tokens were converted to ETH — yielding approximately 125 ETH — and laundered through the Tornado Cash privacy mixer. Vestra DAO publicly acknowledged the breach, stated it had blacklisted the compromised staking contract, and offered the attacker a 20% bounty (approximately $96,000–$100,000) in exchange for returning the remainder of the funds; negotiations did not reach a settlement.","heading":"December 2024 Smart Contract Exploit","sources":[{"url":"https://medium.com/coinmonks/overview-c1a710e0ea9f","name":"medium.com","type":"other","credibility":3},{"url":"https://news.shib.io/2024/12/06/vestra-dao-suffers-500k-exploit-token-plunges-50/","name":"news.shib.io","type":"other","credibility":3},{"url":"https://www.binance.com/en/square/post/12-06-2024-vestra-dao-faces-cyber-attack-exploiting-staking-contract-flaw-17201499210818","name":"binance.com","type":"other","credibility":3},{"url":"https://coinsbench.com/vestra-dao-500k-exploit-a-simple-breakdown-4d9436856c17","name":"coinsbench.com","type":"other","credibility":3},{"url":"https://cryptopanic.com/news/20366782/Vestra-DAO-Smart-Contract-Exploited-480K-Lost-What-Happened-Vestra-DAOs-VSTR-token-fell-victim-to-a-smart-contract-exploit-draining-480000-Aftermath-Stolen-tokens-converted-to-ETH-and-laundered-via-Tornado-Cash-Impact-VSTR-price-dropped-50-users-urged","name":"cryptopanic.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Vestra DAO commissioned two security audits from CertiK, the most recent of which was delivered on August 5, 2024 — approximately four months before the December 2024 exploit. The CertiK audit identified 14 total findings: 0 critical, 3 major (2 acknowledged, 1 resolved), 2 medium (1 partially resolved, 1 acknowledged), 7 minor (6 resolved, 1 partially resolved), and 2 informational (both resolved). Reported major findings included centralization concerns and various logical issues. The formal verification assessment of the PrivateSale.sol contract achieved a rating of 6 out of 13 verified properties. CertiK granted Vestra DAO a Gold team verification badge on October 29, 2024, confirming 4 core team members. Notably, the logic error in the unStake() function that enabled the December 2024 exploit — a missing active-position validation check — does not appear to have been flagged in publicly disclosed audit findings, raising questions about the comprehensiveness of the pre-launch audit coverage. QuillAudits, in a post-mortem analysis, cited the absence of active status validation, the failure to delete staking data post-unstake, and the lack of engagement with professional auditors as the root causes of the vulnerability.","heading":"Security Audit Findings and Pre-Exploit Audit Failure","sources":[{"url":"https://skynet.certik.com/projects/vestradao","name":"skynet.certik.com","type":"other","credibility":3},{"url":"https://medium.com/coinmonks/overview-c1a710e0ea9f","name":"medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Prior to the exploit, VSTR traded at approximately $0.013. Following the attack on December 4–5, 2024, the token's price plummeted to approximately $0.005, representing a decline of roughly 50% within hours. The token subsequently recovered partially to approximately $0.009 but has remained volatile. Approximately 755,631,188 VSTR tokens that remained in the compromised staking contract were permanently removed from circulation by the team as a protective measure to stabilize tokenomics. As of mid-2026, VSTR trades at approximately $0.007 with a market capitalization of roughly $11.6 million and a circulating supply of approximately 1.7 billion tokens. Trading volume is thin, with the primary Uniswap V3 VSTR/WETH pool reporting approximately $27,000 in daily volume. The total token supply is listed at approximately 49.98 billion VSTR, though a large portion is reported as burned or removed from circulation. The incident has contributed to persistently low liquidity and elevated volatility in the token.","heading":"Market and Token Impact","sources":[{"url":"https://news.shib.io/2024/12/06/vestra-dao-suffers-500k-exploit-token-plunges-50/","name":"news.shib.io","type":"other","credibility":3},{"url":"https://www.coingecko.com/en/coins/vestra-dao","name":"coingecko.com","type":"other","credibility":3},{"url":"https://coincodex.com/crypto/vestra-dao/","name":"coincodex.com","type":"other","credibility":3},{"url":"https://www.geckoterminal.com/eth/pools/0x2349a69875aad7beb787f6f230ea2d71a52d6283","name":"geckoterminal.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the exploit, Vestra DAO's team issued a public statement on X (formerly Twitter) acknowledging the breach. The statement confirmed that the team quickly identified the vulnerability, blacklisted the compromised staking contract to prevent further drainage, and indicated that the project may have sufficient reserves to compensate affected users. The team extended a 20% white-hat bounty offer to the attacker in exchange for returning the majority of stolen funds; this offer was not accepted. No publicly disclosed compensation plan with specific amounts, eligibility criteria, or a defined timeline for affected stakers has been confirmed in available sources as of mid-2026. The team stated it removed 755 million VSTR tokens from circulation to protect tokenomics. The project has continued operations and has outlined a 2025 roadmap including the Brolyz closed beta, open beta, and AI-backed GameFi features, though the status of these deliverables relative to their stated timelines is not independently verified in available sources.","heading":"Incident Response and User Compensation","sources":[{"url":"https://news.shib.io/2024/12/06/vestra-dao-suffers-500k-exploit-token-plunges-50/","name":"news.shib.io","type":"other","credibility":3},{"url":"https://www.binance.com/en/square/post/12-04-2024-vestra-dao-faces-ongoing-hack-with-significant-losses-17117929990841","name":"binance.com","type":"other","credibility":3},{"url":"https://www.mitrade.com/insights/news/live-news/article-3-504835-20241205","name":"mitrade.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On-chain analysis of the December 2024 exploit shows the attacker funded initial gas via 0.51 ETH transferred to Beaverbuild, a block-building service, for transaction prioritization. The attacker flooded the network with transactions involving batches of 500,000–520,000 VSTR, receiving 20,000 VSTR per call. The attacker's gas expenditure reached approximately $40,000, briefly making the attacking account one of the highest gas consumers on Ethereum during the exploit window. Stolen VSTR was converted to ETH, yielding a total of approximately 125 ETH, which was then routed through Tornado Cash — a sanctioned Ethereum privacy mixer — to obscure the trail of funds. The use of Tornado Cash renders recovery of the stolen assets highly unlikely. Relevant on-chain addresses from published post-mortems include the vulnerable staking contract at partial address 0x8A30d6, attacker address at 0x954386, and attacker contract at 0x81AD99; full address hashes have been published in QuillAudits and CoinsBench post-mortem analyses referenced below.","heading":"On-Chain and Laundering Activity","sources":[{"url":"https://medium.com/coinmonks/overview-c1a710e0ea9f","name":"medium.com","type":"other","credibility":3},{"url":"https://coinsbench.com/vestra-dao-500k-exploit-a-simple-breakdown-4d9436856c17","name":"coinsbench.com","type":"other","credibility":3},{"url":"https://news.shib.io/2024/12/06/vestra-dao-suffers-500k-exploit-token-plunges-50/","name":"news.shib.io","type":"other","credibility":3}],"severity":"medium"},{"content":"CertiK's Skynet platform lists Vestra DAO as holding a Gold verification badge with 4 core team members verified as of October 29, 2024. The project is classified as Tier 2 geo-risk under CertiK's framework. The Vestra DAO website includes a team page at vestradao.com/team, however publicly available search results do not disclose the names, professional histories, or prior project affiliations of individual team members. The VSTR token was developed by the CMLE NFT community. The project's tokenomics include blacklist functionality integrated into the token contract, which the team used post-exploit to restrict the compromised staking contract. The degree of true decentralization is uncertain given CertiK's identification of centralization concerns as major findings during the August 2024 audit. No regulatory actions, lawsuits, or government enforcement proceedings against Vestra DAO or its team members have been identified in available sources.","heading":"Team and Transparency","sources":[{"url":"https://skynet.certik.com/projects/vestradao","name":"skynet.certik.com","type":"other","credibility":3},{"url":"https://vestradao.com/team","name":"vestradao.com","type":"other","credibility":3},{"url":"https://www.rootdata.com/Projects/detail/Vestra%20DAO?k=MTUxMTM%3D","name":"rootdata.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2023-03","event":"Vestra DAO project inception date per CertiK records.","source":"","date_original":"2023-03-01"},{"date":"2024-08-05","event":"CertiK delivered second security audit; 14 findings identified including 3 major issues; no critical issues flagged.","source":""},{"date":"2024-10-29","event":"CertiK granted Vestra DAO a Gold team verification badge with 4 verified core team members.","source":""},{"date":"2024-11","event":"VSTR token begins trading on Uniswap V3 (approximate date, approximately one month before the exploit).","source":"","date_original":"2024-11-01"},{"date":"2024-11-04","event":"Attacker stakes 500,000 VSTR in the locked staking contract, beginning a one-month preparation phase for the exploit.","source":""},{"date":"2024-12-04","event":"Exploit executed: attacker repeatedly called unStake() on an inactive staking position, draining approximately 73,720,000 VSTR (~$480,000–$500,000). VSTR price collapsed from ~$0.013 to ~$0.005.","source":""},{"date":"2024-12-05","event":"Vestra DAO team publicly acknowledged the exploit on X, blacklisted the compromised staking contract, and offered attacker a 20% white-hat bounty. Stolen ETH (~125 ETH) began moving through Tornado Cash.","source":""},{"date":"2024-12-06","event":"Multiple crypto news outlets report on the incident. Team announces removal of 755,631,188 VSTR from circulation to protect tokenomics. Bounty negotiations with attacker fail.","source":""},{"date":"2025-04","event":"Brolyz SocialFi platform open beta launch was scheduled per roadmap; independent verification of delivery is not available in public sources.","source":"","date_original":"2025-04-01"}],"sources_used":[{"url":"https://www.coingecko.com/en/coins/vestra-dao","name":"coingecko.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://etherscan.io/token/0x92d5942f468447f1f21c2092580f15544923b434","name":"etherscan.io","type":"other","archive_url":"http://web.archive.org/web/20260413215125/https://etherscan.io/token/0x92d5942f468447f1f21c2092580f15544923b434","credibility":3,"archive_timestamp":"2026-04-13T21:51:25+00:00"},{"url":"https://skynet.certik.com/projects/vestradao","name":"skynet.certik.com","type":"other","archive_url":"http://web.archive.org/web/20260308195317/https://skynet.certik.com/projects/vestradao","credibility":3,"archive_timestamp":"2026-03-08T19:53:17+00:00"},{"url":"https://docs.vestradao.com/cmle-nft-community/brolyz","name":"docs.vestradao.com","type":"other","archive_url":"http://web.archive.org/web/20260413200450/https://docs.vestradao.com/cmle-nft-community/brolyz","credibility":3,"archive_timestamp":"2026-04-13T20:04:50+00:00"},{"url":"https://app.uniswap.org/explore/tokens/ethereum/0x92d5942f468447f1f21c2092580f15544923b434","name":"app.uniswap.org","type":"other","archive_url":"http://web.archive.org/web/20260510215419/https://app.uniswap.org/explore/tokens/ethereum/0x92d5942f468447f1f21c2092580f15544923b434","credibility":3,"archive_timestamp":"2026-05-10T21:54:19+00:00"},{"url":"https://medium.com/coinmonks/overview-c1a710e0ea9f","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://news.shib.io/2024/12/06/vestra-dao-suffers-500k-exploit-token-plunges-50/","name":"news.shib.io","type":"other","archive_url":"http://web.archive.org/web/20260123195300/https://news.shib.io/2024/12/06/vestra-dao-suffers-500k-exploit-token-plunges-50/","credibility":3,"archive_timestamp":"2026-01-23T19:53:00+00:00"},{"url":"https://www.binance.com/en/square/post/12-06-2024-vestra-dao-faces-cyber-attack-exploiting-staking-contract-flaw-17201499210818","name":"binance.com","type":"other","archive_url":"https://web.archive.org/web/20260829083327/https://www.binance.com/en/square/post/12-06-2024-vestra-dao-faces-cyber-attack-exploiting-staking-contract-flaw-17201499210818","credibility":3,"archive_timestamp":"2026-08-29T08:33:27+00:00"},{"url":"https://coinsbench.com/vestra-dao-500k-exploit-a-simple-breakdown-4d9436856c17","name":"coinsbench.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://cryptopanic.com/news/20366782/Vestra-DAO-Smart-Contract-Exploited-480K-Lost-What-Happened-Vestra-DAOs-VSTR-token-fell-victim-to-a-smart-contract-exploit-draining-480000-Aftermath-Stolen-tokens-converted-to-ETH-and-laundered-via-Tornado-Cash-Impact-VSTR-price-dropped-50-users-urged","name":"cryptopanic.com","type":"other","archive_url":"https://web.archive.org/web/20260829175615/https://cryptopanic.com/news/20366782/Vestra-DAO-Smart-Contract-Exploited-480K-Lost-What-Happened-Vestra-DAOs-VSTR-token-fell-victim-to-a-smart-contract-exploit-draining-480000-Aftermath-Stolen-tokens-converted-to-ETH-and-laundered-via-Tornado-Cash-Impact-VSTR-price-dropped-50-users-urged","credibility":3,"archive_timestamp":"2026-08-29T17:56:15+00:00"},{"url":"https://coincodex.com/crypto/vestra-dao/","name":"coincodex.com","type":"other","archive_url":"https://web.archive.org/web/20260829224855/https://coincodex.com/crypto/vestra-dao/","credibility":3,"archive_timestamp":"2026-08-29T22:48:55+00:00"},{"url":"https://www.geckoterminal.com/eth/pools/0x2349a69875aad7beb787f6f230ea2d71a52d6283","name":"geckoterminal.com","type":"other","archive_url":"https://web.archive.org/web/20260829122336/https://www.geckoterminal.com/eth/pools/0x2349a69875aad7beb787f6f230ea2d71a52d6283","credibility":3,"archive_timestamp":"2026-08-29T12:23:36+00:00"},{"url":"https://www.binance.com/en/square/post/12-04-2024-vestra-dao-faces-ongoing-hack-with-significant-losses-17117929990841","name":"binance.com","type":"other","archive_url":"https://web.archive.org/web/20260829083316/https://www.binance.com/en/square/post/12-04-2024-vestra-dao-faces-ongoing-hack-with-significant-losses-17117929990841","credibility":3,"archive_timestamp":"2026-08-29T08:33:16+00:00"},{"url":"https://www.mitrade.com/insights/news/live-news/article-3-504835-20241205","name":"mitrade.com","type":"other","archive_url":"https://web.archive.org/web/20260829051118/https://www.mitrade.com/insights/news/live-news/article-3-504835-20241205","credibility":3,"archive_timestamp":"2026-08-29T05:11:18+00:00"},{"url":"https://vestradao.com/team","name":"vestradao.com","type":"other","archive_url":"http://web.archive.org/web/20260114202840/https://vestradao.com/team","credibility":3,"archive_timestamp":"2026-01-14T20:28:40+00:00"},{"url":"https://www.rootdata.com/Projects/detail/Vestra%20DAO?k=MTUxMTM%3D","name":"rootdata.com","type":"other","archive_url":"https://web.archive.org/web/20260829091408/https://www.rootdata.com/Projects/detail/Vestra%20DAO?k=MTUxMTM%3D","credibility":3,"archive_timestamp":"2026-08-29T09:14:08+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:27.112992+00:00","updated_at":"2026-08-29T23:26:13.504608+00:00"}}