{"investigation":{"slug":"wise-lending-v1","entity_name":"Wise Lending V1","trust_score":22,"severity_base":null,"score_modifier":0,"confidence":0.78,"status":"published","content_type":"investigation","summary":"Wise Lending V1 is the first version of the Wise Lending decentralized lending and yield-aggregation protocol deployed on Ethereum, built from scratch by WiseSoft LLC and founded by Peter Girr. The V1 deployment suffered two confirmed on-chain exploits within approximately three months, losing an estimated $700,000+ in total user funds across both incidents, with no publicly documented recovery or compensation plan. ZachXBT has flagged the entity, and post-exploit TVL collapsed effectively to zero.","sections":[{"content":"Wise Lending is a decentralized liquidity market built on Ethereum that allows users to supply crypto assets to earn variable APY from borrowers, and to borrow assets against collateral. Unlike many DeFi protocols that fork existing codebases, WiseSoft LLC claimed to have built the smart contracts from scratch. Key architectural features include NFT-based user positions (each user mints an NFT on first interaction, enabling transferable positions), a multi-oracle price system using RedStone Oracles with Uniswap TWAP as a sanity check, integration with external yield sources including Aave and Pendle Finance, and a hard-capped liquidation fee mechanism designed to protect borrowers from excessive losses. The protocol offered a $100,000 bug bounty program administered through Hashlock, an Australian blockchain security firm. The underlying WISE token was issued through a liquidity bootstrap event that raised approximately 57,900 ETH, with more than 28,000 ETH reportedly locked immutably in the WISE/ETH Uniswap pair to establish a price floor. The team, led by founder and CEO Peter Girr, includes software engineer Aaron Hason, Solidity instructor Vitally Marinchenko, and security lead Rene Hochmuth. The V1 contracts were subsequently deprecated following repeated exploits, with the team releasing a V2 version.","heading":"Protocol Overview","sources":[{"url":"https://docs.wise.one/wise-lending/wise_lending","name":"docs.wise.one","type":"other","credibility":3},{"url":"https://wisesoft.gitbook.io/wise/wise-lending","name":"wisesoft.gitbook.io","type":"other","credibility":3},{"url":"https://medium.com/@devinmarty/wise-token-founder-peter-girr-attends-telegram-ama-with-gains-associates-transcript-242d28174141","name":"medium.com","type":"other","credibility":3},{"url":"https://hashlock.com/bug-bounty/wise-lending","name":"hashlock.com","type":"other","credibility":3},{"url":"https://defillama.com/protocol/wise-lending-v1","name":"defillama.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On approximately October 13, 2023, Wise Lending V1 suffered its first documented security incident: a price manipulation attack that resulted in an alleged loss of approximately $260,000. The specific technical mechanism of this first exploit has not been extensively documented in available public sources, but reports describe it as a price manipulation attack. Multiple subsequent news articles covering the January 2024 exploit referenced this earlier October 2023 incident as context, describing the January event as 'the second attack on the protocol within six months.' No official post-mortem from the Wise Lending team addressing the October 2023 incident has been identified in publicly available sources. No public information regarding user compensation or fund recovery related to this first exploit was found.","heading":"First Exploit: October 2023 Price Manipulation Attack","sources":[{"url":"https://coincodecap.com/wise-lending-faces-440k-loss-in-suspected-flash-loan-exploit-of-crypto-assets","name":"coincodecap.com","type":"other","credibility":3},{"url":"https://www.cryptopolitan.com/wise-lending-loses-400000-flash-loan-attack/","name":"cryptopolitan.com","type":"other","credibility":3},{"url":"https://cryptorank.io/news/feed/62124-wise-lending-loses-400000-flash-loan-attack","name":"cryptorank.io","type":"other","credibility":3}],"severity":"medium"},{"content":"On January 12, 2024, Wise Lending V1 suffered a second, more technically documented exploit resulting in a loss of approximately 177 ETH (valued between $440,000 and $464,000 at the time). Blockchain security firm PeckShield attributed the incident to a flaw in the protocol's share accounting logic involving a precision issue. Security researchers at SolidityScan and AstraSec later published detailed post-mortems.\n\nThe attack targeted the Wise PLP Pool, a pool designed for Pendle LP tokens (specifically PLP-stETH-Dec2025). The attacker's address was 0xb90cf1d740b206b6d80854bc525e609dc42b45dc, using an attack contract at 0x91c49cc7fbfe8f70aceeb075952cd64817f9d82c. The vulnerable contract was 0x37e49bf3749513a02fa535f0cbc383796e8107e4.\n\nThe attack proceeded in several steps: first, the attacker borrowed 1,110 stETH tokens worth approximately $2.9 million from Aave v2 via a flash loan. They deposited a small amount of PLP-stETH tokens into the target pool, then made a series of strategic deposits and withdrawals just below the protocol's donation throttle limit. Through this 'stealth donation' approach, the attacker exploited a rounding error in the _calculateShares function — specifically, by performing division before multiplication, causing truncation that allowed each cycle to inflate the share price. The discrepancy between _pseudoTotalPool and _totalDepositShares was amplified iteratively across multiple cycles. Once share prices were sufficiently inflated, the attacker used their inflated shares as collateral to borrow most of the funds from the lending markets across multiple puppet contracts. Assets drained included USDC, USDT, DAI, WETH, and numerous Pendle Finance-associated tokens.\n\nThe core vulnerability was the absence of two standard safeguards: a 'dead share' mechanism (as used by Uniswap V2) that would prevent a single actor from controlling an entire pool's shares, and proper accounting for donations created through deposit/withdrawal rounding cycles. The _cleanUp function's throttle on direct donations was insufficient because it did not account for indirect 'stealth donations' generated through rounding in the deposit/withdrawal cycle. The recommended fix is to always perform multiplication before division in share calculations, and to implement dead shares upon pool initialization.","heading":"Second Exploit: January 2024 Flash Loan and Share Price Inflation Attack","sources":[{"url":"https://cointelegraph.com/news/wise-lending-drained-440k-crypto-apparent-flash-loan-exploit","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://blog.solidityscan.com/wise-lending-hack-analysis-f652f389e397","name":"blog.solidityscan.com","type":"other","credibility":3},{"url":"https://medium.com/@astrasec/wiselending-hack-root-cause-analysis-1a2762f52298","name":"medium.com","type":"other","credibility":3},{"url":"https://www.infect3d.xyz/blog/wise-lending-post-mortem","name":"infect3d.xyz","type":"other","credibility":3},{"url":"https://blog.cobaltintelligence.com/post/wise-lending-suffers-464k-flash-loan-attack","name":"blog.cobaltintelligence.com","type":"other","credibility":3},{"url":"https://coingape.com/just-in-defi-security-suffers-another-hit-with-wise-lending-hack/","name":"coingape.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the January 2024 exploit, Wise Lending submitted its contracts for a competitive audit through Code4rena, conducted between February 21 and March 11, 2024, with $200,000 USDC in prizes. The audit covered 44 smart contracts comprising 6,326 lines of Solidity code. The C4 analysis identified 22 unique vulnerabilities: 5 rated HIGH severity and 17 rated MEDIUM severity. An additional 7 reports covered LOW severity or non-critical issues, and 6 reports recommended gas optimizations.\n\nPrior to the exploits, the Wise Lending team claimed the smart contracts had undergone audits by 'respected security firms' and maintained an active $100,000 bug bounty program through Hashlock. The Hashlock bug bounty specifically covers the WiseOracleHub, PositionNFTs, WiseLending, and AaveHub contracts on Arbitrum. Despite these stated security measures, the protocol was exploited twice in three months on its V1 deployment, raising questions about the effectiveness of pre-launch audit coverage and the protocol's ongoing vulnerability to share-price manipulation attacks.","heading":"Security Audit History and Code4rena Findings","sources":[{"url":"https://code4rena.com/reports/2024-02-wise-lending","name":"code4rena.com","type":"other","credibility":3},{"url":"https://code4rena.com/audits/2024-02-wise-lending","name":"code4rena.com","type":"other","credibility":3},{"url":"https://hashlock.com/bug-bounty/wise-lending","name":"hashlock.com","type":"other","credibility":3},{"url":"https://docs.wise.one/wise-references/100k_bug_bounty","name":"docs.wise.one","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the January 2024 exploit, Wise Lending V1's total value locked (TVL) on Ethereum collapsed to effectively zero. Data from DefiLlama shows the V1 deployment's TVL dropped to approximately $11.60 in the immediate aftermath of the exploit, representing a near-total loss of user deposits. The broader Wise Lending protocol (across all versions) had a modest TVL prior to the exploits, with all deposits concentrated on the Ethereum mainnet.\n\nThe two exploits combined resulted in an estimated total loss exceeding $700,000 in user funds. No official public statement from WiseSoft LLC acknowledging either exploit in detail, providing a post-mortem, or announcing a user compensation plan has been identified. Community frustration was noted in reporting, with users criticizing the team for not initially acknowledging the January 2024 hack publicly. The protocol subsequently launched a V2 version, though the V2 deployment also later suffered its own separate exploit incident.","heading":"TVL Collapse and Protocol Impact","sources":[{"url":"https://defillama.com/protocol/wise-lending-v1","name":"defillama.com","type":"other","credibility":3},{"url":"https://coinpaper.com/3049/major-incidents-from-last-week-wise-lending-exploit-and-xai-token-rug-pull","name":"coinpaper.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/wise-protocols-lose-38-9-m-jan-2024-exploits","name":"cointelegraph.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On-chain investigator ZachXBT has flagged Wise Lending as a risk entity. The specific nature and timing of this flag are not fully detailed in available public sources retrieved during this investigation, though ZachXBT's monitoring of DeFi protocols with repeated exploit history is consistent with his documented pattern of flagging protocols exhibiting systemic security failures. The two confirmed exploits within three months, combined with the lack of public post-mortems or user compensation announcements, and the near-zero TVL remaining on V1, constitute a pattern that risk monitoring services and community researchers have identified as high-severity concerns. The Wise Lending V1 deployment is considered deprecated as of early 2024.","heading":"ZachXBT Flag and Community Risk Signals","sources":[{"url":"https://beincrypto.com/avoid-crypto-scams-zachxbt-critical-checks/","name":"beincrypto.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/wise-lending-drained-440k-crypto-apparent-flash-loan-exploit","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://coingape.com/just-in-defi-security-suffers-another-hit-with-wise-lending-hack/","name":"coingape.com","type":"other","credibility":3}],"severity":"medium"},{"content":"WiseSoft LLC is a Delaware-incorporated company. The founder and CEO is Peter Girr, described publicly as a former U.S. Army Intelligence officer. The development team includes Aaron Hason (software engineer), Vitally Marinchenko (Solidity instructor and developer), and Rene Hochmuth (security lead). The team also employs frontend and Web3 developers. The team has stated publicly that no WISE tokens were allocated to founders, team members, or advisors for free — all team members allegedly purchased tokens on the open market. The protocol's governance and treasury design directs 100% of ecosystem profits to WISE token holders. Despite these stated pro-decentralization measures, the absence of transparent incident response communications following two exploits drew criticism from the community.","heading":"Team and Governance Background","sources":[{"url":"https://lightyagamicrypto.medium.com/who-is-peter-girr-50ab6f4db6ed","name":"lightyagamicrypto.medium.com","type":"other","credibility":3},{"url":"https://medium.com/@devinmarty/wise-token-founder-peter-girr-attends-telegram-ama-with-gains-associates-transcript-242d28174141","name":"medium.com","type":"other","credibility":3},{"url":"https://wisesoft.gitbook.io/wise/wise-lending","name":"wisesoft.gitbook.io","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2023-10-13","event":"Wise Lending V1 suffers its first documented exploit: an alleged price manipulation attack resulting in an estimated $260,000 loss. No official post-mortem was published.","source":""},{"date":"2024-01-12","event":"Wise Lending V1 suffers a second flash loan and share price inflation attack. Attacker (0xb90cf1d740b206b6d80854bc525e609dc42b45dc) exploits a precision loss vulnerability in _calculateShares, draining approximately 177 ETH (~$440,000-$464,000). PeckShield attributes the loss to flawed share accounting logic.","source":""},{"date":"2024-01-12","event":"Wise Lending V1 TVL collapses to effectively zero following the exploit. Multiple tokens including USDC, USDT, DAI, WETH, and Pendle Finance-associated tokens are drained.","source":""},{"date":"2024-02-21","event":"Code4rena competitive audit of Wise Lending smart contracts begins, running through March 11, 2024. The audit subsequently identifies 5 high-severity and 17 medium-severity vulnerabilities across 44 contracts.","source":""},{"date":"2024-03-11","event":"Code4rena audit of Wise Lending concludes. Report published identifying 22 unique vulnerabilities (5 high, 17 medium) in 6,326 lines of Solidity code across 44 contracts.","source":""}],"sources_used":[{"url":"https://docs.wise.one/wise-lending/wise_lending","name":"docs.wise.one","type":"other","archive_url":"http://web.archive.org/web/20260421014442/https://docs.wise.one/wise-lending/wise_lending","credibility":3,"archive_timestamp":"2026-04-21T01:44:42+00:00"},{"url":"https://wisesoft.gitbook.io/wise/wise-lending","name":"wisesoft.gitbook.io","type":"other","archive_url":"http://web.archive.org/web/20260309211949/https://wisesoft.gitbook.io/wise/wise-lending","credibility":3,"archive_timestamp":"2026-03-09T21:19:49+00:00"},{"url":"https://medium.com/@devinmarty/wise-token-founder-peter-girr-attends-telegram-ama-with-gains-associates-transcript-242d28174141","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://hashlock.com/bug-bounty/wise-lending","name":"hashlock.com","type":"other","archive_url":"http://web.archive.org/web/20250908062525/https://hashlock.com/bug-bounty/wise-lending","credibility":3,"archive_timestamp":"2025-09-08T06:25:25+00:00"},{"url":"https://defillama.com/protocol/wise-lending-v1","name":"defillama.com","type":"other","archive_url":"http://web.archive.org/web/20250913043438/https://defillama.com/protocol/wise-lending-v1","credibility":3,"archive_timestamp":"2025-09-13T04:34:38+00:00"},{"url":"https://coincodecap.com/wise-lending-faces-440k-loss-in-suspected-flash-loan-exploit-of-crypto-assets","name":"coincodecap.com","type":"other","archive_url":"http://web.archive.org/web/20251208215032/https://coincodecap.com/wise-lending-faces-440k-loss-in-suspected-flash-loan-exploit-of-crypto-assets","credibility":3,"archive_timestamp":"2025-12-08T21:50:32+00:00"},{"url":"https://www.cryptopolitan.com/wise-lending-loses-400000-flash-loan-attack/","name":"cryptopolitan.com","type":"other","archive_url":"http://web.archive.org/web/20260123235113/https://www.cryptopolitan.com/wise-lending-loses-400000-flash-loan-attack/","credibility":3,"archive_timestamp":"2026-01-23T23:51:13+00:00"},{"url":"https://cryptorank.io/news/feed/62124-wise-lending-loses-400000-flash-loan-attack","name":"cryptorank.io","type":"other","archive_url":"https://web.archive.org/web/20260829114041/https://cryptorank.io/news/feed/62124-wise-lending-loses-400000-flash-loan-attack","credibility":3,"archive_timestamp":"2026-08-29T11:40:41+00:00"},{"url":"https://cointelegraph.com/news/wise-lending-drained-440k-crypto-apparent-flash-loan-exploit","name":"cointelegraph.com","type":"other","archive_url":"http://web.archive.org/web/20260123143009/https://cointelegraph.com/news/wise-lending-drained-440k-crypto-apparent-flash-loan-exploit","credibility":3,"archive_timestamp":"2026-01-23T14:30:09+00:00"},{"url":"https://blog.solidityscan.com/wise-lending-hack-analysis-f652f389e397","name":"blog.solidityscan.com","type":"other","archive_url":"http://web.archive.org/web/20260419231740/https://blog.solidityscan.com/wise-lending-hack-analysis-f652f389e397/","credibility":3,"archive_timestamp":"2026-04-19T23:17:40+00:00"},{"url":"https://medium.com/@astrasec/wiselending-hack-root-cause-analysis-1a2762f52298","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.infect3d.xyz/blog/wise-lending-post-mortem","name":"infect3d.xyz","type":"other","archive_url":"http://web.archive.org/web/20260609144316/https://www.infect3d.xyz/blog/wise-lending-post-mortem","credibility":3,"archive_timestamp":"2026-06-09T14:43:16+00:00"},{"url":"https://blog.cobaltintelligence.com/post/wise-lending-suffers-464k-flash-loan-attack","name":"blog.cobaltintelligence.com","type":"other","archive_url":"http://web.archive.org/web/20260611171108/https://blog.cobaltintelligence.com/post/wise-lending-suffers-464k-flash-loan-attack","credibility":3,"archive_timestamp":"2026-06-11T17:11:08+00:00"},{"url":"https://coingape.com/just-in-defi-security-suffers-another-hit-with-wise-lending-hack/","name":"coingape.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://code4rena.com/reports/2024-02-wise-lending","name":"code4rena.com","type":"other","archive_url":"http://web.archive.org/web/20260308140210/https://code4rena.com/reports/2024-02-wise-lending","credibility":3,"archive_timestamp":"2026-03-08T14:02:10+00:00"},{"url":"https://code4rena.com/audits/2024-02-wise-lending","name":"code4rena.com","type":"other","archive_url":"http://web.archive.org/web/20260704121558/https://code4rena.com/audits/2024-02-wise-lending","credibility":3,"archive_timestamp":"2026-07-04T12:15:58+00:00"},{"url":"https://docs.wise.one/wise-references/100k_bug_bounty","name":"docs.wise.one","type":"other","archive_url":"http://web.archive.org/web/20260517034048/https://docs.wise.one/wise-references/100k_bug_bounty","credibility":3,"archive_timestamp":"2026-05-17T03:40:48+00:00"},{"url":"https://coinpaper.com/3049/major-incidents-from-last-week-wise-lending-exploit-and-xai-token-rug-pull","name":"coinpaper.com","type":"other","archive_url":"http://web.archive.org/web/20260417114912/https://coinpaper.com/3049/major-incidents-from-last-week-wise-lending-exploit-and-xai-token-rug-pull","credibility":3,"archive_timestamp":"2026-04-17T11:49:12+00:00"},{"url":"https://cointelegraph.com/news/wise-protocols-lose-38-9-m-jan-2024-exploits","name":"cointelegraph.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://beincrypto.com/avoid-crypto-scams-zachxbt-critical-checks/","name":"beincrypto.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://lightyagamicrypto.medium.com/who-is-peter-girr-50ab6f4db6ed","name":"lightyagamicrypto.medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:35.859367+00:00","updated_at":"2026-08-30T05:14:08.713253+00:00"}}