Astrid Finance
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·AEGLxt…EkCBSummary
Astrid Finance is an Ethereum-based liquid restaking protocol built on EigenLayer, allowing users to deposit liquid staking tokens (stETH, rETH, cbETH) in exchange for liquid restaked tokens. On October 28, 2023, the protocol suffered a smart contract exploit due to a missing input validation check in its withdraw function, resulting in the theft of approximately $228,000 in assets. The attacker eventually returned 80% of stolen funds after an on-chain negotiation and legal threat by the team; all affected users received refunds, and the vulnerable contracts remain paused pending re-audit.
Connected Entities
7 entities · 60 linked investigations- Ethereum→mentioned with→Coinbase(60%)
- ZachXBT→mentioned with→Ethereum(70%)
- Rocket Pool→mentioned with→Ethereum(80%)
- Eigenlayer→mentioned with→Ethereum(70%)
- Eigenlayer→mentioned with→ZachXBT(70%)
- Astrid Finance→mentioned with→Coinbase(60%)
- Polkadot→mentioned with→Coinbase(60%)
- Astrid Finance→mentioned with→ZachXBT(70%)
- Polkadot→mentioned with→Ethereum(65%)
- Astrid Finance→mentioned with→Polkadot(70%)
- + 4 more
Timeline(7 events)
28 October 2023
Astrid Finance exploited on Ethereum Mainnet via missing input validation in withdraw function; approximately $228,000 in stETH, rETH, and cbETH drained by attacker at address 0x792ec27874e1f614e757a1ae49d00ef5b2c73959.
28 October 2023
Astrid Finance team detects exploit, pauses vulnerable contracts, and takes a snapshot of all token holders to facilitate future refunds.
28 October 2023
Team initially states the vulnerability originated from an auditor-recommended fix; retracts the statement approximately one hour later, attributing the flaw to a mutual oversight by both the team and the auditing firm.
29 October 2023
Team sends on-chain message to attacker offering a 20% bounty (approximately 25.6 ETH) to return the remaining 80% of stolen funds; deadline set for October 31, 2023 at 8:00 am UTC with threat of legal action.
30 October 2023
Attacker returns approximately 102 ETH (roughly $182,000) — the 80% share — ahead of the deadline. Team states the matter is 'settled amicably.'
31 October 2023
Team publishes full list of affected depositors and their refund amounts; confirms all user refunds processed. Remaining recovered funds moved to multisig wallet for re-audit and redevelopment.
November 2023
Astrid Finance announces plan to undergo multiple independent smart contract audits before any future mainnet relaunch; contracts remain paused.
Decision Log
- hash: 4SgrVWhSwFk1CstKzWejkYJtw2TaTSEUEhemAt7RafzM
This investigation is cryptographically anchored to the Solana blockchain (1 event). 5 of 8 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 5/4/2026, 2:54:37 AM
last updated: 8/30/2026, 8:30:07 PM
6 viewsavoid.net — verified advice for a post-truth world