Skip to main content
AVOID.NET

Astrid Finance

avoid.net/astrid-finance38/100·72% conf.
[AI-DRAFTED · AWAITING VERIFICATION][src:defillama]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·AEGLxt…EkCB

Summary

Astrid Finance is an Ethereum-based liquid restaking protocol built on EigenLayer, allowing users to deposit liquid staking tokens (stETH, rETH, cbETH) in exchange for liquid restaked tokens. On October 28, 2023, the protocol suffered a smart contract exploit due to a missing input validation check in its withdraw function, resulting in the theft of approximately $228,000 in assets. The attacker eventually returned 80% of stolen funds after an on-chain negotiation and legal threat by the team; all affected users received refunds, and the vulnerable contracts remain paused pending re-audit.

Connected Entities

7 entities · 60 linked investigations
Relationships
  • Ethereummentioned withCoinbase(60%)
  • ZachXBTmentioned withEthereum(70%)
  • Rocket Poolmentioned withEthereum(80%)
  • Eigenlayermentioned withEthereum(70%)
  • Eigenlayermentioned withZachXBT(70%)
  • Astrid Financementioned withCoinbase(60%)
  • Polkadotmentioned withCoinbase(60%)
  • Astrid Financementioned withZachXBT(70%)
  • Polkadotmentioned withEthereum(65%)
  • Astrid Financementioned withPolkadot(70%)
  • + 4 more
Have evidence about Astrid Finance?

Timeline(7 events)

28 October 2023

Astrid Finance exploited on Ethereum Mainnet via missing input validation in withdraw function; approximately $228,000 in stETH, rETH, and cbETH drained by attacker at address 0x792ec27874e1f614e757a1ae49d00ef5b2c73959.

28 October 2023

Astrid Finance team detects exploit, pauses vulnerable contracts, and takes a snapshot of all token holders to facilitate future refunds.

28 October 2023

Team initially states the vulnerability originated from an auditor-recommended fix; retracts the statement approximately one hour later, attributing the flaw to a mutual oversight by both the team and the auditing firm.

29 October 2023

Team sends on-chain message to attacker offering a 20% bounty (approximately 25.6 ETH) to return the remaining 80% of stolen funds; deadline set for October 31, 2023 at 8:00 am UTC with threat of legal action.

30 October 2023

Attacker returns approximately 102 ETH (roughly $182,000) — the 80% share — ahead of the deadline. Team states the matter is 'settled amicably.'

31 October 2023

Team publishes full list of affected depositors and their refund amounts; confirms all user refunds processed. Remaining recovered funds moved to multisig wallet for re-audit and redevelopment.

November 2023

Astrid Finance announces plan to undergo multiple independent smart contract audits before any future mainnet relaunch; contracts remain paused.

Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event). 5 of 8 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 5/4/2026, 2:54:37 AM

last updated: 8/30/2026, 8:30:07 PM

6 views

avoid.net — verified advice for a post-truth world