Skip to main content
AVOID.NET
Carrot Protocolreviewed 2026-09-07 · 27 claims checked

Fact-check findings

What an automated fact-checker found when it re-read Carrot Protocol against the sources the page cites. Only the most recent review is shown.

Read this first

These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.

“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.

Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.

disputed 5unverifiable 2link rot 1confirmed 196 corrections pending · 0 applied

disputed

5 claims

The reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.

  1. #4[disputed][awaiting moderator]in section: Protocol Overview
    Carrot operated for more than two years before its closure.
    reviewerCarrot operated for more than two years before its closureNo citation was given for this claim. Independent company-data sources place Carrot Labs' founding in 2024, with its pre-seed round in September 2024, making an operating history of 'more than two years' by the April 2026 shutdown unlikely; more plausible is roughly one to two years.
    Proposed correction (not yet applied)
    Carrot operated for approximately one to two years before its closure.
  2. #5[disputed][awaiting moderator]in section: Protocol Overview
    No specific founding date, team names, or headquarters information was publicly disclosed in sources reviewed.
    reviewerNo founding date, team names, or headquarters information for Carrot was publicly disclosedThis information is publicly available via basic web/company-database search (Tracxn, Crunchbase, LinkedIn, crypto-fundraising.info) and was not a genuine research dead end.
    Proposed correction (not yet applied)
    The protocol was operated by Carrot Labs, Inc., a company founded in 2024 and headquartered in Austin, Texas, co-founded by Jack Rieck and James Blair, which raised a $600,000 pre-seed round in September 2024.
  3. #12[disputed][awaiting moderator]in section: The Drift Protocol Exploit (Root Cause)
    Elliptic assessed the operation matches the October 2024 Radiant Capital hack attributed by Mandiant to UNC4736 with medium-high confidence.
    reviewerElliptic assessed the operation matches the October 2024 Radiant Capital hack (UNC4736) with medium-high confidenceThe page's own timeline entry for 2026-04-05 correctly attributes this specific assessment to Drift Protocol; this sentence in the section body misattributes it to Elliptic.
    Proposed correction (not yet applied)
    Drift Protocol, supported by the SEAL 911 investigation team, assessed with medium-high confidence that the operation matches the October 2024 Radiant Capital hack attributed by Mandiant to UNC4736.
  4. #24[disputed][awaiting moderator]in section: Broader DeFi Contagion and Downstream Protocol Impact
    The Drift exploit ($285 million) and the Kelp DAO exploit, together, accounted for more than 90% of all crypto stolen in April 2026.
    reviewerThe Drift exploit ($285M) and the Kelp DAO exploit together accounted for more than 90% of all crypto stolen in April 2026The only independent reporting found that quantifies this combined percentage puts it at 82%, not over 90%. No source was cited by the page for this specific figure.
    Proposed correction (not yet applied)
    The Drift exploit ($285 million) and the Kelp DAO exploit, together, accounted for approximately 82% of all crypto stolen in April 2026.
  5. #25[disputed][awaiting moderator]in section: Security Audits and Pre-Shutdown Risk Profile
    No publicly available audit reports or specific audit findings were located during this investigation.
    reviewerNo publicly available audit reports or specific audit findings for Carrot were locatedThe audits page is a direct subpage of the official documentation already cited elsewhere in the page (docs.deficarrot.com/), making this an easily discoverable gap rather than a genuine absence of public information.
    Proposed correction (not yet applied)
    Audit reports from Sec3, MadShield, and Adevar Labs (for the Carrot Lend vault contracts) are publicly available and linked from the protocol's documentation site.

unverifiable

2 claims

No source the reviewer could reach confirms or contradicts the claim.

  1. #11[unverifiable][awaiting moderator]in section: The Drift Protocol Exploit (Root Cause)
    Attackers then whitelisted CVT as collateral with effectively unlimited borrowing limits, deposited 500 million CVT, and systematically withdrew real assets including USDC ($71.4 million), JLP ($159.3 million), and cbBTC ($11.3 million) across 31 transactions in approximately 12 minutes.
    reviewerAttackers deposited 500 million CVT and withdrew USDC ($71.4M), JLP ($159.3M), and cbBTC ($11.3M) across 31 transactions in ~12 minutesThe transaction count (31) and duration (~12 minutes) are independently confirmed. The precise per-asset dollar breakdown ($71.4M USDC / $159.3M JLP / $11.3M cbBTC) and the exact '500 million CVT' figure could not be located in any tier-1 source consulted; JLP loss estimates in primary sources cluster closer to $155M.
  2. #19[unverifiable][awaiting moderator]in section: TVL Collapse and Financial Impact on Carrot
    At the time of the shutdown announcement, DefiLlama recorded Carrot's TVL at approximately $1.82 million with active loans of approximately $690,000 and CRT token liquidity of approximately $104,000 split between Orca DEX ($65,000) and Raydium AMM ($39,000).
    reviewerAt shutdown, DefiLlama recorded Carrot's TVL at ~$1.82M with active loans of ~$690,000 and CRT DEX liquidity of ~$104,000 (Orca $65K / Raydium $39K)Could not independently verify this granular breakdown; the specific archived snapshot cited elsewhere in the page's own source list for this URL predates the events described by about seven months.

confirmed

19 claims

The cited evidence supports the claim as written.

  1. #1[confirmed][no action needed]in the summary
    On April 30, 2026, the protocol announced a permanent shutdown after its total value locked collapsed 93% — from approximately $28 million to under $2 million — as a downstream casualty of the $285 million Drift Protocol exploit on April 1, 2026.
    reviewerCarrot's TVL collapsed 93%, from ~$28M to under $2M, as a downstream casualty of the April 1, 2026 Drift Protocol exploitMultiple independent sources (CoinTelegraph, CryptoTimes, KuCoin) corroborate the $28M to $1.99M / 93% figures used by the page. One syndicated outlet reported different numbers ($11.4M/$1.18M), but it is an outlier against the weight of other reporting.
  2. #2[confirmed][no action needed]in the summary
    Carrot was not directly hacked; its failure resulted from deep liquidity dependencies on Drift's infrastructure, making it the first confirmed DeFi protocol to shut down as a result of the Drift exploit contagion.
    reviewerCarrot was the first confirmed DeFi protocol to shut down as a result of the Drift exploit contagionWidely and consistently reported across independent outlets as the first DeFi protocol to permanently close due to Drift contagion, with no directly attributed exploit of Carrot's own contracts.
  3. #3[confirmed][no action needed]in section: Protocol Overview
    According to its documentation, Carrot was audited by Sec3 and MadShield and charged zero management fees across all products.
    reviewerCarrot offered CRT, Boost and Turbo products, was audited by Sec3 and MadShield, and charged zero management feesDirectly confirmed by the protocol's own documentation.
  4. #6[confirmed][no action needed]in section: The Drift Protocol Exploit (Root Cause)
    The attack was the largest DeFi hack of 2026 and the second-largest security incident in Solana's history, behind only the $326 million Wormhole bridge exploit of 2022.
    reviewerDrift Protocol was exploited for ~$285-286M on April 1, 2026, the largest DeFi hack of 2026 and second-largest Solana security incident behind the $326M Wormhole exploit of 2022Well corroborated across tier-1 and tier-2 sources.
  5. #7[confirmed][no action needed]in section: The Drift Protocol Exploit (Root Cause)
    Beginning in the fall of 2025, threat actors posing as a legitimate quantitative trading firm built relationships with Drift contributors, depositing over $1 million to establish credibility.
    reviewerThreat actors began a social engineering campaign in fall 2025, depositing over $1 million to build credibility with Drift contributorsDirectly confirmed by the cited Chainalysis source.
  6. #8[confirmed][no action needed]in section: The Drift Protocol Exploit (Root Cause)
    On March 26, Drift migrated to a 2-of-5 threshold Security Council multisig configuration with a zero timelock, eliminating the intervention window needed for detection.
    reviewerBetween March 23-30, 2026 attackers induced pre-signing of dormant transactions via durable nonces; on March 26 Drift migrated to a 2-of-5 multisig with zero timelockConfirmed by both cited tier-1 sources.
  7. #9[confirmed][no action needed]in section: The Drift Protocol Exploit (Root Cause)
    On March 12, attackers created a fabricated asset called CarbonVote Token (CVT), seeded a small liquidity pool, and wash-traded it to anchor its price at approximately $1, then deployed a controlled price oracle feeding that artificial valuation to Drift's system.
    reviewerOn March 12, attackers created a fabricated CarbonVote Token (CVT), seeded a pool, and wash-traded it to anchor its price at ~$1Confirmed.
  8. #10[confirmed][no action needed]in section: The Drift Protocol Exploit (Root Cause)
    At approximately 16:05 UTC on April 1, two transactions executed one second apart transferred administrative control to attacker-controlled addresses.
    reviewerAt approximately 16:05 UTC on April 1, two transactions executed one second apart transferred admin control to attacker addressesConfirmed by an independent technical post-mortem, not just the page's own cited sources.
  9. #13[confirmed][no action needed]in section: The Drift Protocol Exploit (Root Cause)
    TRM Labs identified indicators consistent with DPRK tradecraft including initial funding withdrawn from Tornado Cash on March 11, timing patterns aligned with the Pyongyang timezone, and attack sophistication consistent with state-sponsored operations.
    reviewerTRM Labs identified DPRK tradecraft indicators including Tornado Cash withdrawal on March 11 and Pyongyang timezone patternsDirectly confirmed.
  10. #14[confirmed][no action needed]in section: The Drift Protocol Exploit (Root Cause)
    Chainalysis noted the attack illustrates that 'the greatest risks are no longer just in smart contracts, but in the systems, and people, that surround them.'
    reviewerChainalysis stated the attack shows risks are 'no longer just in smart contracts, but in the systems, and people, that surround them'Verbatim quote match.
  11. #15[confirmed][no action needed]in section: TVL Collapse and Financial Impact on Carrot
    Carrot Protocol's total value locked stood at approximately $28 million immediately before the April 1, 2026 Drift exploit.
    reviewerCarrot's TVL was ~$28 million immediately before the April 1, 2026 Drift exploitConfirmed across multiple outlets.
  12. #16[confirmed][no action needed]in section: TVL Collapse and Financial Impact on Carrot
    By the time the shutdown was announced on April 30, TVL had declined to approximately $1.99 million — a collapse of roughly 93% in one month.
    reviewerBy April 30 shutdown, TVL had declined to ~$1.99 million, a ~93% collapse in one monthConfirmed.
  13. #17[confirmed][no action needed]in section: TVL Collapse and Financial Impact on Carrot
    The direct financial impairment to Carrot from Drift exposure is reported at approximately $8 million.
    reviewerDirect financial impairment to Carrot from Drift exposure is reported at approximately $8 millionConfirmed directly by cited source, whose headline centers on this figure.
  14. #18[confirmed][no action needed]in section: TVL Collapse and Financial Impact on Carrot
    The CRT token's net asset value dropped to approximately $57.52 to $57.58 per unit by mid-April, reflecting the losses absorbed within the CRT vault strategy.
    reviewerCRT token NAV dropped to approximately $57.52-$57.58 per unit by mid-AprilConfirmed.
  15. #20[confirmed][no action needed]in section: Permanent Shutdown and Wind-Down Mechanics
    The team's official statement read: 'Carrot is shutting down. This is certainly not the outcome we wanted, but the situation with the Drift exploit has proven to be catastrophic for our continued operations.'
    reviewerCarrot announced permanent closure on April 30, 2026, with official quote about the shutdownQuote verified verbatim against an independent source.
  16. #21[confirmed][no action needed]in section: Permanent Shutdown and Wind-Down Mechanics
    The protocol established May 14, 2026 as the final deadline for voluntary user withdrawals from all three products: Boost, Turbo, and CRT.
    reviewerMay 14, 2026 was the final deadline for voluntary user withdrawals from Boost, Turbo, and CRTConfirmed.
  17. #22[confirmed][no action needed]in section: Broader DeFi Contagion and Downstream Protocol Impact
    Early reports identified 11 protocols with immediate disruptions; that number grew to at least 20 as further integrations were uncovered.
    reviewer11 protocols initially identified as affected by the Drift exploit, growing to at least 20; Ranger Finance lost ~$900K (6% of TVL), Gauntlet ~$6.4M, Prime Numbers Fi >$10MConfirmed with only minor (sub-10%) variance on Ranger Finance's exact loss figure across sources.
  18. #23[confirmed][no action needed]in section: Broader DeFi Contagion and Downstream Protocol Impact
    April 2026 was the worst month for DeFi losses since February 2025, with approximately $630 million stolen across 25 separate incidents.
    reviewerApril 2026 was the worst month for DeFi losses since February 2025, with ~$630 million stolen across 25 separate incidentsConfirmed via independent research, though the page cites no specific source for this particular claim.
  19. #26[confirmed][no action needed]in the timeline
    Drift Protocol states with medium-high confidence that the attack matches the profile of UNC4736, a North Korean state-affiliated hacking group previously attributed to the October 2024 Radiant Capital hack
    reviewerOn April 5, 2026 Drift Protocol stated with medium-high confidence the attack matched the UNC4736/Radiant Capital profileThis timeline entry correctly attributes the assessment to Drift Protocol, unlike the corresponding sentence in sections[1].content which misattributes it to Elliptic (see separate finding).
How this fits together. The reviewer reads the published page and its cited sources and records one finding per claim. A human moderator decides whether each proposed correction is applied; those decisions, and the score changes they cause, appear in the audit log. Earlier review runs are not shown here; only the latest reflects the page as it stands.