Fact-check findings
What an automated fact-checker found when it re-read Carrot Protocol against the sources the page cites. Only the most recent review is shown.
These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.
“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.
Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.
disputed
5 claimsThe reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.
- #4[disputed][awaiting moderator]in section: Protocol Overview
“Carrot operated for more than two years before its closure.”
reviewerCarrot operated for more than two years before its closureNo citation was given for this claim. Independent company-data sources place Carrot Labs' founding in 2024, with its pre-seed round in September 2024, making an operating history of 'more than two years' by the April 2026 shutdown unlikely; more plausible is roughly one to two years.Proposed correction (not yet applied)Carrot operated for approximately one to two years before its closure. - #5[disputed][awaiting moderator]in section: Protocol Overview
“No specific founding date, team names, or headquarters information was publicly disclosed in sources reviewed.”
reviewerNo founding date, team names, or headquarters information for Carrot was publicly disclosedThis information is publicly available via basic web/company-database search (Tracxn, Crunchbase, LinkedIn, crypto-fundraising.info) and was not a genuine research dead end.Proposed correction (not yet applied)The protocol was operated by Carrot Labs, Inc., a company founded in 2024 and headquartered in Austin, Texas, co-founded by Jack Rieck and James Blair, which raised a $600,000 pre-seed round in September 2024. - #12[disputed][awaiting moderator]in section: The Drift Protocol Exploit (Root Cause)
“Elliptic assessed the operation matches the October 2024 Radiant Capital hack attributed by Mandiant to UNC4736 with medium-high confidence.”
reviewerElliptic assessed the operation matches the October 2024 Radiant Capital hack (UNC4736) with medium-high confidenceThe page's own timeline entry for 2026-04-05 correctly attributes this specific assessment to Drift Protocol; this sentence in the section body misattributes it to Elliptic.Proposed correction (not yet applied)Drift Protocol, supported by the SEAL 911 investigation team, assessed with medium-high confidence that the operation matches the October 2024 Radiant Capital hack attributed by Mandiant to UNC4736. - #24[disputed][awaiting moderator]in section: Broader DeFi Contagion and Downstream Protocol Impact
“The Drift exploit ($285 million) and the Kelp DAO exploit, together, accounted for more than 90% of all crypto stolen in April 2026.”
reviewerThe Drift exploit ($285M) and the Kelp DAO exploit together accounted for more than 90% of all crypto stolen in April 2026The only independent reporting found that quantifies this combined percentage puts it at 82%, not over 90%. No source was cited by the page for this specific figure.Proposed correction (not yet applied)The Drift exploit ($285 million) and the Kelp DAO exploit, together, accounted for approximately 82% of all crypto stolen in April 2026. - #25[disputed][awaiting moderator]in section: Security Audits and Pre-Shutdown Risk Profile
“No publicly available audit reports or specific audit findings were located during this investigation.”
reviewerNo publicly available audit reports or specific audit findings for Carrot were locatedThe audits page is a direct subpage of the official documentation already cited elsewhere in the page (docs.deficarrot.com/), making this an easily discoverable gap rather than a genuine absence of public information.Proposed correction (not yet applied)Audit reports from Sec3, MadShield, and Adevar Labs (for the Carrot Lend vault contracts) are publicly available and linked from the protocol's documentation site.citeddocs.deficarrot.com/
unverifiable
2 claimsNo source the reviewer could reach confirms or contradicts the claim.
- #11[unverifiable][awaiting moderator]in section: The Drift Protocol Exploit (Root Cause)
“Attackers then whitelisted CVT as collateral with effectively unlimited borrowing limits, deposited 500 million CVT, and systematically withdrew real assets including USDC ($71.4 million), JLP ($159.3 million), and cbBTC ($11.3 million) across 31 transactions in approximately 12 minutes.”
reviewerAttackers deposited 500 million CVT and withdrew USDC ($71.4M), JLP ($159.3M), and cbBTC ($11.3M) across 31 transactions in ~12 minutesThe transaction count (31) and duration (~12 minutes) are independently confirmed. The precise per-asset dollar breakdown ($71.4M USDC / $159.3M JLP / $11.3M cbBTC) and the exact '500 million CVT' figure could not be located in any tier-1 source consulted; JLP loss estimates in primary sources cluster closer to $155M. - #19[unverifiable][awaiting moderator]in section: TVL Collapse and Financial Impact on Carrot
“At the time of the shutdown announcement, DefiLlama recorded Carrot's TVL at approximately $1.82 million with active loans of approximately $690,000 and CRT token liquidity of approximately $104,000 split between Orca DEX ($65,000) and Raydium AMM ($39,000).”
reviewerAt shutdown, DefiLlama recorded Carrot's TVL at ~$1.82M with active loans of ~$690,000 and CRT DEX liquidity of ~$104,000 (Orca $65K / Raydium $39K)Could not independently verify this granular breakdown; the specific archived snapshot cited elsewhere in the page's own source list for this URL predates the events described by about seven months.
link rot
1 claimA cited source no longer resolves or no longer says what the page attributes to it.
- #27[link rot][awaiting moderator]in the cited sources
“http://web.archive.org/web/20250910075818/https://defillama.com/protocol/carrot”
reviewerDefiLlama TVL dashboard for Carrot supports the TVL figures cited in the TVL Collapse sectionThe archived copy of this source predates the events it is cited to support by roughly seven months and cannot verify the TVL/loan/liquidity figures in the TVL Collapse and Financial Impact section. A fresh, dated archive capture of the live DefiLlama page (or a capture close to April-May 2026) is needed.
confirmed
19 claimsThe cited evidence supports the claim as written.
- #1[confirmed][no action needed]in the summary
“On April 30, 2026, the protocol announced a permanent shutdown after its total value locked collapsed 93% — from approximately $28 million to under $2 million — as a downstream casualty of the $285 million Drift Protocol exploit on April 1, 2026.”
reviewerCarrot's TVL collapsed 93%, from ~$28M to under $2M, as a downstream casualty of the April 1, 2026 Drift Protocol exploitMultiple independent sources (CoinTelegraph, CryptoTimes, KuCoin) corroborate the $28M to $1.99M / 93% figures used by the page. One syndicated outlet reported different numbers ($11.4M/$1.18M), but it is an outlier against the weight of other reporting. - #2[confirmed][no action needed]in the summary
“Carrot was not directly hacked; its failure resulted from deep liquidity dependencies on Drift's infrastructure, making it the first confirmed DeFi protocol to shut down as a result of the Drift exploit contagion.”
reviewerCarrot was the first confirmed DeFi protocol to shut down as a result of the Drift exploit contagionWidely and consistently reported across independent outlets as the first DeFi protocol to permanently close due to Drift contagion, with no directly attributed exploit of Carrot's own contracts. - #3[confirmed][no action needed]in section: Protocol Overview
“According to its documentation, Carrot was audited by Sec3 and MadShield and charged zero management fees across all products.”
reviewerCarrot offered CRT, Boost and Turbo products, was audited by Sec3 and MadShield, and charged zero management feesDirectly confirmed by the protocol's own documentation.citeddocs.deficarrot.com/ - #6[confirmed][no action needed]in section: The Drift Protocol Exploit (Root Cause)
“The attack was the largest DeFi hack of 2026 and the second-largest security incident in Solana's history, behind only the $326 million Wormhole bridge exploit of 2022.”
reviewerDrift Protocol was exploited for ~$285-286M on April 1, 2026, the largest DeFi hack of 2026 and second-largest Solana security incident behind the $326M Wormhole exploit of 2022Well corroborated across tier-1 and tier-2 sources. - #7[confirmed][no action needed]in section: The Drift Protocol Exploit (Root Cause)
“Beginning in the fall of 2025, threat actors posing as a legitimate quantitative trading firm built relationships with Drift contributors, depositing over $1 million to establish credibility.”
reviewerThreat actors began a social engineering campaign in fall 2025, depositing over $1 million to build credibility with Drift contributorsDirectly confirmed by the cited Chainalysis source. - #8[confirmed][no action needed]in section: The Drift Protocol Exploit (Root Cause)
“On March 26, Drift migrated to a 2-of-5 threshold Security Council multisig configuration with a zero timelock, eliminating the intervention window needed for detection.”
reviewerBetween March 23-30, 2026 attackers induced pre-signing of dormant transactions via durable nonces; on March 26 Drift migrated to a 2-of-5 multisig with zero timelockConfirmed by both cited tier-1 sources. - #9[confirmed][no action needed]in section: The Drift Protocol Exploit (Root Cause)
“On March 12, attackers created a fabricated asset called CarbonVote Token (CVT), seeded a small liquidity pool, and wash-traded it to anchor its price at approximately $1, then deployed a controlled price oracle feeding that artificial valuation to Drift's system.”
reviewerOn March 12, attackers created a fabricated CarbonVote Token (CVT), seeded a pool, and wash-traded it to anchor its price at ~$1Confirmed. - #10[confirmed][no action needed]in section: The Drift Protocol Exploit (Root Cause)
“At approximately 16:05 UTC on April 1, two transactions executed one second apart transferred administrative control to attacker-controlled addresses.”
reviewerAt approximately 16:05 UTC on April 1, two transactions executed one second apart transferred admin control to attacker addressesConfirmed by an independent technical post-mortem, not just the page's own cited sources. - #13[confirmed][no action needed]in section: The Drift Protocol Exploit (Root Cause)
“TRM Labs identified indicators consistent with DPRK tradecraft including initial funding withdrawn from Tornado Cash on March 11, timing patterns aligned with the Pyongyang timezone, and attack sophistication consistent with state-sponsored operations.”
reviewerTRM Labs identified DPRK tradecraft indicators including Tornado Cash withdrawal on March 11 and Pyongyang timezone patternsDirectly confirmed. - #14[confirmed][no action needed]in section: The Drift Protocol Exploit (Root Cause)
“Chainalysis noted the attack illustrates that 'the greatest risks are no longer just in smart contracts, but in the systems, and people, that surround them.'”
reviewerChainalysis stated the attack shows risks are 'no longer just in smart contracts, but in the systems, and people, that surround them'Verbatim quote match. - #15[confirmed][no action needed]in section: TVL Collapse and Financial Impact on Carrot
“Carrot Protocol's total value locked stood at approximately $28 million immediately before the April 1, 2026 Drift exploit.”
reviewerCarrot's TVL was ~$28 million immediately before the April 1, 2026 Drift exploitConfirmed across multiple outlets. - #16[confirmed][no action needed]in section: TVL Collapse and Financial Impact on Carrot
“By the time the shutdown was announced on April 30, TVL had declined to approximately $1.99 million — a collapse of roughly 93% in one month.”
reviewerBy April 30 shutdown, TVL had declined to ~$1.99 million, a ~93% collapse in one monthConfirmed. - #17[confirmed][no action needed]in section: TVL Collapse and Financial Impact on Carrot
“The direct financial impairment to Carrot from Drift exposure is reported at approximately $8 million.”
reviewerDirect financial impairment to Carrot from Drift exposure is reported at approximately $8 millionConfirmed directly by cited source, whose headline centers on this figure. - #18[confirmed][no action needed]in section: TVL Collapse and Financial Impact on Carrot
“The CRT token's net asset value dropped to approximately $57.52 to $57.58 per unit by mid-April, reflecting the losses absorbed within the CRT vault strategy.”
reviewerCRT token NAV dropped to approximately $57.52-$57.58 per unit by mid-AprilConfirmed. - #20[confirmed][no action needed]in section: Permanent Shutdown and Wind-Down Mechanics
“The team's official statement read: 'Carrot is shutting down. This is certainly not the outcome we wanted, but the situation with the Drift exploit has proven to be catastrophic for our continued operations.'”
reviewerCarrot announced permanent closure on April 30, 2026, with official quote about the shutdownQuote verified verbatim against an independent source. - #21[confirmed][no action needed]in section: Permanent Shutdown and Wind-Down Mechanics
“The protocol established May 14, 2026 as the final deadline for voluntary user withdrawals from all three products: Boost, Turbo, and CRT.”
reviewerMay 14, 2026 was the final deadline for voluntary user withdrawals from Boost, Turbo, and CRTConfirmed. - #22[confirmed][no action needed]in section: Broader DeFi Contagion and Downstream Protocol Impact
“Early reports identified 11 protocols with immediate disruptions; that number grew to at least 20 as further integrations were uncovered.”
reviewer11 protocols initially identified as affected by the Drift exploit, growing to at least 20; Ranger Finance lost ~$900K (6% of TVL), Gauntlet ~$6.4M, Prime Numbers Fi >$10MConfirmed with only minor (sub-10%) variance on Ranger Finance's exact loss figure across sources. - #23[confirmed][no action needed]in section: Broader DeFi Contagion and Downstream Protocol Impact
“April 2026 was the worst month for DeFi losses since February 2025, with approximately $630 million stolen across 25 separate incidents.”
reviewerApril 2026 was the worst month for DeFi losses since February 2025, with ~$630 million stolen across 25 separate incidentsConfirmed via independent research, though the page cites no specific source for this particular claim. - #26[confirmed][no action needed]in the timeline
“Drift Protocol states with medium-high confidence that the attack matches the profile of UNC4736, a North Korean state-affiliated hacking group previously attributed to the October 2024 Radiant Capital hack”
reviewerOn April 5, 2026 Drift Protocol stated with medium-high confidence the attack matched the UNC4736/Radiant Capital profileThis timeline entry correctly attributes the assessment to Drift Protocol, unlike the corresponding sentence in sections[1].content which misattributes it to Elliptic (see separate finding).