Skip to main content
Sign in
Dango3 decisions on this page

Audit log

Every state-changing event for Dango: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions carry three independent witnesses — the original source, an Internet Archive snapshot taken at submission time, and a Solana memo signed by our publicly-disclosed publisher key.

  1. #1publishby system:backfill
    2026-05-29 02:41:07Z
    Score: ?? (no score change)
    anchoranchored
    chain
    mainnet-betaslot 422,849,389
    sig
    25PcWsTVkC8G…bEDxPCSnexplorer ↗
    hash
    Az8MigwhMtFm…7Cuny7F5sha256 → base58
    verifying row…full verify ↗
    canonical bytes (4595 B) ▸
    {"actor":"system:backfill","investigation_id":"79a41b54-63cf-4342-8c1b-516bf780f51d","kind":"publish","page_slug":"dango","published_at":"2026-05-29T02:41:07.170Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Dango","sections":[{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://grug.build/dango.html","type":"other","url":""},{"credibility":3,"name":"https://docs.dango.exchange/","type":"other","url":""},{"credibility":3,"name":"https://simplystaking.com/introduction-to-dango","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://www.gate.com/crypto-calendar/fundraising-information/106164","type":"other","url":""},{"credibility":3,"name":"https://web3.bitget.com/en/dapp/dango-24707","type":"other","url":""},{"credibility":3,"name":"https://www.rootdata.com/projects/detail/Dango?k=MTUyMTU%3D","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://phemex.com/news/article/dango-defi-platform-suffers-410010-usdc-exploit-due-to-logic-flaw-72936","type":"other","url":""},{"credibility":3,"name":"https://www.cryptointegrat.com/p/dango-perps-protocol-exploited-for","type":"other","url":""},{"credibility":3,"name":"https://ourcryptotalk.com/news/dango-perp-dex-exploit-insurance-fund-bug","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://www.mexc.com/news/1024306","type":"other","url":""},{"credibility":3,"name":"https://www.kucoin.com/news/flash/dango-resolves-exploit-after-white-hat-returns-funds-users-unaffected","type":"other","url":""},{"credibility":3,"name":"https://www.panewslab.com/en/articles/019d898e-f42a-739c-ab2a-3e26b912bbdf","type":"other","url":""},{"credibility":3,"name":"https://www.binance.com/en/square/post/312271750832898","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://www.cryptointegrat.com/p/dango-perps-protocol-exploited-for","type":"other","url":""},{"credibility":3,"name":"https://ourcryptotalk.com/news/dango-perp-dex-exploit-insurance-fund-bug","type":"other","url":""},{"credibility":3,"name":"https://phemex.com/news/article/dango-defi-platform-suffers-410010-usdc-exploit-due-to-logic-flaw-72936","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://web3.bitget.com/en/dapp/dango-24707","type":"other","url":""},{"credibility":3,"name":"https://airdrops.io/dango/","type":"other","url":""},{"credibility":3,"name":"https://coinlaunch.space/events-contests/dango-exchange-retrodrop/","type":"other","url":""}]}],"sources_used":[],"summary":"Dango (ticker: DNG) is a DeFi-native Layer-1 blockchain and perpetual futures exchange that raised $3.6 million in seed funding in November 2024 from Hack VC, Lemniscap, and Delphi Labs. On April 13, 2026, the protocol suffered a logic flaw exploit in its insurance fund donation contract, resulting in $1.9 million USDC being drained; approximately $410,010 was bridged to Ethereum before bridge rate limits halted further outflows. The attacker was identified as a white hat who returned all funds in exchange for a bug bounty, leaving user positions and trading functions unaffected.","timeline":[{"date":"2024-11-16","event":"Dango closes $3.6 million seed funding round led by Hack VC and Lemniscap, with participation from Delphi Labs, Public Works, Cherry Crypto, and Interop.","source":""},{"date":"2025-01-01","event":"Dango testnet 2.0 airdrop campaign opens; users begin accumulating points through trading and vault deposits across weekly epochs.","source":""},{"date":"2026-04-13","event":"Attacker exploits a sign-error logic flaw in Dango's insurance fund donation contract, draining approximately $1.9 million USDC from the perpetual futures collateral pool. $410,010 USDC is bridged to Ethereum before bridge rate limits halt further outflows. Dango pauses its chain and engages SEAL-911.","source":""},{"date":"2026-04-14","event":"Dango confirms the attacker self-identified as a white hat and agreed to return all funds in exchange for a bug bounty. Full $1.9 million USDC is returned. Team announces user funds were unaffected and no trading positions were impacted.","source":""},{"date":"2026-04-15","event":"Dango resumes points farming campaign and announces additional security reviews and removal of the vulnerable donation logic prior to full relaunch.","source":""}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision a2f70e8b-26d1-48be-8b3e-dc76bbd87701
  2. #2reviewby reviewerreviewer
    2026-06-10 00:07:42Z
    Score: 5252 (no score change)
    The Dango investigation page's core factual claims — the $3.6M seed round, the April 13 2026 exploit mechanics ($1.9M USDC via insurance fund sign error), the $410,010 bridged to Ethereum, chain pause with SEAL-911 engagement, and white hat fund return — are all confirmed by multiple independent sources. Three claims are only partially supported: the specific investor entity name (Delphi Labs vs. Delphi Ventures, minor), the January 2025 testnet 2.0 campaign start date (evidence suggests a later launch), and the specific April 15 resume date post-exploit. The most significant structural issue is that all six section content fields are empty, leaving 12 cited URLs unanchored to any visible claim text.
    anchoranchored
    chain
    mainnet-betaslot 425,433,443
    sig
    545NFULu9PCN…C5AZHnEcexplorer ↗
    hash
    BjrVkwJrWKqP…z9Bu2L4zsha256 → base58
    verifying row…full verify ↗
    canonical bytes (1050 B) ▸
    {"actor":"reviewer","decided_at":"2026-06-10T00:07:42.617Z","decision":"review","investigation_id":"79a41b54-63cf-4342-8c1b-516bf780f51d","new_score":52,"page_slug":"dango","prev_score":52,"reason":"The Dango investigation page's core factual claims — the $3.6M seed round, the April 13 2026 exploit mechanics ($1.9M USDC via insurance fund sign error), the $410,010 bridged to Ethereum, chain pause with SEAL-911 engagement, and white hat fund return — are all confirmed by multiple independent sources. Three claims are only partially supported: the specific investor entity name (Delphi Labs vs. Delphi Ventures, minor), the January 2025 testnet 2.0 campaign start date (evidence suggests a later launch), and the specific April 15 resume date post-exploit. The most significant structural issue is that all six section content fields are empty, leaving 12 cited URLs unanchored to any visible claim text.","score_delta":0,"sequence_num":2,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision a11eec3b-6c1d-45ee-8978-c98467f87ef7
  3. #3review approveby judgejudge
    2026-06-10 00:07:42Z
    Score: 5252 (no score change)
    All 12 claims reviewed returned zero disputed findings. Nine claims are fully confirmed by multiple independent sources; three are partially supported but involve only minor imprecision — an investor entity name variant (Delphi Labs vs. Delphi Ventures, claim_findings[2]), an uncertain campaign start date (claim_findings[10]), and an unverified specific post-exploit resume date (claim_findings[11]). The core factual record — the $3.6M seed round, the April 13 2026 sign-error exploit draining $1.9M USDC, the $410,010 bridged to Ethereum, chain pause with SEAL-911 engagement, and white hat full fund return — is confirmed across multiple credible sources. Three high-priority coverage gaps (missing on-chain transaction hashes, no official team postmortem, and empty section content fields) indicate the page needs substantive expansion but do not constitute factual failures warranting revision or denial.
    anchoranchored
    chain
    mainnet-betaslot 425,433,450
    sig
    4WmL9Gi1kxtA…XhGcWACjexplorer ↗
    hash
    DikWDRN2VJVX…zixHdoJ6sha256 → base58
    verifying row…full verify ↗
    canonical bytes (1257 B) ▸
    {"actor":"judge","decided_at":"2026-06-10T00:07:42.617Z","decision":"review_approve","investigation_id":"79a41b54-63cf-4342-8c1b-516bf780f51d","new_score":52,"page_slug":"dango","prev_score":52,"reason":"All 12 claims reviewed returned zero disputed findings. Nine claims are fully confirmed by multiple independent sources; three are partially supported but involve only minor imprecision — an investor entity name variant (Delphi Labs vs. Delphi Ventures, claim_findings[2]), an uncertain campaign start date (claim_findings[10]), and an unverified specific post-exploit resume date (claim_findings[11]). The core factual record — the $3.6M seed round, the April 13 2026 sign-error exploit draining $1.9M USDC, the $410,010 bridged to Ethereum, chain pause with SEAL-911 engagement, and white hat full fund return — is confirmed across multiple credible sources. Three high-priority coverage gaps (missing on-chain transaction hashes, no official team postmortem, and empty section content fields) indicate the page needs substantive expansion but do not constitute factual failures warranting revision or denial.","score_delta":0,"sequence_num":3,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision b30befbe-62d9-4263-aebf-37bf025f024b
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.