DeFiTuna
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·4ftQ8Q…wcshSummary
DeFiTuna is a Solana-native concentrated liquidity market maker (CLMM) and lending protocol that was exploited on July 16, 2026, for approximately $569,601–$580,000 USDC. Attackers bypassed the protocol's solvency check by exploiting an integer rounding vulnerability in its position value calculation, then laundered stolen funds via the Mayan bridge to Ethereum and into the Railgun privacy mixer. As of late July 2026, no formal post-mortem had been published, no depositor reimbursement plan had been announced, and a meaningful portion of the stolen funds remained untraceable.
Connected Entities
5 entities · 10 linked investigations- 9ytGWP8tCRF1keREJ5VHqBpSuM9MZYwm3oFQQa1SvESb→mentioned with→DeFiTuna(50%)
- BK9aTnKfPNnnj45Me5ACrky2vexzUrZHRzr4BjmQpH3c→mentioned with→DeFiTuna(50%)
- 917DKTphW3rhBG5gsJpwKsNGisNV2dx74uUFd8HBEjtg→mentioned with→DeFiTuna(50%)
- 7hiHL8AgDuLNVDQLfN3GHdLAEeCN1F7uz6nSANRvFJst→mentioned with→DeFiTuna(50%)
- + 1 more
Community submissions
- Under reviewincriminatingWayback pending7/30/2026, 10:08:04 PM
“CertiK's incident analysis provides technical confirmation of the solvency-check bypass via illiquid pool manipulation; $580K drained July 16 from Solana-based DeFiTuna”
— avoid-scout
Timeline(8 events)
14 March 2025
Sec3 begins security audit of DeFiTuna smart contracts at commit 7ced6e0b11d1bcd4126fdc2fd2592dc52f6868b7.
DefiTuna — Sec3 Security Audit Report17 March 2025
Sec3 security audit completed; DeFiTuna states no critical issues remain unresolved. Audit scope reportedly did not cover later modifications to lending contracts.
DefiTuna — Sec3 Security Audit Report16 July 2026
Exploit executed at 05:48:12 UTC in a single Solana transaction. Attackers create illiquid TUNA/USDC pool, borrow 569,601 USDC through the lending pool, route it via Jupiter swap, exploit integer rounding in solvency check to bypass is_healthy(), and withdraw funds via DecreaseLimitOrder calls. Approximately $569,601–$580,000 USDC stolen from the USDC lending pool.
DefiTuna Incident Analysis — CertiK16 July 2026
Stolen USDC bridged from Solana to Ethereum via Mayan Finance. Approximately 140 ETH deposited into Railgun privacy mixer on Ethereum.
DefiTuna Incident Analysis — CertiK17 July 2026
DeFiTuna publicly discloses the exploit via social media, stating the exploit pathway has been closed and recovery efforts are underway. Incident reported by CryptoTimes and Phemex News.
Solana's DeFiTuna Hit by $580K Exploit, USDC Pool Left Short — CryptoTimes18 July 2026
Incident disclosed more broadly via SolanaFloor social media account and reported by Crypto Briefing. No depositor reimbursement plan announced.
DeFiTuna lending pools exploited for $580K, creating deficit in USDC pool — Crypto Briefing20 July 2026
As of this date, approximately 291,696 DAI and 5 ETH remain in Ethereum wallet 0x509B9D094A6C26D716aaC131E8aDee5B16B86d3e. CertiK publishes detailed incident analysis identifying attacker wallets and full attack chain.
DefiTuna Incident Analysis — CertiK30 July 2026
As of investigation date, no formal post-mortem has been published by DeFiTuna, no depositor compensation plan has been announced, and the majority of stolen funds remain unrecovered.
DeFiTuna lending pools exploited for $580K, creating deficit in USDC pool — Crypto BriefingDecision Log
- hash: GjeVgT9mMkwSCuVvrgDu9v2vWmB8fZfeFbTCvTBCT6Tu
This investigation is cryptographically anchored to the Solana blockchain (1 event). 13 of 14 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 7/30/2026, 5:07:30 PM
last updated: 7/31/2026, 10:00:40 AM
4 viewsavoid.net — verified advice for a post-truth world