DeFiTuna
Summary
DeFiTuna is a Solana-native concentrated liquidity market maker (CLMM) and lending protocol that was exploited on July 16, 2026, for approximately $569,601–$580,000 USDC. Attackers bypassed the protocol's solvency check by exploiting an integer rounding vulnerability in its position value calculation, then laundered stolen funds via the Mayan bridge to Ethereum and into the Railgun privacy mixer. As of late July 2026, no formal post-mortem had been published, no depositor reimbursement plan had been announced, and a meaningful portion of the stolen funds remained untraceable.
Connected Entities
5 entities · 10 linked investigations- 9ytGWP8tCRF1keREJ5VHqBpSuM9MZYwm3oFQQa1SvESb→mentioned with→DeFiTuna(50%)
- BK9aTnKfPNnnj45Me5ACrky2vexzUrZHRzr4BjmQpH3c→mentioned with→DeFiTuna(50%)
- 917DKTphW3rhBG5gsJpwKsNGisNV2dx74uUFd8HBEjtg→mentioned with→DeFiTuna(50%)
- 7hiHL8AgDuLNVDQLfN3GHdLAEeCN1F7uz6nSANRvFJst→mentioned with→DeFiTuna(50%)
- + 1 more
Timeline(8 events)
2025-03-14
Sec3 begins security audit of DeFiTuna smart contracts at commit 7ced6e0b11d1bcd4126fdc2fd2592dc52f6868b7.
DefiTuna — Sec3 Security Audit Report2025-03-17
Sec3 security audit completed; DeFiTuna states no critical issues remain unresolved. Audit scope reportedly did not cover later modifications to lending contracts.
DefiTuna — Sec3 Security Audit Report2026-07-16
Exploit executed at 05:48:12 UTC in a single Solana transaction. Attackers create illiquid TUNA/USDC pool, borrow 569,601 USDC through the lending pool, route it via Jupiter swap, exploit integer rounding in solvency check to bypass is_healthy(), and withdraw funds via DecreaseLimitOrder calls. Approximately $569,601–$580,000 USDC stolen from the USDC lending pool.
DefiTuna Incident Analysis — CertiK2026-07-16
Stolen USDC bridged from Solana to Ethereum via Mayan Finance. Approximately 140 ETH deposited into Railgun privacy mixer on Ethereum.
DefiTuna Incident Analysis — CertiK2026-07-17
DeFiTuna publicly discloses the exploit via social media, stating the exploit pathway has been closed and recovery efforts are underway. Incident reported by CryptoTimes and Phemex News.
Solana's DeFiTuna Hit by $580K Exploit, USDC Pool Left Short — CryptoTimes2026-07-18
Incident disclosed more broadly via SolanaFloor social media account and reported by Crypto Briefing. No depositor reimbursement plan announced.
DeFiTuna lending pools exploited for $580K, creating deficit in USDC pool — Crypto Briefing2026-07-20
As of this date, approximately 291,696 DAI and 5 ETH remain in Ethereum wallet 0x509B9D094A6C26D716aaC131E8aDee5B16B86d3e. CertiK publishes detailed incident analysis identifying attacker wallets and full attack chain.
DefiTuna Incident Analysis — CertiK2026-07-30
As of investigation date, no formal post-mortem has been published by DeFiTuna, no depositor compensation plan has been announced, and the majority of stolen funds remain unrecovered.
DeFiTuna lending pools exploited for $580K, creating deficit in USDC pool — Crypto BriefingDecision Log
- #1publish⛓ pending7/30/2026, 5:07:37 PMhash: GjeVgT9mMkwSCuVvrgDu9v2vWmB8fZfeFbTCvTBCT6Tu
10 of 14 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 7/30/2026, 5:07:30 PM
last updated: 7/30/2026, 6:20:09 PM
avoid.net — verified advice for a post-truth world