Skip to main content
Sign in
DeFiTuna1 decision on this page

Audit log

Every state-changing event for DeFiTuna: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-07-30 17:07:37Z
    Score: ?? (no score change)
    anchorpending
    chain
    hash
    GjeVgT9mMkwS…vTBCT6Tusha256 → base58
    verifying row…
    canonical bytes (18712 B) ▸
    {"actor":"system:backfill","investigation_id":"3a1af04c-8b46-458d-a39f-5d79e2f89fba","kind":"publish","page_slug":"defituna","published_at":"2026-07-30T17:07:37.906Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"DeFiTuna","sections":[{"content":"DeFiTuna is a decentralized finance protocol deployed on the Solana blockchain. It combines three features typically offered by separate platforms: Uniswap v3-style concentrated liquidity market making, on-chain lending pools, and leveraged trading positions of up to 5x. Users can run long, short, or delta-neutral strategies. The protocol's native token, TUNA, accrues 100% of protocol revenue distributed to stakers. DeFiTuna has been live for approximately two and a half years as of mid-2026. According to CertiK Skynet data, the TUNA token had a market capitalization of approximately $403,000 and a 24-hour trading volume of $72 at the time of assessment, reflecting a project with a modest market footprint.","heading":"Protocol Overview","severity":"low","sources":[{"credibility":2,"name":"Solana's DeFiTuna Hit by $580K Exploit, USDC Pool Left Short — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/17/solana-protocol-defituna-hit-by-580k-exploit-usdc-pool-left-short/"},{"credibility":2,"name":"DeFituna (TUNA) Security Score & Audit — CertiK Skynet","type":"research","url":"https://skynet.certik.com/projects/defituna"},{"credibility":2,"name":"Tokenomics — DefiTuna Official Docs","type":"official","url":"https://docs.defituna.com/tuna/tokenomics"}]},{"content":"On July 16, 2026 at approximately 05:48:12 UTC, a single transaction on the Solana blockchain executed the complete exploit sequence. The attack involved multiple coordinated steps targeting a flaw in DeFiTuna's solvency check logic.\n\nFirst, attackers created a nearly empty TUNA/USDC Fusion pool with initial pricing aligned to oracle rates, specifically to bypass pre-swap deviation checks. Two attacker-controlled limit orders were then placed at tick 208,640, contributing only 0.001052 TUNA in total — a negligible amount of liquidity designed to receive incoming USDC.\n\nUsing the protocol's `Open_and_increase_tuna_spot_position_jupiter` function, the attackers routed 569,601 USDC borrowed from DeFiTuna's lending pool through Jupiter's embedded router into the manipulated pool. The swap returned only 494 raw TUNA units. When DeFiTuna's `compute_total_and_debt()` function calculated position value (494 × 0.0018375338 = 0.907), the `to_num::<u64>()` integer conversion discarded the fractional component, rounding the result down to zero.\n\nThe protocol's `is_healthy()` solvency function treated a zero-valued position as having always-1.0x leverage — effectively marking the position as healthy despite it owing 569,601 USDC. With the solvency check bypassed, each attacker wallet called `DecreaseLimitOrder` to withdraw approximately 284,280 USDC per position.\n\nCertiK identified the root cause as the use of `to_num::<u64>()` in the position valuation logic, which silently truncated fractional results to zero rather than rounding up or raising an error. This is classified as a precision/rounding vulnerability in Rust smart contract arithmetic.","heading":"July 2026 Exploit: Technical Analysis","severity":"critical","sources":[{"credibility":2,"name":"DefiTuna Incident Analysis — CertiK","type":"research","url":"https://www.certik.com/blog/defituna-incident-analysis"},{"credibility":2,"name":"DeFiTuna lending pools exploited for $580K, creating deficit in USDC pool — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/defituna-lending-pools-exploited-580k/"}]},{"content":"CertiK's post-incident analysis identified at least nine attacker-controlled wallets involved in the exploit. The primary identified addresses include:\n\n- 9ytGWP8tCRF1keREJ5VHqBpSuM9MZYwm3oFQQa1SvESb (Attacker 1)\n- 917DKTphW3rhBG5gsJpwKsNGisNV2dx74uUFd8HBEjtg (Attacker 2 / Fake Pool)\n- 7hiHL8AgDuLNVDQLfN3GHdLAEeCN1F7uz6nSANRvFJst (Attacker 3)\n- BK9aTnKfPNnnj45Me5ACrky2vexzUrZHRzr4BjmQpH3c (Attacker 4)\n\nFour additional attacker wallets (Attackers 5–9) were also identified in the analysis.\n\nFollowing the exploit, stolen USDC was bridged from Solana to the Ethereum network via Mayan Finance. On Ethereum, approximately 140 ETH was deposited into the Railgun zero-knowledge privacy mixer to obscure the fund trail. As of July 20, 2026, approximately 291,696 DAI and 5 ETH remained in the Ethereum wallet 0x509B9D094A6C26D716aaC131E8aDee5B16B86d3e. No funds had been recovered or returned as of the time of reporting.","heading":"Attacker Wallets and Fund Tracing","severity":"critical","sources":[{"credibility":2,"name":"DefiTuna Incident Analysis — CertiK","type":"research","url":"https://www.certik.com/blog/defituna-incident-analysis"},{"credibility":3,"name":"DeFiTuna Hack Rocks Solana as $580K Vanishes From Lending Pool — HokaNews","type":"news_article","url":"https://www.hokanews.com/2026/07/defituna-hack-rocks-solana-as-580k.html"}]},{"content":"DeFiTuna commissioned an independent security audit from Sec3, which was conducted beginning March 14, 2025 and completed March 17, 2025, targeting the Solana program at commit 7ced6e0b11d1bcd4126fdc2fd2592dc52f6868b7. The audit report identified 11 issues or questions. DeFiTuna's documentation states no critical issues remained unresolved at completion.\n\nHowever, reporting following the July 2026 exploit noted that the lending infrastructure affected by the attack had undergone significant modifications after the Sec3 audit was completed, and that the updated contracts were reportedly not included in the original security assessment scope. This gap between audited code and deployed production code is a significant factor in the exploit's occurrence.\n\nCertiK Skynet, in a separate assessment, assigned DeFiTuna a code security score of 45.47 out of 100 — the lowest of any category evaluated — and noted the absence of a bug bounty program and lack of CertiK team verification. An overall score of 65.56 (BB rating) was assigned. CertiK Skynet noted it had not conducted its own formal audit of the protocol.","heading":"Audit History and Pre-Exploit Security Posture","severity":"high","sources":[{"credibility":2,"name":"DefiTuna — Sec3 Security Audit Report (PDF)","type":"research","url":"https://resources.cryptocompare.com/asset-management/21395/1767889733766.pdf"},{"credibility":2,"name":"DeFituna (TUNA) Security Score & Audit — CertiK Skynet","type":"research","url":"https://skynet.certik.com/projects/defituna"},{"credibility":3,"name":"DeFiTuna Hack Rocks Solana as $580K Vanishes From Lending Pool — HokaNews","type":"news_article","url":"https://www.hokanews.com/2026/07/defituna-hack-rocks-solana-as-580k.html"}]},{"content":"DeFiTuna publicly acknowledged the exploit via social channels, stating that it had 'identified and mitigated the attack vector' and was 'working on trying to recover the funds.' The exploit pathway was confirmed closed by the team. However, as of late July 2026, the team had not published a formal post-mortem explaining the precise vulnerability, had not identified the attackers publicly, and had not engaged a third-party security firm to confirm findings or re-audit the remaining contracts.\n\nThe team's communications did not commit to backstopping the USDC pool deficit from protocol reserves in the event that fund recovery failed. No concrete timeline for a recovery plan or depositor reimbursement mechanism had been announced. Crypto Briefing noted that DeFiTuna's next public communication would be critical for stakeholder confidence, as the absence of a formal incident report and compensation plan left affected depositors in uncertainty.","heading":"Team Response and Transparency","severity":"high","sources":[{"credibility":2,"name":"DeFiTuna lending pools exploited for $580K, creating deficit in USDC pool — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/defituna-lending-pools-exploited-580k/"},{"credibility":2,"name":"Solana's DeFiTuna Hit by $580K Exploit, USDC Pool Left Short — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/17/solana-protocol-defituna-hit-by-580k-exploit-usdc-pool-left-short/"}]},{"content":"The exploit created a direct deficit in DeFiTuna's USDC lending pool, meaning pool liabilities exceeded assets by approximately $569,601–$580,000. This creates a classic bank-run risk scenario: while most depositors remain in the pool, withdrawals may process normally, but simultaneous large-scale withdrawals would expose the shortfall and result in some depositors receiving less than their full principal.\n\nDeFiTuna's team noted that holders of the TUNA governance token did not experience direct losses from the exploit itself, as the token is separate from the USDC lending pool. However, TUNA stakers who rely on protocol revenue distributions face indirect risk if TVL and protocol activity decline materially following the incident.\n\nThe deficit sits as bad debt on the pool's books until the team either recovers stolen funds, injects capital from treasury, or socializes losses across depositors — none of which had been formally decided as of late July 2026. Users with funds in the USDC lending pool faced delayed withdrawal risk and potential proportional haircuts depending on the resolution path chosen.","heading":"User and Depositor Risk","severity":"high","sources":[{"credibility":2,"name":"Solana's DeFiTuna Hit by $580K Exploit, USDC Pool Left Short — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/17/solana-protocol-defituna-hit-by-580k-exploit-usdc-pool-left-short/"},{"credibility":2,"name":"DefiTuna Loses $580,000 in Lending Pool Exploit — Phemex News","type":"news_article","url":"https://phemex.com/news/article/defituna-suffers-580000-loss-in-lending-pool-exploit-93463"},{"credibility":3,"name":"Why the $580,000 Exploit of DeFiTuna's Lending Pools Matters for Investors — CoinFomania","type":"news_article","url":"https://coinfomania.com/why-the-580000-exploit-of-defitunas-lending-pools-matters-for-investors/"}]},{"content":"The DeFiTuna exploit occurred during a period of elevated exploit activity affecting Solana and the broader DeFi ecosystem in July 2026. In a single week spanning July 17–19, 2026, multiple protocols suffered losses totaling over $20 million, including Ostium, Across Protocol, and Cascade. On July 20, 2026, Allbridge Core suffered a $1.65 million Solana flash-loan exploit — its second incident since 2023. The week of July 20–26 saw aggregate crypto losses exceed $47 million, with additional incidents at AFX Trade, Wanchain, and Verus.\n\nThis clustering of attacks is consistent with broader DeFi TVL decline trends: aggregate DeFi total value locked fell from approximately $115 billion in January 2026 to approximately $70 billion by July 2026, reflecting a sustained capital outflow from the sector partly attributable to security incidents and reduced risk appetite.","heading":"Broader Context: Solana DeFi Exploit Wave, July 2026","severity":"medium","sources":[{"credibility":2,"name":"Crypto Loses Over $20M in a Week as Ostium, Across, Cascade Get Hacked — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/19/crypto-loses-over-20m-in-a-week-as-ostium-across-cascade-get-hacked/"},{"credibility":2,"name":"Allbridge Core Hit by $1.65M Solana Flash-Loan Exploit, Its Second Since 2023 — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/20/allbridge-core-hit-by-1-65m-solana-flash-loan-exploit-its-second-since-2023/"},{"credibility":2,"name":"Crypto Loses Over $47M in a Week as AFX Trade, Wanchain, Verus Get Hacked — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/26/crypto-loses-over-47m-in-a-week-as-afx-trade-wanchain-verus-get-hacked/"},{"credibility":2,"name":"DeFi Total Value Locked Slides Every Month in 2026 to $70 Billion — Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/defi-total-value-locked-slides-072657247.html"}]}],"sources_used":[{"credibility":2,"name":"DefiTuna Incident Analysis — CertiK","type":"research","url":"https://www.certik.com/blog/defituna-incident-analysis"},{"credibility":2,"name":"DeFiTuna lending pools exploited for $580K, creating deficit in USDC pool — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/defituna-lending-pools-exploited-580k/"},{"credibility":2,"name":"Solana's DeFiTuna Hit by $580K Exploit, USDC Pool Left Short — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/17/solana-protocol-defituna-hit-by-580k-exploit-usdc-pool-left-short/"},{"credibility":2,"name":"DefiTuna Loses $580,000 in Lending Pool Exploit — Phemex News","type":"news_article","url":"https://phemex.com/news/article/defituna-suffers-580000-loss-in-lending-pool-exploit-93463"},{"credibility":3,"name":"Why the $580,000 Exploit of DeFiTuna's Lending Pools Matters for Investors — CoinFomania","type":"news_article","url":"https://coinfomania.com/why-the-580000-exploit-of-defitunas-lending-pools-matters-for-investors/"},{"credibility":3,"name":"DeFiTuna Hack Rocks Solana as $580K Vanishes From Lending Pool — HokaNews","type":"news_article","url":"https://www.hokanews.com/2026/07/defituna-hack-rocks-solana-as-580k.html"},{"credibility":2,"name":"DeFituna (TUNA) Security Score & Audit — CertiK Skynet","type":"research","url":"https://skynet.certik.com/projects/defituna"},{"credibility":2,"name":"DefiTuna — Sec3 Security Audit Report (PDF)","type":"research","url":"https://resources.cryptocompare.com/asset-management/21395/1767889733766.pdf"},{"credibility":2,"name":"Tokenomics — DefiTuna Official Docs","type":"official","url":"https://docs.defituna.com/tuna/tokenomics"},{"credibility":2,"name":"Crypto Loses Over $20M in a Week as Ostium, Across, Cascade Get Hacked — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/19/crypto-loses-over-20m-in-a-week-as-ostium-across-cascade-get-hacked/"},{"credibility":2,"name":"Allbridge Core Hit by $1.65M Solana Flash-Loan Exploit, Its Second Since 2023 — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/20/allbridge-core-hit-by-1-65m-solana-flash-loan-exploit-its-second-since-2023/"},{"credibility":2,"name":"Crypto Loses Over $47M in a Week as AFX Trade, Wanchain, Verus Get Hacked — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/26/crypto-loses-over-47m-in-a-week-as-afx-trade-wanchain-verus-get-hacked/"},{"credibility":2,"name":"DeFi Total Value Locked Slides Every Month in 2026 to $70 Billion — Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/defi-total-value-locked-slides-072657247.html"},{"credibility":2,"name":"Biggest DeFi Hacks and Exploits of 2026 — CCN","type":"news_article","url":"https://www.ccn.com/education/crypto/defi-hacks-exploits-causes-crypto-stolen-2026/"}],"summary":"DeFiTuna is a Solana-native concentrated liquidity market maker (CLMM) and lending protocol that was exploited on July 16, 2026, for approximately $569,601–$580,000 USDC. Attackers bypassed the protocol's solvency check by exploiting an integer rounding vulnerability in its position value calculation, then laundered stolen funds via the Mayan bridge to Ethereum and into the Railgun privacy mixer. As of late July 2026, no formal post-mortem had been published, no depositor reimbursement plan had been announced, and a meaningful portion of the stolen funds remained untraceable.","timeline":[{"date":"2025-03-14","event":"Sec3 begins security audit of DeFiTuna smart contracts at commit 7ced6e0b11d1bcd4126fdc2fd2592dc52f6868b7.","source":"DefiTuna — Sec3 Security Audit Report","source_url":"https://resources.cryptocompare.com/asset-management/21395/1767889733766.pdf"},{"date":"2025-03-17","event":"Sec3 security audit completed; DeFiTuna states no critical issues remain unresolved. Audit scope reportedly did not cover later modifications to lending contracts.","source":"DefiTuna — Sec3 Security Audit Report","source_url":"https://resources.cryptocompare.com/asset-management/21395/1767889733766.pdf"},{"date":"2026-07-16","event":"Exploit executed at 05:48:12 UTC in a single Solana transaction. Attackers create illiquid TUNA/USDC pool, borrow 569,601 USDC through the lending pool, route it via Jupiter swap, exploit integer rounding in solvency check to bypass is_healthy(), and withdraw funds via DecreaseLimitOrder calls. Approximately $569,601–$580,000 USDC stolen from the USDC lending pool.","source":"DefiTuna Incident Analysis — CertiK","source_url":"https://www.certik.com/blog/defituna-incident-analysis"},{"date":"2026-07-16","event":"Stolen USDC bridged from Solana to Ethereum via Mayan Finance. Approximately 140 ETH deposited into Railgun privacy mixer on Ethereum.","source":"DefiTuna Incident Analysis — CertiK","source_url":"https://www.certik.com/blog/defituna-incident-analysis"},{"date":"2026-07-17","event":"DeFiTuna publicly discloses the exploit via social media, stating the exploit pathway has been closed and recovery efforts are underway. Incident reported by CryptoTimes and Phemex News.","source":"Solana's DeFiTuna Hit by $580K Exploit, USDC Pool Left Short — CryptoTimes","source_url":"https://www.cryptotimes.io/2026/07/17/solana-protocol-defituna-hit-by-580k-exploit-usdc-pool-left-short/"},{"date":"2026-07-18","event":"Incident disclosed more broadly via SolanaFloor social media account and reported by Crypto Briefing. No depositor reimbursement plan announced.","source":"DeFiTuna lending pools exploited for $580K, creating deficit in USDC pool — Crypto Briefing","source_url":"https://cryptobriefing.com/defituna-lending-pools-exploited-580k/"},{"date":"2026-07-20","event":"As of this date, approximately 291,696 DAI and 5 ETH remain in Ethereum wallet 0x509B9D094A6C26D716aaC131E8aDee5B16B86d3e. CertiK publishes detailed incident analysis identifying attacker wallets and full attack chain.","source":"DefiTuna Incident Analysis — CertiK","source_url":"https://www.certik.com/blog/defituna-incident-analysis"},{"date":"2026-07-30","event":"As of investigation date, no formal post-mortem has been published by DeFiTuna, no depositor compensation plan has been announced, and the majority of stolen funds remain unrecovered.","source":"DeFiTuna lending pools exploited for $580K, creating deficit in USDC pool — Crypto Briefing","source_url":"https://cryptobriefing.com/defituna-lending-pools-exploited-580k/"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 7d2c5093-5534-4edb-8394-c4eb61df3f32
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.