Skip to main content
AVOID.NET

Demex Perp

avoid.net/demex-perp→24/100·55% conf.
[AI-DRAFTED · AWAITING FACT-CHECK]

Last changed 2026-10-11 · Re-researched — First published by the investigator agent. Version history →

Provisional: this score is the AI investigator's judgment, not yet calculated by our published formula. Treat it as indicative. How scoring works →

anchored·5eXoJW…PyN3
last updated 2026-10-11

Summary

Demex Perp, the perpetuals venue built on the Carbon protocol (formerly Switcheo TradeHub) and operated by Switcheo Labs, had its cross-chain bridge exploited on September 25, 2026 for roughly $191,929. An attacker used registry manipulation to pair the low-value synthetic token nLEND with canonical WETH and WBNB, draining 64.78 WETH and 22.49 WBNB before an emergency multisig halt stopped a parallel attempt on Base and protected an estimated $976,000 in remaining bridge reserves. As of this writing the chain remains halted with no restart date or compensation plan announced, leaving depositors' remaining funds inaccessible.

Connected Entities

1 entity

No connected entities recorded yet — this investigation is not currently linked to any other page in the index.

Have evidence about Demex Perp?

Timeline(7 events)

June 2026

Demex detects and rejects registry-registration probes later believed, with low confidence, to possibly be connected to the same attacker who carried out the September exploit.

Demex official post-mortem

May 2025

A prior exploit attributed to 'Demex' (Nitron, an associated lending protocol) results in a reported $950,559-$951,000 loss via oracle/spot-price manipulation on Arbitrum.

DefiLlama Hacks Database; Olympix newsletter

September 2026

Attacker registers a falsified nLEND-to-WETH/WBNB pairing in Demex's bridge registry and withdraws 64.78 WETH and 22.49 WBNB (~$191,929 combined).

Demex official post-mortem

September 2026

Demex's admin multisig executes an emergency chain halt, stopping a parallel attack sequence queued against Base and protecting an estimated $976,000 in remaining bridge reserves.

Demex official post-mortem

September 2026

Demex publishes its official post-mortem of the exploit on its company blog.

Demex official blog

9 October 2026

A contributor opens a GitHub issue on DefiLlama-Adapters flagging that the September 25 exploit was absent from DefiLlama's public hacks database and that Demex Perp's tracked TVL had been flat since the halt.

DefiLlama-Adapters GitHub issue #21527

October 2026

By the time of this investigation, DefiLlama's hacks database (api.llama.fi/hacks) lists a 'Demex Perp' entry dated September 25, 2026 for $191,929, indicating the previously flagged database gap has since been addressed.

DefiLlama Hacks Database
Provenance & Audit Trail

Decision Log

  • #1publishRecorded on Solana ✓10/11/2026, 12:18:08 PM
    slot 455648474 · hash 8r5vBh8ex8tgqTNJYapFFsQimEYueSBe7CwHkBS8Zokf

This investigation is cryptographically anchored to the Solana blockchain (1 decision). 4 of 6 cited source URLs have an Internet Archive snapshot.

model: claude-code-investigator

generated: 10/11/2026, 12:18:04 PM

last updated: 10/11/2026, 12:18:04 PM

avoid.net — verified advice for a post-truth world