Skip to main content
AVOID.NET

Dexible V2

avoid.net/dexible-v218/100·88% conf.
[AI-DRAFTED · AWAITING VERIFICATION][src:defillama]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·3foX9r…kiaB

Summary

Dexible V2 is a multichain DEX aggregator that suffered a critical smart contract exploit on February 17, 2023, resulting in approximately $2 million in user funds stolen across Ethereum and Arbitrum. The attack exploited an unvalidated router address in the selfSwap function of the v2 contracts, which had never undergone a formal third-party security audit. Stolen funds were laundered through Tornado Cash and have not been recovered; the protocol has since ceased operations.

Connected Entities

7 entities · 60 linked investigations
Relationships
  • Fantom (Sonic Labs)mentioned withBinance(60%)
  • Binancementioned withEthereum(65%)
  • Dexible V2mentioned withArbitrum(70%)
  • Dexible V2mentioned withBinance(60%)
  • Dexible V2mentioned withEthereum(80%)
  • Dexible V2mentioned withSushiSwap(65%)
  • Dexible V2mentioned withPolygon(60%)
  • SushiSwapmentioned withArbitrum(65%)
  • SushiSwapmentioned withEthereum(60%)
  • SushiSwapmentioned withPolygon(65%)
  • + 6 more

Connected Through

6 shared actors · 636 investigations

Distinct actors this investigation shares with others — holders, traders, and named parties. Shared infrastructure (exchanges, pools) is excluded.

Have evidence about Dexible V2?

Timeline(7 events)

17 February 2023

Attacker (0x684083f312ac50f538cc4b634d85a2feafaab77a) exploits selfSwap vulnerability in Dexible V2 contracts, stealing approximately $2 million across Ethereum and Arbitrum from 17 user accounts.

CoinDesk

17 February 2023

PeckShield raises public alarm about the exploit on Twitter, approximately five hours before Dexible's official response.

REKT News

17 February 2023

Dexible issues official announcement more than nine hours after the exploit began; CEO Michael Coon states contracts have been paused.

CoinTelegraph

17 February 2023

Attacker converts stolen TRU tokens to ETH via SushiSwap and routes approximately $1.5 million through Tornado Cash on Ethereum; $450,000 from Arbitrum is bridged to BSC and also laundered via Tornado Cash.

Quadriga Initiative

20 February 2023

Dexible team releases post-mortem report acknowledging no formal audit was performed on the v2 contracts and that internal review failed to identify the vulnerability.

REKT News

20 February 2023

Security researchers publish technical analyses of the selfSwap arbitrary external call vulnerability, identifying the lack of router address validation as the root cause.

BlockApex

31 December 2023

Dexible listed as permanently closed on Crunchbase; no victim compensation program was ever established and stolen funds were not recovered.

Crunchbase
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event). 9 of 10 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 5/4/2026, 2:54:44 AM

last updated: 8/29/2026, 1:35:34 AM

4 views

avoid.net — verified advice for a post-truth world