← Dexodus Finance3 decisions on this page
Audit log
Every state-changing event for Dexodus Finance: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-05-29 17:31:32ZScore: ? → ? (no score change)anchoranchored
- chain
- ●mainnet-betaslot 422,984,223
- sig
384hhycyjbAA…pwUsHo19explorer ↗- hash
2Y5KvTswX9Xj…rmcTowm2sha256 → base58
verifying row…full verify ↗canonical bytes (7190 B) ▸
{"actor":"system:backfill","investigation_id":"303d6dc0-64f2-4fd3-b0f2-6049f92eef1b","kind":"publish","page_slug":"dexodus-finance","published_at":"2026-05-29T17:31:32.500Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Dexodus Finance","sections":[{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://www.dexodus.finance/","type":"other","url":""},{"credibility":3,"name":"https://docs.dexodus.finance/","type":"other","url":""},{"credibility":3,"name":"https://defillama.com/protocol/dexodus-finance","type":"other","url":""},{"credibility":3,"name":"https://www.rootdata.com/Projects/detail/Dexodus?k=MTIzMDY%3D","type":"other","url":""},{"credibility":3,"name":"https://tracxn.com/d/companies/dexodus/__zdky1RGiu4H__hbUCIbACv0IrffrxdueStGtghorcU0","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://www.quillaudits.com/blog/hack-analysis/dexodus-finance-exploit","type":"other","url":""},{"credibility":3,"name":"https://quillaudits.medium.com/dexodus-lost-300k-in-a-signature-replay-attack-heres-the-breakdown-46b7165970e2","type":"other","url":""},{"credibility":3,"name":"https://blog.solidityscan.com/dexodus-finance-hack-analysis-d699135f575c","type":"other","url":""},{"credibility":3,"name":"https://medium.com/@zhenyazhdarkin/dexodus-finance-exploit-how-a-stale-chainlink-report-enabled-a-291k-price-manipulation-attack-39dcee1efff0","type":"other","url":""},{"credibility":3,"name":"https://olympix.security/blog/how-dexodus-got-rekt-by-reused-signatures-and-how-olympix-wouldve-prevented-it","type":"other","url":""},{"credibility":3,"name":"https://defillama.com/hacks","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://olympix.security/blog/how-dexodus-got-rekt-by-reused-signatures-and-how-olympix-wouldve-prevented-it","type":"other","url":""},{"credibility":3,"name":"https://www.quillaudits.com/blog/hack-analysis/dexodus-finance-exploit","type":"other","url":""},{"credibility":3,"name":"https://blog.solidityscan.com/dexodus-finance-hack-analysis-d699135f575c","type":"other","url":""},{"credibility":3,"name":"https://www.halborn.com/audits/dexodus/dexodusv2","type":"other","url":""},{"credibility":3,"name":"https://www.halborn.com/audits/dexodus","type":"other","url":""},{"credibility":3,"name":"https://olympixai.medium.com/dexodus-zora-numa-946k-lost-to-replays-access-bugs-and-locked-in-prices-40c37b78391c","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://coinpedia.org/information/dexodus-demonstrates-what-defi-recovery-should-look-like/","type":"other","url":""},{"credibility":3,"name":"https://www.ainvest.com/news/dexodus-recover-100-funds-crisis-launches-gen-system-2506/","type":"other","url":""},{"credibility":3,"name":"https://cryptodaily.co.uk/2025/06/the-defi-protocol-that-just-pulled-off-the-impossible","type":"other","url":""},{"credibility":3,"name":"https://bitcoinethereumnews.com/tech/dexodus-demonstrates-what-defi-recovery-should-look-like/","type":"other","url":""},{"credibility":3,"name":"https://x.com/IncentiveFi/status/1927357040030032365","type":"other","url":""},{"credibility":3,"name":"https://quillaudits.medium.com/dexodus-lost-300k-in-a-signature-replay-attack-heres-the-breakdown-46b7165970e2","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://www.halborn.com/audits/dexodus/dexodusv2","type":"other","url":""},{"credibility":3,"name":"https://www.halborn.com/audits/dexodus","type":"other","url":""},{"credibility":3,"name":"https://docs.dexodus.finance/security-audits","type":"other","url":""},{"credibility":3,"name":"https://blog.solidityscan.com/dexodus-finance-hack-analysis-d699135f575c","type":"other","url":""},{"credibility":3,"name":"https://olympix.security/blog/how-dexodus-got-rekt-by-reused-signatures-and-how-olympix-wouldve-prevented-it","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://x.com/IncentiveFi/status/1927357040030032365","type":"other","url":""},{"credibility":3,"name":"https://www.quillaudits.com/blog/hack-analysis/dexodus-finance-exploit","type":"other","url":""},{"credibility":3,"name":"https://blog.solidityscan.com/dexodus-finance-hack-analysis-d699135f575c","type":"other","url":""},{"credibility":3,"name":"https://olympixai.medium.com/dexodus-zora-numa-946k-lost-to-replays-access-bugs-and-locked-in-prices-40c37b78391c","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://defillama.com/protocol/dexodus-finance","type":"other","url":""},{"credibility":3,"name":"https://defx.com/en/protocol/dexodus-finance.html","type":"other","url":""},{"credibility":3,"name":"https://web3.bitget.com/en/dapp/dexodus-28569","type":"other","url":""},{"credibility":3,"name":"https://pump.fun/coin/9eEcioewNN6hcvRsYAT5UPko4R4gfLgz9XQhGRPqpump","type":"other","url":""},{"credibility":3,"name":"https://www.rootdata.com/Projects/detail/Dexodus?k=MTIzMDY%3D","type":"other","url":""}]}],"sources_used":[],"summary":"Dexodus Finance is an oracle-based perpetual derivatives DEX operating on Coinbase's Base L2 network, founded in 2023 and headquartered in Barcelona, Spain. On May 26, 2025, the protocol suffered a signature replay attack that drained approximately $291,000–$300,000 from its liquidity pool due to the absence of nonce tracking and timestamp validation in its Chainlink oracle price-report verification logic. The team claims to have achieved 100% fund recovery within 24 hours, deprecated Perps V1, and launched a redesigned Perps V2 system; however, the protocol's current TVL remains modest at approximately $1.28M and independent verification of the full recovery narrative is limited.","timeline":[{"date":"2023-01-01","event":"Dexodus Finance founded in Barcelona, Spain by Miguel Jalon, Omar Alshaeb Foz, and Alvaro Luque Vargas.","source":""},{"date":"2025-05-26","event":"Signature replay exploit on Perps V1 drains approximately $291,000–$300,000 from the liquidity pool; attack transaction hash 0x6ffb494293fc5c32c5a6ab7dc3fff1fcc6e90fba9a6d6e486ba0a15ce518147e confirmed on-chain.","source":""},{"date":"2025-05-27","event":"Team claims 100% recovery of affected liquidity pool funds; 107 ETH reported transferred to team-controlled multisig; 6.2 ETH transferred to Binance in alleged bounty settlement. Exploit vector patched.","source":""},{"date":"2025-05-27","event":"Perps V1 deprecated; trader collateral transferred directly to user accounts. Perps V2 system launched. Halborn, SEAL 911, Chainlink Security, and Binance reported to be tracing attacker wallet.","source":""},{"date":"2025-06-01","event":"Multiple post-mortem analyses published by QuillAudits, SolidityScan, and Olympix confirming signature replay root cause.","source":""},{"date":"2025-06-25","event":"Token Generation Event conducted; 16% of total token supply allocated to community participants.","source":""}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 56dd97f4-c3d7-40c7-84ad-0af859142bc7 - #2reviewby reviewerreviewer2026-08-19 01:41:35ZScore: 42 → 42 (no score change)The core incident narrative (May 26, 2025 signature-replay exploit, mechanism, root cause, and tx hash) is well corroborated by three independent security-research firms and is presented with appropriate hedging (no unhedged fraud allegations against the team). However, the page contains two clear factual errors: the current TVL figure ($1.28M) contradicts its own cited source, which shows the protocol at near-zero TVL with a deadUrl flag; and the post-mortem publication date (June 1, 2025) is off by 1.5–3.5 months against the actual publication dates of the cited pieces. The '100% recovery' claim is correctly framed as an unverified team claim, and independent security researchers describe the recovery as partial/unspecified rather than complete — this gap between team messaging and independent assessment is real and the page's hedging language is appropriate, though it should more explicitly flag that independent sources describe the recovery as partial.anchoranchored
- chain
- ●mainnet-betaslot 443,509,073
- sig
2Kvm34UWR2Uc…UhgDnUeoexplorer ↗- hash
2PLFf1t2S1NS…A4mKgyURsha256 → base58
verifying row…full verify ↗canonical bytes (1321 B) ▸
{"actor":"reviewer","decided_at":"2026-08-19T01:41:35.772Z","decision":"review","investigation_id":"303d6dc0-64f2-4fd3-b0f2-6049f92eef1b","new_score":42,"page_slug":"dexodus-finance","prev_score":42,"reason":"The core incident narrative (May 26, 2025 signature-replay exploit, mechanism, root cause, and tx hash) is well corroborated by three independent security-research firms and is presented with appropriate hedging (no unhedged fraud allegations against the team). However, the page contains two clear factual errors: the current TVL figure ($1.28M) contradicts its own cited source, which shows the protocol at near-zero TVL with a deadUrl flag; and the post-mortem publication date (June 1, 2025) is off by 1.5–3.5 months against the actual publication dates of the cited pieces. The '100% recovery' claim is correctly framed as an unverified team claim, and independent security researchers describe the recovery as partial/unspecified rather than complete — this gap between team messaging and independent assessment is real and the page's hedging language is appropriate, though it should more explicitly flag that independent sources describe the recovery as partial.","score_delta":0,"sequence_num":2,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}Verify offline (run on your own machine)python -m src.verify_decision f5e072d2-aa68-456c-b024-5af622e5f6e8 - #3review reviseby judgejudge2026-08-19 01:41:35ZScore: 42 → 55 (+13)The reviewer classifies the entity's sole material adverse event — the May 26, 2025 signature-replay exploit — as a suffered third-party attack against a smart-contract defect, not own-fraud or misappropriation (calibration_assessment.incident_attributions[0], attribution 'b'). Per the scoring rubric's own instruction, incidents attributed 'b' cap severity at CAUTIONARY (50-69), so the current 42/WARNING score treats a suffered hack as if it carried fraud-attributable weight, which the evidence (three independent tier-2 security firms corroborating mechanism and root cause, no insider-involvement signal) does not support. Mitigating the upside: the team patched within 24 hours and engaged credible incident response (SEAL 911's own public activity log independently confirms involvement — claim_findings[5]), and 107 ETH recovery to a multisig is independently corroborated. Capping the upside: the team's '100% recovery' claim is contradicted by the two independent researchers who actually investigated (they describe partial/unspecified recovery — claim_findings[2]), and the page's own cited TVL source (DefiLlama) shows near-zero TVL with a deadUrl flag, not the $1.28M stated on the page (claim_findings[3]), leaving the protocol's current operating status genuinely uncertain. Net effect: the current score under-credits that this was a suffered hack with a competent, verifiable response, while the recommended 55 appropriately reflects the unresolved recovery-percentage and operational-status gaps rather than pushing to the top of CAUTIONARY or into VERIFIED.anchoranchored
- chain
- ●mainnet-betaslot 443,509,077
- sig
2JTn6JN2DUg5…MGWSueAwexplorer ↗- hash
29VNggH3FuM9…mpQQG5s8sha256 → base58
verifying row…full verify ↗canonical bytes (1935 B) ▸
{"actor":"judge","decided_at":"2026-08-19T01:41:35.772Z","decision":"review_revise","investigation_id":"303d6dc0-64f2-4fd3-b0f2-6049f92eef1b","new_score":55,"page_slug":"dexodus-finance","prev_score":42,"reason":"The reviewer classifies the entity's sole material adverse event — the May 26, 2025 signature-replay exploit — as a suffered third-party attack against a smart-contract defect, not own-fraud or misappropriation (calibration_assessment.incident_attributions[0], attribution 'b'). Per the scoring rubric's own instruction, incidents attributed 'b' cap severity at CAUTIONARY (50-69), so the current 42/WARNING score treats a suffered hack as if it carried fraud-attributable weight, which the evidence (three independent tier-2 security firms corroborating mechanism and root cause, no insider-involvement signal) does not support. Mitigating the upside: the team patched within 24 hours and engaged credible incident response (SEAL 911's own public activity log independently confirms involvement — claim_findings[5]), and 107 ETH recovery to a multisig is independently corroborated. Capping the upside: the team's '100% recovery' claim is contradicted by the two independent researchers who actually investigated (they describe partial/unspecified recovery — claim_findings[2]), and the page's own cited TVL source (DefiLlama) shows near-zero TVL with a deadUrl flag, not the $1.28M stated on the page (claim_findings[3]), leaving the protocol's current operating status genuinely uncertain. Net effect: the current score under-credits that this was a suffered hack with a competent, verifiable response, while the recommended 55 appropriately reflects the unresolved recovery-percentage and operational-status gaps rather than pushing to the top of CAUTIONARY or into VERIFIED.","score_delta":13,"sequence_num":3,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}Verify offline (run on your own machine)python -m src.verify_decision 15eff8aa-bf3e-4b0e-aab2-1a07bcfc7658
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.