← DODO AMM3 decisions on this page
Audit log
Every state-changing event for DODO AMM: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-05-28 18:37:20ZScore: ? → ? (no score change)anchoranchored
- chain
- ●mainnet-betaslot 422,776,111
- sig
34NH2Z5KQhDK…DB7VJAPYexplorer ↗- hash
3c4cnzrCQfRz…uwbJCBDasha256 → base58
verifying row…full verify ↗canonical bytes (10536 B) ▸
{"actor":"system:backfill","investigation_id":"3ff37634-d276-4760-a4b9-2c4b57a50a6d","kind":"publish","page_slug":"dodo-amm","published_at":"2026-05-28T18:37:20.809Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"DODO AMM","sections":[{"content":"","heading":"","severity":"none","sources":[{"credibility":2,"name":"What Is DODO? PMM Algorithm Explained — Gate Learn","type":"other","url":"https://www.gate.com/learn/articles/what-is-dodo/626"},{"credibility":2,"name":"DODO: Capital Efficient DEX — Messari","type":"research","url":"https://messari.io/report/dodo-capital-efficient-dex"},{"credibility":2,"name":"What Is DODO? — Binance Academy","type":"other","url":"https://academy.binance.com/en/articles/what-is-dodo"}]},{"content":"","heading":"","severity":"high","sources":[{"credibility":2,"name":"Explained: The DODO DEX Hack (March 2021) — Halborn","type":"research","url":"https://www.halborn.com/blog/post/explained-the-dodo-dex-hack-march-2021"},{"credibility":1,"name":"DODO DEX Drained of $3.8M in DeFi Exploit — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2021/03/09/dodo-dex-drained-of-38m-in-defi-exploit"},{"credibility":2,"name":"DODO Details $3.8 Million DeFi Attack in Post Mortem — BeInCrypto","type":"news_article","url":"https://beincrypto.com/dodo-details-defi-attack-post-mortem/"},{"credibility":1,"name":"Decentralized exchange DODO recovers some funds after attackers exploit bug for $3.8M — The Block","type":"news_article","url":"https://www.theblock.co/linked/97734/dodo-dex-exploit-bug-attack"},{"credibility":2,"name":"SlowMist: An Analysis of the Attack on DODO — SlowMist / Medium","type":"research","url":"https://slowmist.medium.com/an-analysis-of-the-attack-on-dodo-628128ee6f5f"},{"credibility":2,"name":"DeFi Hacks Continue: DODO Exploited for up to $3.8M — CryptoPotato","type":"news_article","url":"https://cryptopotato.com/defi-hacks-continue-decentralized-exchange-dodo-exploited-for-up-to-3-8m/"},{"credibility":2,"name":"DODO Finance Initialization Vulnerability — Quadriga Initiative","type":"community_report","url":"https://www.quadrigainitiative.com/casestudy/dodofinancehack.php"}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":1,"name":"DODO Security Audits — DODO Official Documentation","type":"official","url":"https://docs.dodoex.io/en/home/security"},{"credibility":2,"name":"Explained: The DODO DEX Hack (March 2021) — Halborn","type":"research","url":"https://www.halborn.com/blog/post/explained-the-dodo-dex-hack-march-2021"}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":2,"name":"DODO (DODO) Tokenomics — Tokenomist","type":"research","url":"https://tokenomist.ai/dodo"},{"credibility":2,"name":"DODO Token(DODO) Tokenomics and ICO/IDO Info — CoinCarp","type":"other","url":"https://www.coincarp.com/currencies/dodo/project-info/"},{"credibility":2,"name":"DODO (DODO) IDO Funding Rounds & Tokenomics Analysis — CryptoRank","type":"research","url":"https://cryptorank.io/ico/dodo"}]},{"content":"","heading":"","severity":"low","sources":[]},{"content":"","heading":"","severity":"low","sources":[{"credibility":2,"name":"DODO TVL, Fees, Revenue, Volume — DeFiLlama","type":"on_chain","url":"https://defillama.com/protocol/dodo"},{"credibility":2,"name":"Dodo DEX Review 2025 — Coin Bureau","type":"research","url":"https://coinbureau.com/review/dodo-dex-review"},{"credibility":2,"name":"DODO: Everything You Need To Know — Komodo Platform","type":"other","url":"https://komodoplatform.com/en/academy/what-is-dodo-dodo/"}]}],"sources_used":[{"credibility":2,"name":"Explained: The DODO DEX Hack (March 2021) — Halborn","type":"research","url":"https://www.halborn.com/blog/post/explained-the-dodo-dex-hack-march-2021"},{"credibility":1,"name":"DODO DEX Drained of $3.8M in DeFi Exploit — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2021/03/09/dodo-dex-drained-of-38m-in-defi-exploit"},{"credibility":2,"name":"DODO Details $3.8 Million DeFi Attack in Post Mortem — BeInCrypto","type":"news_article","url":"https://beincrypto.com/dodo-details-defi-attack-post-mortem/"},{"credibility":1,"name":"Decentralized exchange DODO recovers some funds after attackers exploit bug for $3.8M — The Block","type":"news_article","url":"https://www.theblock.co/linked/97734/dodo-dex-exploit-bug-attack"},{"credibility":2,"name":"SlowMist: An Analysis of the Attack on DODO — SlowMist / Medium","type":"research","url":"https://slowmist.medium.com/an-analysis-of-the-attack-on-dodo-628128ee6f5f"},{"credibility":2,"name":"DeFi Hacks Continue: DODO Exploited for up to $3.8M — CryptoPotato","type":"news_article","url":"https://cryptopotato.com/defi-hacks-continue-decentralized-exchange-dodo-exploited-for-up-to-3-8m/"},{"credibility":2,"name":"DODO Finance Initialization Vulnerability — Quadriga Initiative","type":"community_report","url":"https://www.quadrigainitiative.com/casestudy/dodofinancehack.php"},{"credibility":1,"name":"DODO Security Audits — DODO Official Documentation","type":"official","url":"https://docs.dodoex.io/en/home/security"},{"credibility":2,"name":"DODO TVL, Fees, Revenue, Volume — DeFiLlama","type":"on_chain","url":"https://defillama.com/protocol/dodo"},{"credibility":2,"name":"DODO (DODO) Tokenomics — Tokenomist","type":"research","url":"https://tokenomist.ai/dodo"},{"credibility":2,"name":"DODO Token(DODO) Tokenomics and ICO/IDO Info — CoinCarp","type":"other","url":"https://www.coincarp.com/currencies/dodo/project-info/"},{"credibility":2,"name":"DODO (DODO) IDO Funding Rounds & Tokenomics Analysis — CryptoRank","type":"research","url":"https://cryptorank.io/ico/dodo"},{"credibility":2,"name":"Dodo DEX Review 2025 — Coin Bureau","type":"research","url":"https://coinbureau.com/review/dodo-dex-review"},{"credibility":2,"name":"What Is DODO? PMM Algorithm Explained — Gate Learn","type":"other","url":"https://www.gate.com/learn/articles/what-is-dodo/626"},{"credibility":2,"name":"DODO: Capital Efficient DEX — Messari","type":"research","url":"https://messari.io/report/dodo-capital-efficient-dex"},{"credibility":1,"name":"DODO DEX Drained of $3.8M — Nasdaq (CoinDesk reprint)","type":"news_article","url":"https://www.nasdaq.com/articles/dodo-dex-drained-of-$3.8m-in-defi-exploit-2021-03-09"},{"credibility":2,"name":"Decentralized Exchange DODO Hacked For $3.8 Million — Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/news/decentralized-exchange-dodo-hacked-3-004826782.html"}],"summary":"DODO is a decentralized exchange (DEX) protocol launched in 2020, operating across 14 EVM-compatible chains, and known for its proprietary Proactive Market Maker (PMM) algorithm that concentrates liquidity near market price. On March 8, 2021, an attacker exploited a critical initialization vulnerability in DODO's V2 Crowdpooling smart contracts, draining approximately $3.8 million across four pools; roughly $3.1 million was subsequently recovered through voluntary restitution and frontrunning bot operator cooperation. The protocol continues to operate and has undergone multiple third-party security audits post-exploit, though it has lost significant market share and TVL since its 2021 peak.","timeline":[{"date":"2020-07-10","event":"DODO V1 smart contracts audited by PeckShield.","source":"DODO Official Documentation","source_url":"https://docs.dodoex.io/en/home/security"},{"date":"2020-09-18","event":"DODO V1 smart contracts audited by Trail of Bits.","source":"DODO Official Documentation","source_url":"https://docs.dodoex.io/en/home/security"},{"date":"2020-12-17","event":"DODO V2 contracts audited by PeckShield prior to V2 launch.","source":"DODO Official Documentation","source_url":"https://docs.dodoex.io/en/home/security"},{"date":"2021-02-18","event":"vDODO contracts audited by CertiK.","source":"DODO Official Documentation","source_url":"https://docs.dodoex.io/en/home/security"},{"date":"2021-03-08","event":"Attackers exploit a critical re-initialization vulnerability in DODO V2 Crowdpooling smart contracts, draining approximately $3.8 million from four pools (WSZO, WCRES, ETHA, FUSI) using flash loans. Two frontrunning MEV bots also execute the exploit ahead of the primary attacker.","source":"CoinDesk","source_url":"https://www.coindesk.com/tech/2021/03/09/dodo-dex-drained-of-38m-in-defi-exploit"},{"date":"2021-03-09","event":"DODO publicly discloses the attack; initial reports estimate $2.1 million in losses. Token price falls approximately 6% to $3.84. TVL declines 29% to $39 million.","source":"BeInCrypto","source_url":"https://beincrypto.com/dodo-dex-exploited-for-2-million-in-latest-defi-incursion/"},{"date":"2021-03-10","event":"DODO releases post-mortem with updated figures confirming $3.8 million total drained. Team reports recovery of $1.89 million (approximately 1,139,456 USDT and 411 ETH), with $200,000 frozen on an exchange. Net unrecovered loss estimated at approximately $700,000.","source":"BeInCrypto post-mortem","source_url":"https://beincrypto.com/dodo-details-defi-attack-post-mortem/"},{"date":"2021-03-16","event":"V2 CrowdPooling and Vending Machine contracts audited by Beosin — after the exploit had already occurred.","source":"DODO Official Documentation","source_url":"https://docs.dodoex.io/en/home/security"},{"date":"2021-04-13","event":"DODO V2 contracts audited by SlowMist as part of post-exploit remediation.","source":"DODO Official Documentation","source_url":"https://docs.dodoex.io/en/home/security"},{"date":"2021-12-15","event":"DODO LimitOrder, RFQ, and CrowdPooling V2 contracts audited by CertiK.","source":"DODO Official Documentation","source_url":"https://docs.dodoex.io/en/home/security"},{"date":"2022-12-12","event":"DODOFeeRouteProxy contract audited by Sherlock.","source":"DODO Official Documentation","source_url":"https://docs.dodoex.io/en/home/security"},{"date":"2023-07-01","event":"DODO V3 contracts audited by Sherlock.","source":"DODO Official Documentation","source_url":"https://docs.dodoex.io/en/home/security"},{"date":"2024-04-01","event":"DODO announces DODOchain, an omni-chain trading DEX initiative, as part of strategic pivot.","source":"Coin Bureau DODO DEX Review","source_url":"https://coinbureau.com/review/dodo-dex-review"},{"date":"2025-01-01","event":"DODO token vesting schedules fully complete; entire 1,000,000,000 token supply now circulating.","source":"Tokenomist DODO Unlock Events","source_url":"https://www.tokenomist.ai/dodo/unlock-events"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 97f902df-9834-496a-95a2-25409ef20038 - #2reviewby reviewerreviewer2026-08-18 16:55:18ZScore: 42 → 42 (no score change)The page's core narrative is well supported: a March 8, 2021 smart-contract exploit drained ~$3.8M from DODO's V2 Crowdpooling pools, and DODO's own account (corroborated by Quadriga Initiative) confirms ~$3.1M was recovered within 24 hours via attacker restitution and frontrunning-bot cooperation, consistent with the page's summary. All nine audit dates in the timeline match DODO's official security page exactly. Two defects were found: a wrong token-price figure (page says 6% drop to $3.84; contemporaneous reporting says ~2.55% to $3.94) and an internally inconsistent net-unrecovered-loss figure that conflates an early $1.89M recovery report with a later $3.1M final tally. The editorial language throughout is appropriately hedged (attack attributed to an external attacker, not to DODO), and no unhedged-allegation issues were found. No incidents beyond the single 2021 exploit were identified in five-plus years of subsequent operation, which is a point in the entity's favor that the page does not explicitly foreground.anchoranchored
- chain
- ●mainnet-betaslot 443,508,335
- sig
3cquukDqjETD…yP382vZ1explorer ↗- hash
BsG8fGAh5mxm…jPWC9AuLsha256 → base58
verifying row…full verify ↗canonical bytes (1378 B) ▸
{"actor":"reviewer","decided_at":"2026-08-18T16:55:18.552Z","decision":"review","investigation_id":"3ff37634-d276-4760-a4b9-2c4b57a50a6d","new_score":42,"page_slug":"dodo-amm","prev_score":42,"reason":"The page's core narrative is well supported: a March 8, 2021 smart-contract exploit drained ~$3.8M from DODO's V2 Crowdpooling pools, and DODO's own account (corroborated by Quadriga Initiative) confirms ~$3.1M was recovered within 24 hours via attacker restitution and frontrunning-bot cooperation, consistent with the page's summary. All nine audit dates in the timeline match DODO's official security page exactly. Two defects were found: a wrong token-price figure (page says 6% drop to $3.84; contemporaneous reporting says ~2.55% to $3.94) and an internally inconsistent net-unrecovered-loss figure that conflates an early $1.89M recovery report with a later $3.1M final tally. The editorial language throughout is appropriately hedged (attack attributed to an external attacker, not to DODO), and no unhedged-allegation issues were found. No incidents beyond the single 2021 exploit were identified in five-plus years of subsequent operation, which is a point in the entity's favor that the page does not explicitly foreground.","score_delta":0,"sequence_num":2,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}Verify offline (run on your own machine)python -m src.verify_decision 63cacef2-7a59-4c88-b246-50bf819beb68 - #3review reviseby judgejudge2026-08-18 16:55:18ZScore: 42 → 60 (+18)The reviewer classifies the sole material incident on the page — the March 8, 2021 V2 Crowdpooling exploit — as attribution 'b' (suffered), noting DODO was the victim of an external smart-contract attack, published a transparent post-mortem, recovered roughly 82% of the drained funds within 24 hours (claim_findings[3]-[4], both confirmed), and has had no further exploits, fraud allegations, or regulatory actions in over five years of subsequent operation (calibration_assessment.incident_attributions[0]). Per the scoring rubric's own worked example, a suffered hack with this recovery profile caps exposure at CAUTIONARY (50-69), not WARNING (20-49); the current 42/WARNING score appears to be treating the incident as entity-attributable risk rather than victimhood. The reviewer's recommended 60 appropriately sits mid-band rather than at the top, reflecting two legitimate residual drags that are unrelated to fraud: the exploited Crowdpooling contracts shipped without a pre-launch audit (a process gap, not misconduct), and the protocol's TVL/market relevance has declined sharply since 2021. This is a correction in the entity's favor — the page's own hedged language ('an attacker exploited,' 'voluntary restitution') already reflects the suffered-hack read; the score band did not.anchoranchored
- chain
- ●mainnet-betaslot 443,508,339
- sig
3KBsJkaeaZAZ…PLLKRAwGexplorer ↗- hash
5KwmDakGe8PG…kMnqxjkYsha256 → base58
verifying row…full verify ↗canonical bytes (1643 B) ▸
{"actor":"judge","decided_at":"2026-08-18T16:55:18.552Z","decision":"review_revise","investigation_id":"3ff37634-d276-4760-a4b9-2c4b57a50a6d","new_score":60,"page_slug":"dodo-amm","prev_score":42,"reason":"The reviewer classifies the sole material incident on the page — the March 8, 2021 V2 Crowdpooling exploit — as attribution 'b' (suffered), noting DODO was the victim of an external smart-contract attack, published a transparent post-mortem, recovered roughly 82% of the drained funds within 24 hours (claim_findings[3]-[4], both confirmed), and has had no further exploits, fraud allegations, or regulatory actions in over five years of subsequent operation (calibration_assessment.incident_attributions[0]). Per the scoring rubric's own worked example, a suffered hack with this recovery profile caps exposure at CAUTIONARY (50-69), not WARNING (20-49); the current 42/WARNING score appears to be treating the incident as entity-attributable risk rather than victimhood. The reviewer's recommended 60 appropriately sits mid-band rather than at the top, reflecting two legitimate residual drags that are unrelated to fraud: the exploited Crowdpooling contracts shipped without a pre-launch audit (a process gap, not misconduct), and the protocol's TVL/market relevance has declined sharply since 2021. This is a correction in the entity's favor — the page's own hedged language ('an attacker exploited,' 'voluntary restitution') already reflects the suffered-hack read; the score band did not.","score_delta":18,"sequence_num":3,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}Verify offline (run on your own machine)python -m src.verify_decision f498d385-b7b0-4fd9-982e-9b73a7e2ac2f
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.