Skip to main content
AVOID.NET
DoinGud1 decision on this page

Audit log

Every state-changing event for DoinGud: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-09-22 17:19:23Z
    Score: ?? (no score change)
    anchoranchored
    chain
    mainnet-betaslot 449,444,220
    sig
    3o2XJPopMFa4…qFSs6FEPexplorer ↗
    hash
    AwW43KQycdxQ…aj4Js67tsha256 → base58
    verifying row…full verify ↗
    canonical bytes (17858 B) ▸
    {"actor":"system:backfill","investigation_id":"1f6691f1-c228-4ea1-9e75-37f0d1944f7b","kind":"publish","page_slug":"doingud","published_at":"2026-09-22T17:19:23.280Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"DoinGud","sections":[{"content":"DoinGud was founded in 2021 by Manuel Gonzalez Alzuru (Manu), Andrew Kline, and Kyle Gordon, and was incorporated in Zug, Switzerland. The platform operated as a community-driven NFT marketplace built on the Polygon blockchain, allowing creators to mint and sell digital works while directing a portion of proceeds — between 5% and 95% of primary sales, and 2.5% of secondary sales — to vetted social impact organizations aligned with the United Nations' 17 Sustainable Development Goals. The platform supported cryptocurrency and credit card payments and emphasized permaweb media storage for long-term accessibility. Advisors included representatives from Gitcoin, Aave, Mask Network, and Giveth. The platform also planned to issue a native governance and staking token called $AMOR. DoinGud ran a podcast called Tokenverse and hosted community events. According to company profile aggregators including Tracxn, the company is no longer active as of the time of this investigation. PitchBook records indicate DoinGud was acquired by a US company called Cleo on or around January 26, 2024, though the nature and completeness of that transaction could not be independently verified from primary sources available.","heading":"Platform Overview and History","severity":"low","sources":[{"credibility":2,"name":"DoinGud: A New NFT Platform Where Every Transaction Does Good — PRNewswire","type":"news_article","url":"https://www.prnewswire.com/news-releases/doingud-a-new-nft-platform-where-every-transaction-does-good-301295276.html"},{"credibility":2,"name":"First Artist-Activists Join NFT Marketplace DoinGud — GlobeNewswire","type":"news_article","url":"https://www.globenewswire.com/news-release/2021/09/02/2291053/0/en/First-Artist-Activists-Join-NFT-Marketplace-DoinGud-To-Launch-Humanity-Positive-NFTs.html"},{"credibility":2,"name":"DoinGud Company Profile — Tracxn","type":"other","url":"https://tracxn.com/d/companies/doingud/__QjMCflTyekG5ww-SHvI082cy7Xs4wqGN2K6lZ5EsG2A"},{"credibility":2,"name":"A Dream Team of Partners for DoinGud — Newswire","type":"news_article","url":"https://www.newswire.com/news/a-dream-team-of-partners-for-doingud-21401443"},{"credibility":2,"name":"DoinGud Company Profile — PitchBook","type":"other","url":"https://pitchbook.com/profiles/company/466201-00"}]},{"content":"In September 2021, DoinGud announced a $5 million seed funding round. Investors included venture capital firms Hard Yaka, Kenetic Capital, Alameda Research, IOSG Ventures, DAO Square, Ellipti, Genblock Capital, and Supernova, as well as notable individual backers including Sandeep Nailwal (co-founder of Polygon), Griff Green of Commons Stack, and Jordan Ellis of dOrg. Additional backing came from ecosystem participants including MaskBook, dOrg, MetaCartel Ventures China, and Giveth. The announced use of proceeds was to develop new features, build cross-chain operability, improve NFT accessibility, and launch the $AMOR token. Alameda Research, one of the listed investors, was a trading firm founded by Sam Bankman-Fried that collapsed in November 2022 following the FTX bankruptcy. No claims have been made that Alameda's collapse had a direct causal role in DoinGud's wind-down; the connection is noted as context.","heading":"Funding and Investors","severity":"low","sources":[{"credibility":2,"name":"DoinGud Raises $5 Million Seed Round — GlobeNewswire","type":"news_article","url":"https://www.globenewswire.com/en/news-release/2021/09/30/2306249/0/en/Social-impact-organization-DoinGud-raises-5-Million-in-their-mission-to-change-the-world-of-art-and-charity.html"},{"credibility":2,"name":"DoinGud $5M Seed Raise — Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/news/social-impact-organization-doingud-raises-130000323.html"}]},{"content":"On September 21, 2026, an attacker exploited a logic flaw in DoinGud's Diamond bidding contract deployed on the Polygon network, draining approximately $35,486 USDC.e. The vulnerability resided in the contract's acceptBid function: when a bid was accepted, the function paid out the bid amount but did not mark the bid record as consumed or clear the record from contract state. This allowed the same bid to be accepted multiple times within a single transaction. The attacker's method, as described by SlowMist's hacked incident tracker, was: (1) flash-loan USDC equivalent to the contract's total balance from a third-party lending pool; (2) place a bid on an NFT they themselves controlled; (3) call acceptBid twice against the same bid record, receiving the payout on both calls; (4) repay the flash loan, retaining the drained funds as profit. The flaw is categorized as a missing-state-update or reentrancy-adjacent vulnerability — the contract failed to enforce that bid records could be consumed only once. DoinGud's Diamond contract architecture follows the EIP-2535 multi-facet proxy standard, which organizes contract logic into separate facet contracts behind a single proxy address. The bidding facet's failure to update state before or after payout is consistent with a check-effects-interactions pattern violation. At the time of the exploit, DoinGud had ceased active operations and its front end was reportedly dormant, meaning no active team appears to have monitored or responded to the incident. The $35,486 loss is modest relative to most DeFi exploits, but the incident exemplifies the broader class of zombie-contract attacks, where funds stranded in deprecated protocols remain accessible to anyone who identifies a flaw in the dormant code.","heading":"September 2026 Diamond Bidding Contract Exploit","severity":"high","sources":[{"credibility":2,"name":"SlowMist Hacked — Incident Tracker (DoinGud entry)","type":"community_report","url":"https://hacked.slowmist.io/"},{"credibility":2,"name":"Abandoned DeFi Protocols Leave Zombie Smart Contracts Behind — CryptoDaily","type":"news_article","url":"https://cryptodaily.co.uk/2026/08/abandoned-defi-zombie-smart-contracts"},{"credibility":1,"name":"ERC-2535: Diamonds, Multi-Facet Proxy — Ethereum EIPs","type":"official","url":"https://eips.ethereum.org/EIPS/eip-2535"}]},{"content":"The root cause of the September 2026 exploit is a state-management defect in the acceptBid function of DoinGud's bidding facet. In a correctly implemented bidding system using the EIP-2535 Diamond pattern, accepting a bid should atomically: (a) verify the bid exists and is valid; (b) delete or invalidate the bid record to prevent reuse; (c) transfer payment to the seller. DoinGud's implementation apparently performed (a) and (c) but omitted (b), leaving the bid record in an unconsumed state after the first payout. Because the flash loan and both acceptBid calls occurred within a single transaction, the contract's balance appeared sufficient for both calls. The attack is structurally similar to a double-spend: the attacker obtained two payouts from one bid. This class of error — failing to clear consumed state before or immediately after issuing a transfer — is addressed by the check-effects-interactions (CEI) pattern, which requires that all state changes occur before any external calls or ether/token transfers. There is no publicly available audit report for DoinGud's bidding contract found during this investigation; if an audit was conducted, its coverage of the bidding facet is unknown.","heading":"Technical Vulnerability Analysis: Missing Bid Consumption","severity":"high","sources":[{"credibility":2,"name":"Proxy Pattern Vulnerabilities: UUPS, Transparent, and Diamond — DEV Community","type":"research","url":"https://dev.to/h33min/proxy-pattern-vulnerabilities-uups-transparent-and-diamond-pc7"},{"credibility":1,"name":"SC04:2026 Flash Loan-Facilitated Attacks — OWASP Smart Contract Security","type":"research","url":"https://scs.owasp.org/sctop10/SC04-FlashLoanAttacks/"}]},{"content":"The DoinGud exploit fits a pattern identified by security researchers and chronicled in 2026: abandoned DeFi protocols whose front ends shut down but whose smart contracts remain live and callable on-chain. A CryptoDaily analysis from August 2026 notes that public deprecation notices and front-end shutdowns do not disable smart contracts, which remain callable indefinitely unless explicitly paused or drained. Contracts that hold residual balances are particularly susceptible because attackers have a clear economic incentive to find exploitable logic. In DoinGud's case, the bidding contract still held approximately $35,486 USDC.e at the time of the exploit, suggesting funds were never withdrawn by users or operators during or after wind-down. The broader 2026 landscape saw multiple legacy and zombie contract drains, including the Aztec Connect RollupProcessorV3 ($2.1–2.3 million, June 2026) and a separate legacy Polygon royalties contract ($261,000, also June 2026). Industry guidance recommends that protocol teams publish formal wind-down timelines, enable withdrawal-only modes, actively drain residual balances, and revoke administrative roles before ceasing operations.","heading":"Zombie Contract Risk and Platform Wind-Down","severity":"medium","sources":[{"credibility":2,"name":"Abandoned DeFi Protocols Leave Zombie Smart Contracts Behind — CryptoDaily","type":"news_article","url":"https://cryptodaily.co.uk/2026/08/abandoned-defi-zombie-smart-contracts"},{"credibility":2,"name":"Legacy Polygon Royalties Contract Exploit Drains $261K — Bitget News","type":"news_article","url":"https://www.bitget.com/news/detail/12560605475628"},{"credibility":2,"name":"Biggest DeFi Hacks and Exploits of 2026 — CCN","type":"news_article","url":"https://www.ccn.com/education/crypto/defi-hacks-exploits-causes-crypto-stolen-2026/"}]},{"content":"No prior smart contract exploits, regulatory actions, SEC filings, or fraud allegations against DoinGud, its founders, or its associated entities were found during this investigation. The inclusion of Alameda Research among DoinGud's seed investors is noted as a contextual risk marker, given Alameda's collapse in 2022; however, no public claims connect Alameda's failure to any misconduct by DoinGud. The $AMOR token was announced as a planned governance token but no evidence of a public token sale or listing was found in available sources. ICO aggregator ICO Drops listed no data on an upcoming or completed AMOR token sale as of May 2026. DoinGud's website (doingud.com) remained nominally accessible as of mid-2026 per search index results, suggesting the domain was not fully decommissioned. The NFT market broadly experienced a severe downturn from late 2022 onward; DappRadar data cited in industry reporting shows art NFT trading volume fell from $2.9 billion in 2021 to approximately $23.8 million in early 2025, a 93% decline. DoinGud's operational wind-down is consistent with the fate of dozens of NFT marketplaces founded during the 2021 bull cycle.","heading":"Prior Issues and Risk Indicators","severity":"low","sources":[{"credibility":3,"name":"DoinGud (AMOR) Token Sale Information — ICO Drops","type":"other","url":"https://icodrops.com/doingud/"},{"credibility":2,"name":"NFT Marketplaces Are Shutting Down: What Went Wrong? — Live Bitcoin News","type":"news_article","url":"https://www.livebitcoinnews.com/nft-marketplaces-are-shutting-down-what-went-wrong/"}]}],"sources_used":[{"credibility":2,"name":"DoinGud: A New NFT Platform Where Every Transaction Does Good — PRNewswire","type":"news_article","url":"https://www.prnewswire.com/news-releases/doingud-a-new-nft-platform-where-every-transaction-does-good-301295276.html"},{"credibility":2,"name":"DoinGud Raises $5 Million Seed Round — GlobeNewswire","type":"news_article","url":"https://www.globenewswire.com/en/news-release/2021/09/30/2306249/0/en/Social-impact-organization-DoinGud-raises-5-Million-in-their-mission-to-change-the-world-of-art-and-charity.html"},{"credibility":2,"name":"First Artist-Activists Join DoinGud — GlobeNewswire","type":"news_article","url":"https://www.globenewswire.com/news-release/2021/09/02/2291053/0/en/First-Artist-Activists-Join-NFT-Marketplace-DoinGud-To-Launch-Humanity-Positive-NFTs.html"},{"credibility":2,"name":"Giving Tuesday: DoinGud Launches First Charitable NFT Collection — GlobeNewswire","type":"news_article","url":"https://www.globenewswire.com/news-release/2021/11/30/2343243/0/en/Giving-Tuesday-DoinGud-Launches-First-Charitable-NFT-Collection-with-H-Creative.html"},{"credibility":2,"name":"A Dream Team of Partners for DoinGud — Newswire","type":"news_article","url":"https://www.newswire.com/news/a-dream-team-of-partners-for-doingud-21401443"},{"credibility":2,"name":"DoinGud Company Profile — Tracxn","type":"other","url":"https://tracxn.com/d/companies/doingud/__QjMCflTyekG5ww-SHvI082cy7Xs4wqGN2K6lZ5EsG2A"},{"credibility":2,"name":"DoinGud Company Profile — PitchBook","type":"other","url":"https://pitchbook.com/profiles/company/466201-00"},{"credibility":2,"name":"SlowMist Hacked Incident Tracker","type":"community_report","url":"https://hacked.slowmist.io/"},{"credibility":2,"name":"Abandoned DeFi Protocols Leave Zombie Smart Contracts Behind — CryptoDaily","type":"news_article","url":"https://cryptodaily.co.uk/2026/08/abandoned-defi-zombie-smart-contracts"},{"credibility":2,"name":"Legacy Polygon Royalties Contract Exploit Drains $261K — Bitget News","type":"news_article","url":"https://www.bitget.com/news/detail/12560605475628"},{"credibility":1,"name":"SC04:2026 Flash Loan-Facilitated Attacks — OWASP Smart Contract Security","type":"research","url":"https://scs.owasp.org/sctop10/SC04-FlashLoanAttacks/"},{"credibility":1,"name":"ERC-2535: Diamonds, Multi-Facet Proxy — Ethereum EIPs","type":"official","url":"https://eips.ethereum.org/EIPS/eip-2535"},{"credibility":2,"name":"Proxy Pattern Vulnerabilities: UUPS, Transparent, and Diamond — DEV Community","type":"research","url":"https://dev.to/h33min/proxy-pattern-vulnerabilities-uups-transparent-and-diamond-pc7"},{"credibility":2,"name":"NFT Marketplaces Are Shutting Down: What Went Wrong? — Live Bitcoin News","type":"news_article","url":"https://www.livebitcoinnews.com/nft-marketplaces-are-shutting-down-what-went-wrong/"},{"credibility":3,"name":"DoinGud (AMOR) Token Sale Information — ICO Drops","type":"other","url":"https://icodrops.com/doingud/"},{"credibility":2,"name":"Biggest DeFi Hacks and Exploits of 2026 — CCN","type":"news_article","url":"https://www.ccn.com/education/crypto/defi-hacks-exploits-causes-crypto-stolen-2026/"},{"credibility":2,"name":"Manuel Gonzalez Alzuru — Crunchbase Person Profile","type":"other","url":"https://www.crunchbase.com/person/manuel-gonzalez-alzuru"}],"summary":"DoinGud was a Polygon-based NFT marketplace founded in 2021 that raised $5 million to connect creators with charitable causes via blockchain. The platform is reported to have ceased active operations and was reportedly acquired in early 2024; however, its smart contracts remained deployed and holding funds. On September 21, 2026, an attacker exploited a bid-record-clearing flaw in DoinGud's Diamond bidding contract on Polygon, draining approximately $35,486 USDC.e via a flash loan. The incident illustrates the ongoing risk posed by dormant DeFi and NFT contracts that retain live balances after a platform winds down.","timeline":[{"date":"2021-05-19","event":"DoinGud publicly announced as a new NFT marketplace built on Polygon, targeting a summer 2021 launch.","source":"PRNewswire","source_url":"https://www.prnewswire.com/news-releases/doingud-a-new-nft-platform-where-every-transaction-does-good-301295276.html"},{"date":"2021-09-02","event":"First artist-activists announced as joining the DoinGud platform ahead of launch.","source":"GlobeNewswire","source_url":"https://www.globenewswire.com/news-release/2021/09/02/2291053/0/en/First-Artist-Activists-Join-NFT-Marketplace-DoinGud-To-Launch-Humanity-Positive-NFTs.html"},{"date":"2021-09-30","event":"DoinGud announced a $5 million seed round from investors including Alameda Research, Kenetic Capital, Hard Yaka, IOSG Ventures, and Polygon co-founder Sandeep Nailwal.","source":"GlobeNewswire","source_url":"https://www.globenewswire.com/en/news-release/2021/09/30/2306249/0/en/Social-impact-organization-DoinGud-raises-5-Million-in-their-mission-to-change-the-world-of-art-and-charity.html"},{"date":"2021-11-30","event":"DoinGud launched its first charitable NFT collection with H+ Creative on Giving Tuesday.","source":"GlobeNewswire","source_url":"https://www.globenewswire.com/news-release/2021/11/30/2343243/0/en/Giving-Tuesday-DoinGud-Launches-First-Charitable-NFT-Collection-with-H-Creative.html"},{"date":"2022-11-01","event":"Alameda Research, one of DoinGud's seed investors, collapsed alongside FTX. No direct operational impact on DoinGud was reported.","source":"General knowledge / multiple news outlets","source_url":"https://www.reuters.com/technology/ftx-collapse-crypto-exchange-sam-bankman-fried-2022-11-12/"},{"date":"2024-01-26","event":"DoinGud was reportedly acquired by a US company called Cleo, according to PitchBook records. The scope and terms of the acquisition are not confirmed from primary sources.","source":"PitchBook (secondary aggregator)","source_url":"https://pitchbook.com/profiles/company/466201-00"},{"date":"2026-09-21","event":"An attacker exploited a missing bid-consumption flaw in DoinGud's Diamond bidding contract on Polygon, using a flash loan to accept the same bid twice and drain approximately $35,486 USDC.e.","source":"SlowMist Hacked Incident Tracker","source_url":"https://hacked.slowmist.io/"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 2860d85c-98fa-449f-8fd7-50da8d450251
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.