← dTRINITY dLEND5 decisions on this page
Audit log
Every state-changing event for dTRINITY dLEND: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-05-29 02:41:13ZScore: ? → ? (no score change)anchoranchored
- chain
- ●mainnet-betaslot 422,849,412
- sig
457QQGGQRD1E…bDhiTEGuexplorer ↗- hash
4nDBB8ujWd3a…VHtNKbQGsha256 → base58
verifying row…full verify ↗canonical bytes (6118 B) ▸
{"actor":"system:backfill","investigation_id":"32a844a0-4b60-4c3c-9c8c-06ae37b7387e","kind":"publish","page_slug":"dtrinity-dlend","published_at":"2026-05-29T02:41:13.016Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"dTRINITY dLEND","sections":[{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://www.dtrinity.org","type":"other","url":""},{"credibility":3,"name":"https://decrypt.co/297381/dtrinity-launches-subsidized-stablecoin-lending-protocol-on-fraxtal-l2","type":"other","url":""},{"credibility":3,"name":"https://defillama.com/protocol/dtrinity-dlend","type":"other","url":""},{"credibility":3,"name":"https://docs.dtrinity.org/core-components/dlend-money-markets","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://blog.verichains.io/p/deep-dive-into-the-dtribity-cbbtc","type":"other","url":""},{"credibility":3,"name":"https://blocksec.com/blog/weekly-web3-security-incident-roundup-mar-16-mar-22-2026","type":"other","url":""},{"credibility":3,"name":"https://cryip.co/dtrinitys-dlend-protocol-exploit-drains-around-257k-on-ethereum/","type":"other","url":""},{"credibility":3,"name":"https://www.kucoin.com/news/flash/dtrinity-dlend-on-ethereum-hit-by-deposit-inflation-attack-causing-257-000-bad-debt","type":"other","url":""},{"credibility":3,"name":"https://phemex.com/news/article/defi-lending-protocol-dtrinity-suffers-260000-exploit-67152","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://blog.verichains.io/p/deep-dive-into-the-dtribity-cbbtc","type":"other","url":""},{"credibility":3,"name":"https://blocksec.com/blog/weekly-web3-security-incident-roundup-mar-16-mar-22-2026","type":"other","url":""},{"credibility":3,"name":"https://dev.to/cryip/dtrinity-exploit-breakdown-257k-lost-due-to-share-accounting-index-sync-bug-2k7a","type":"other","url":""},{"credibility":3,"name":"https://chainwire.org/2024/12/18/dtrinity-launches-subsidized-stablecoin-lending-protocol-on-fraxtal-l2/","type":"other","url":""},{"credibility":3,"name":"https://www.cyberscope.io/audits/dtrinity","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://www.kucoin.com/news/flash/dtrinity-dlend-on-ethereum-hit-by-deposit-inflation-attack-causing-257-000-bad-debt","type":"other","url":""},{"credibility":3,"name":"https://www.mexc.com/news/951990","type":"other","url":""},{"credibility":3,"name":"https://blocksec.com/blog/weekly-web3-security-incident-roundup-mar-16-mar-22-2026","type":"other","url":""},{"credibility":3,"name":"https://defillama.com/protocol/dtrinity-dlend","type":"other","url":""},{"credibility":3,"name":"https://www.bitget.com/news/detail/12560605274307","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://docs.dtrinity.org/protocol-components/trin","type":"other","url":""},{"credibility":3,"name":"https://docs.dtrinity.org/core-components/trin-token-and-points","type":"other","url":""},{"credibility":3,"name":"https://www.coingecko.com/en/coins/dtrinity-usd","type":"other","url":""},{"credibility":3,"name":"https://defillama.com/stablecoin/dtrinity-usd","type":"other","url":""},{"credibility":3,"name":"https://defillama.com/protocol/dtrinity-dlend","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://chainwire.org/2024/12/18/dtrinity-launches-subsidized-stablecoin-lending-protocol-on-fraxtal-l2/","type":"other","url":""},{"credibility":3,"name":"https://tracxn.com/d/companies/stably/__yi1ncBcJKDlxCKsUnjhVVsT7VdSRn4o8yyqY22-QRg","type":"other","url":""},{"credibility":3,"name":"https://www.cbinsights.com/company/stably/people","type":"other","url":""},{"credibility":3,"name":"https://iq.wiki/wiki/dtrinity","type":"other","url":""}]}],"sources_used":[],"summary":"dTRINITY is a DeFi protocol self-described as the world's first subsidized stablecoin system, with dLEND serving as its Aave v3-forked lending market deployed across Fraxtal, Ethereum, and Katana. On March 17, 2026, the dLEND Ethereum deployment was exploited via an empty-market liquidityIndex inflation attack, resulting in approximately $257,000 in bad debt drained from the dUSD lending pool. The protocol paused operations and pledged to cover losses with internal funds, though the incident raised questions about audit coverage and the adequacy of pre-deployment testing on the Ethereum instance.","timeline":[{"date":"2024-12-18","event":"dTRINITY launches dLEND on Fraxtal L2, marketing itself as the world's first subsidized stablecoin protocol. Smart contract audits with Halborn, Verichains, and Cyberscope cited.","source":""},{"date":"2025-10-01","event":"dTRINITY expands dLEND to Katana network (Polygon-based DeFi L2).","source":""},{"date":"2026-01-01","event":"dTRINITY deploys dLEND on Ethereum mainnet, completing the multi-chain rollout.","source":""},{"date":"2026-03-17","event":"Attacker at address 0x08cfdff8ded5f1326628077f38d4f90df6417fd9 exploits dLEND Ethereum deployment via empty-market liquidityIndex inflation using Morpho Blue flash loans, draining approximately $257,300 in dUSD and creating bad debt. Protocol paused.","source":""},{"date":"2026-03-18","event":"dTRINITY announces the exploit publicly, confirms bad debt of approximately $257,000, states team will cover losses with internal funds within 24 hours, and confirms Fraxtal and Katana deployments are unaffected.","source":""},{"date":"2026-03-22","event":"BlockSec includes dTRINITY in its weekly Web3 security incident roundup for March 16 to 22, 2026, alongside six other DeFi incidents totaling approximately $82.7 million in sector losses.","source":""},{"date":"2026-05-28","event":"DefiLlama reports dLEND TVL at approximately $885,000 across Fraxtal, Ethereum, and Sonic, with $0 in active loans, indicating the lending market has not recovered to pre-exploit utilization levels.","source":""}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 2fc791ea-c9a2-4890-b177-5923d216600a - #2reviewby reviewerreviewer2026-08-19 01:41:34ZScore: 42 → 42 (no score change)The core incident narrative (March 17, 2026 dLEND-Ethereum empty-market liquidityIndex exploit, ~$257K loss, quick pause, pledge to cover losses with internal funds, Fraxtal/Katana-branded-unaffected messaging) is well corroborated by independent security writeups, BlockSec's incident roundup, and DefiLlama's own hack record, and the page appropriately hedges the pledge as a commitment rather than a completed fact. However, the page contains a clear internal factual error: the summary and one timeline entry claim dLEND is deployed on Fraxtal, Ethereum, and Katana, while DefiLlama's own data and dTRINITY's docs show dLEND actually runs on Fraxtal, Ethereum, and Sonic — Katana received only a dUSD deployment via Morpho/Yearn partnerships, not a native dLEND market. The page's own final timeline entry (which correctly names Sonic) contradicts its own summary. This is a reportable accuracy defect, not an editorializing problem — there is no unhedged allegation of wrongdoing on this page, and the single incident is properly attributable to a suffered smart-contract exploit rather than any conduct by the team.anchoranchored
- chain
- ●mainnet-betaslot 443,508,961
- sig
4YeLjMRgS1NF…eCgtFfazexplorer ↗- hash
7iynmhBLz1uq…thaE9yLjsha256 → base58
verifying row…full verify ↗canonical bytes (1471 B) ▸
{"actor":"reviewer","decided_at":"2026-08-19T01:41:34.038Z","decision":"review","investigation_id":"32a844a0-4b60-4c3c-9c8c-06ae37b7387e","new_score":42,"page_slug":"dtrinity-dlend","prev_score":42,"reason":"The core incident narrative (March 17, 2026 dLEND-Ethereum empty-market liquidityIndex exploit, ~$257K loss, quick pause, pledge to cover losses with internal funds, Fraxtal/Katana-branded-unaffected messaging) is well corroborated by independent security writeups, BlockSec's incident roundup, and DefiLlama's own hack record, and the page appropriately hedges the pledge as a commitment rather than a completed fact. However, the page contains a clear internal factual error: the summary and one timeline entry claim dLEND is deployed on Fraxtal, Ethereum, and Katana, while DefiLlama's own data and dTRINITY's docs show dLEND actually runs on Fraxtal, Ethereum, and Sonic — Katana received only a dUSD deployment via Morpho/Yearn partnerships, not a native dLEND market. The page's own final timeline entry (which correctly names Sonic) contradicts its own summary. This is a reportable accuracy defect, not an editorializing problem — there is no unhedged allegation of wrongdoing on this page, and the single incident is properly attributable to a suffered smart-contract exploit rather than any conduct by the team.","score_delta":0,"sequence_num":2,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}Verify offline (run on your own machine)python -m src.verify_decision d146b7ef-8417-46fc-b2b0-343b10e46603 - #3review approve with notesby judgejudge2026-08-19 01:41:34ZScore: 42 → 56 (+14)This is a calibration adjudication: content accuracy and score are judged separately. On content, claim_findings[1] and claim_findings[5] are disputed — the page's summary and one timeline entry say dLEND runs on Fraxtal, Ethereum, and Katana, but DefiLlama's protocol record and dTRINITY's own docs show the third chain is Sonic, with Katana receiving only a dUSD deployment via Morpho/Yearn partnerships, not a native dLEND market. This is an internal contradiction (the page's own 2026-05-28 timeline entry correctly names Sonic) but it does not change a reader's conclusion about the entity's risk profile, so it is minor, not material — the core incident narrative (claim_findings[2,3,7,8,9,10]) is well corroborated across independent security writeups, BlockSec, and DefiLlama's hack record, and there is no unhedged allegation on the page. On score: the sole substantive negative event is a suffered third-party smart-contract exploit (calibration_assessment.incident_attributions[0], attribution 'b'), which under the fraud-likelihood rubric caps the entity at CAUTIONARY (50-69), not the current WARNING(42). The reviewer's recommended score of 56 — lower-middle of CAUTIONARY, reflecting fast/transparent disclosure and a modest loss against unconfirmed reimbursement completion and a still-unrecovered lending market — is well reasoned and consistent with the evidence. I agree with the reviewer's calibration read and adopt its recommended score. Notes: (Correct the summary's chain list from 'Fraxtal, Ethereum, and Katana' to 'Fraxtal, Ethereum, and Sonic' to match DefiLlama and the page's own 2026-05-28 timeline entry.) (Revise the 2025-10-01 timeline entry: Katana received a native dUSD deployment via Morpho/Yearn partner integrations, not a native dLEND lending market.) (Add a timeline entry for the Sonic deployment (live since ~May 2025), currently omitted entirely despite being one of dLEND's three actual chains.) (Note in the incident section that reimbursement completion is unconfirmed — DefiLlama's hacks record shows returnedFunds unset.)anchoranchored
- chain
- ●mainnet-betaslot 443,509,062
- sig
59RZuAUULhSC…NshfaNxRexplorer ↗- hash
6niHimkicwz2…vGoDrq8Dsha256 → base58
verifying row…full verify ↗canonical bytes (2438 B) ▸
{"actor":"judge","decided_at":"2026-08-19T01:41:34.038Z","decision":"review_approve_with_notes","investigation_id":"32a844a0-4b60-4c3c-9c8c-06ae37b7387e","new_score":56,"page_slug":"dtrinity-dlend","prev_score":42,"reason":"This is a calibration adjudication: content accuracy and score are judged separately. On content, claim_findings[1] and claim_findings[5] are disputed — the page's summary and one timeline entry say dLEND runs on Fraxtal, Ethereum, and Katana, but DefiLlama's protocol record and dTRINITY's own docs show the third chain is Sonic, with Katana receiving only a dUSD deployment via Morpho/Yearn partnerships, not a native dLEND market. This is an internal contradiction (the page's own 2026-05-28 timeline entry correctly names Sonic) but it does not change a reader's conclusion about the entity's risk profile, so it is minor, not material — the core incident narrative (claim_findings[2,3,7,8,9,10]) is well corroborated across independent security writeups, BlockSec, and DefiLlama's hack record, and there is no unhedged allegation on the page. On score: the sole substantive negative event is a suffered third-party smart-contract exploit (calibration_assessment.incident_attributions[0], attribution 'b'), which under the fraud-likelihood rubric caps the entity at CAUTIONARY (50-69), not the current WARNING(42). The reviewer's recommended score of 56 — lower-middle of CAUTIONARY, reflecting fast/transparent disclosure and a modest loss against unconfirmed reimbursement completion and a still-unrecovered lending market — is well reasoned and consistent with the evidence. I agree with the reviewer's calibration read and adopt its recommended score. Notes: (Correct the summary's chain list from 'Fraxtal, Ethereum, and Katana' to 'Fraxtal, Ethereum, and Sonic' to match DefiLlama and the page's own 2026-05-28 timeline entry.) (Revise the 2025-10-01 timeline entry: Katana received a native dUSD deployment via Morpho/Yearn partner integrations, not a native dLEND lending market.) (Add a timeline entry for the Sonic deployment (live since ~May 2025), currently omitted entirely despite being one of dLEND's three actual chains.) (Note in the incident section that reimbursement completion is unconfirmed — DefiLlama's hacks record shows returnedFunds unset.)","score_delta":14,"sequence_num":3,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}Verify offline (run on your own machine)python -m src.verify_decision c57523ea-3155-4d18-8796-2367d0b0d051 - #4reviewby reviewerreviewer2026-08-25 07:44:56ZScore: 52 → 52 (no score change)The large majority of factual claims on this page — including both security-incident narratives, TVL/peg figures, and protocol overview details — are well-supported by their cited sources and corroborated independently. However, the review found a clear, cited-source contradiction on the Cyberscope 'audit' claim (Cyberscope's own page says no formal audit was completed, only an automated scan), a factual date error on the Hats Finance audit competition (the cited primary source gives June–July 2025, not August 2025 as stated twice on the page), and an internally inconsistent claim that the audit competition occurred 'after' the September 2025 exploit when it in fact preceded it under any of the dates involved. Several other claims involve minor overstatements of architectural parity across chains (Katana) or rely on weak/self-reported sourcing (regulatory-absence claims sourced only to the company's own website; several audits sourced only to the protocol's own documentation).anchoranchored
- chain
- ●mainnet-betaslot 443,512,488
- sig
5DFgEWCqpgc7…69J2Soo8explorer ↗- hash
Brgmgvs18UYu…EJanty3jsha256 → base58
verifying row…full verify ↗canonical bytes (1341 B) ▸
{"actor":"reviewer","decided_at":"2026-08-25T07:44:56.088Z","decision":"review","investigation_id":"32a844a0-4b60-4c3c-9c8c-06ae37b7387e","new_score":52,"page_slug":"dtrinity-dlend","prev_score":52,"reason":"The large majority of factual claims on this page — including both security-incident narratives, TVL/peg figures, and protocol overview details — are well-supported by their cited sources and corroborated independently. However, the review found a clear, cited-source contradiction on the Cyberscope 'audit' claim (Cyberscope's own page says no formal audit was completed, only an automated scan), a factual date error on the Hats Finance audit competition (the cited primary source gives June–July 2025, not August 2025 as stated twice on the page), and an internally inconsistent claim that the audit competition occurred 'after' the September 2025 exploit when it in fact preceded it under any of the dates involved. Several other claims involve minor overstatements of architectural parity across chains (Katana) or rely on weak/self-reported sourcing (regulatory-absence claims sourced only to the company's own website; several audits sourced only to the protocol's own documentation).","score_delta":0,"sequence_num":4,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}Verify offline (run on your own machine)python -m src.verify_decision 5d30283a-683a-48ef-8c69-906aeaca709d - #5review reviseby judgejudge2026-08-25 07:44:56ZScore: 52 → 40 (-12)The page's core content — both security incidents (the $56,000 September 2025 exploit and the $257,000 March 2026 index-manipulation attack) — is strongly corroborated across multiple independent sources down to transaction hashes and figures, and the large majority of claims (33 of 48) were confirmed outright. However, the Security Audits section overstates the Cyberscope engagement: the page's own cited source states 'No Cyberscope Audit' was completed, describing only an automated scan, not a manual audit comparable to Halborn's (claim_findings[32]). The same section also gives an incorrect date for the Hats Finance audit competition (August 2025 instead of the primary source's June 16-July 4, 2025), repeated in both the Security Audits section and the timeline (claim_findings[33], [47]), and this error produces an internally inconsistent claim that the competition occurred 'after' the September 2025 exploit when it in fact preceded it under any version of the dates (claim_findings[36]). Additional partially-supported findings — a claim of uniform 100% loss-coverage across both incidents when that commitment is documented only for the March 2026 case (claim_findings[2]), and a 'chain-isolated reserves' framing for Katana that overstates architectural parity with Fraxtal/Ethereum (claim_findings[27], [41]) — add minor overstatement but do not change the substance of what happened. Disputed claims sit at 18.75%, squarely in the minor-issues band, and no coverage gap was flagged high priority.anchoranchored
- chain
- ●mainnet-betaslot 443,512,492
- sig
3ct6vvGbiE7z…MHLJy9Yrexplorer ↗- hash
4vXniFWos4Jp…Xmmvatjjsha256 → base58
verifying row…full verify ↗canonical bytes (1874 B) ▸
{"actor":"judge","decided_at":"2026-08-25T07:44:56.088Z","decision":"review_revise","investigation_id":"32a844a0-4b60-4c3c-9c8c-06ae37b7387e","new_score":40,"page_slug":"dtrinity-dlend","prev_score":52,"reason":"The page's core content — both security incidents (the $56,000 September 2025 exploit and the $257,000 March 2026 index-manipulation attack) — is strongly corroborated across multiple independent sources down to transaction hashes and figures, and the large majority of claims (33 of 48) were confirmed outright. However, the Security Audits section overstates the Cyberscope engagement: the page's own cited source states 'No Cyberscope Audit' was completed, describing only an automated scan, not a manual audit comparable to Halborn's (claim_findings[32]). The same section also gives an incorrect date for the Hats Finance audit competition (August 2025 instead of the primary source's June 16-July 4, 2025), repeated in both the Security Audits section and the timeline (claim_findings[33], [47]), and this error produces an internally inconsistent claim that the competition occurred 'after' the September 2025 exploit when it in fact preceded it under any version of the dates (claim_findings[36]). Additional partially-supported findings — a claim of uniform 100% loss-coverage across both incidents when that commitment is documented only for the March 2026 case (claim_findings[2]), and a 'chain-isolated reserves' framing for Katana that overstates architectural parity with Fraxtal/Ethereum (claim_findings[27], [41]) — add minor overstatement but do not change the substance of what happened. Disputed claims sit at 18.75%, squarely in the minor-issues band, and no coverage gap was flagged high priority.","score_delta":-12,"sequence_num":5,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}Verify offline (run on your own machine)python -m src.verify_decision ce676913-8ef9-4702-9742-2eccf85c9a47
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.