Skip to main content
Sign in
Fei Protocol / Rari Capital1 decision on this page

Audit log

Every state-changing event for Fei Protocol / Rari Capital: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions carry three independent witnesses — the original source, an Internet Archive snapshot taken at submission time, and a Solana memo signed by our publicly-disclosed publisher key.

  1. #1publishby system:backfill
    2026-05-30 18:29:19Z
    Score: ?? (no score change)
    anchoranchored
    chain
    mainnet-betaslot 423,211,011
    sig
    462ZxVv3uoBC…DNVWbByBexplorer ↗
    hash
    HF5kUnAeLxnE…Q4qL3HTwsha256 → base58
    verifying row…full verify ↗
    canonical bytes (6922 B) ▸
    {"actor":"system:backfill","investigation_id":"d698a662-4475-4ba2-8148-1f4f2c80009a","kind":"publish","page_slug":"fei-rari","published_at":"2026-05-30T18:29:19.006Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Fei Protocol / Rari Capital","sections":[{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://www.coindesk.com/tech/2021/12/21/rari-capital-fei-protocol-token-holders-approve-multibillion-dollar-defi-merger","type":"other","url":""},{"credibility":3,"name":"https://thedefiant.io/news/defi/rari-capital-fei-merger","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://rekt.news/fei-rari-rekt","type":"other","url":""},{"credibility":3,"name":"https://www.coindesk.com/business/2022/04/30/defi-lender-rari-capitalfei-loses-80m-in-hack","type":"other","url":""},{"credibility":3,"name":"https://www.theblock.co/linked/144511/hackers-steal-80-million-from-rari-capitals-lending-pools","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://www.certik.com/resources/blog/6LiXVtPQ8q5AQfqOUPnTOS-revisiting-fei-protocol-incident","type":"other","url":""},{"credibility":3,"name":"https://medium.com/@JackLongarzo/fuse-exploit-post-mortem-76ce18d8974","type":"other","url":""},{"credibility":3,"name":"https://blog.solidityscan.com/rari-capital-re-entrancy-vulnerability-analysis-25df2bbfc803","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://cointelegraph.com/news/rari-fuze-hacker-offered-10m-bounty-by-fei-protocol-to-return-80m-loot","type":"other","url":""},{"credibility":3,"name":"https://decrypt.co/99103/fei-protocol-offers-10m-bounty-after-80m-rari-capital-exploit","type":"other","url":""},{"credibility":3,"name":"https://rekt.news/fei-rari-rekt","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://www.halborn.com/blog/post/explained-the-rari-capital-hack-may-2021","type":"other","url":""},{"credibility":3,"name":"https://cryptobriefing.com/after-11m-hack-rari-capital-team-reimburse-lost-funds/","type":"other","url":""},{"credibility":3,"name":"https://cointelegraph.com/news/rari-capital-falls-victim-to-11-million-exploit","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://cointelegraph.com/news/tribe-dao-votes-in-favor-of-repaying-victims-of-80m-rari-hack","type":"other","url":""},{"credibility":3,"name":"https://decrypt.co/110102/tribe-dao-votes-repay-rari-capital-hack-victims-again","type":"other","url":""},{"credibility":3,"name":"https://protos.com/tribe-kills-dao-overrules-vote-to-pay-crypto-debt/","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://www.sec.gov/newsroom/press-releases/2024-138","type":"other","url":""},{"credibility":3,"name":"https://www.coindesk.com/policy/2024/09/18/defi-lending-platform-rari-capital-settles-sec-charges","type":"other","url":""},{"credibility":3,"name":"https://cryptobriefing.com/sec-rari-capital-settlement/","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://medium.com/@JackLongarzo/fuse-exploit-post-mortem-76ce18d8974","type":"other","url":""},{"credibility":3,"name":"https://www.certik.com/resources/blog/6LiXVtPQ8q5AQfqOUPnTOS-revisiting-fei-protocol-incident","type":"other","url":""},{"credibility":3,"name":"https://securityaffairs.com/130768/hacking/80m-hack-defi-rari-capital-fei-protocol.html","type":"other","url":""}]}],"sources_used":[],"summary":"Fei Protocol and Rari Capital merged in December 2021 under Tribe DAO to form a combined DeFi liquidity and lending platform. On April 30, 2022, a reentrancy attack targeting a known flaw in the Compound Finance codebase drained approximately $80 million from seven Rari Fuse lending pools. Tribe DAO ultimately wound down in late 2022 following contentious governance disputes over victim compensation, and Rari Capital's co-founders faced SEC enforcement action in 2024.","timeline":[{"date":"2021-05-08","event":"Rari Capital suffers first major exploit: approximately $11 million stolen from its Ethereum pool via a price manipulation attack on Alpha Finance's ibETH contracts. The Rari team foregoes personal token allocations to reimburse users.","source":""},{"date":"2021-11-23","event":"Rari Capital and Fei Protocol announce a planned merger into a unified entity to be called Tribe DAO.","source":""},{"date":"2021-12-21","event":"Token holders of both protocols vote to approve the merger. RGT holders vote 93% in favor; TRIBE holders vote 90% in favor. The combined protocols hold approximately $2 billion TVL.","source":""},{"date":"2022-04-30","event":"Reentrancy attack drains approximately $79.75 million from seven Rari Fuse pools (8, 18, 27, 127, 144, 146, 156) over roughly 35 minutes starting at 09:00 UTC. Attacker address: 0x6162759edad730152f0df8115c698a42e666157f. Borrowing is paused globally.","source":""},{"date":"2022-04-30","event":"Fei Protocol offers attacker a $10 million bounty with no questions asked to return stolen funds. The offer is not accepted.","source":""},{"date":"2022-05-01","event":"Follow-up attack on Rari's Arbitrum deployment results in approximately 100 ETH in additional losses.","source":""},{"date":"2022-05-01","event":"Attacker deposits approximately 5,400 ETH (~$15 million) into Tornado Cash and then halts fund movements, leaving approximately $62.7 million unreturned.","source":""},{"date":"2022-05-01","event":"Initial Tribe DAO governance vote on repaying hack victims passes with approximately 75% support, but subsequent execution proposals are vetoed.","source":""},{"date":"2022-08-19","event":"Fei Labs proposes winding down Tribe DAO, citing the macroeconomic environment and the Fuse hack fallout as key reasons.","source":""},{"date":"2022-09-20","event":"Final Tribe DAO governance vote passes with 99% support, authorizing partial repayment of hack victims: 12.68 million FEI to individual victims and 26.61 million DAI to affected DAOs.","source":""},{"date":"2022-09-20","event":"Tribe DAO ceases active governance operations following the repayment vote, effectively shutting down.","source":""},{"date":"2024-09-18","event":"SEC announces settled charges against Rari Capital, Inc. and co-founders Jai Bhavnani, Jack Lipstone, and David Lucid for misleading investors and acting as unregistered brokers.","source":""},{"date":"2024-09-19","event":"U.S. District Court for the Central District of California enters final judgments against Rari Capital and its co-founders. Five-year officer-and-director bars are imposed on all three founders.","source":""}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision eeb99ae6-9f62-467c-b93d-d614cd81797f
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.