Skip to main content
AVOID.NET

Furucombo

avoid.net/furucombo10/100·100% conf.
[AI-DRAFTED · AWAITING VERIFICATION][src:defillama]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·2Xxsbb…aKWf

Summary

Furucombo is an Ethereum-based DeFi composability protocol launched in March 2020 that enables users to batch complex multi-protocol transactions via a drag-and-drop interface. On February 27, 2021, the protocol suffered a critical 'evil contract' exploit in which an attacker spoofed a new Aave v2 implementation via Furucombo's proxy, draining approximately $14–15 million in ETH and ERC-20 tokens from 22 users who had granted standing token approvals to the platform. The team responded with a compensation plan issuing iouCOMBO tokens subject to a 360-day vesting schedule, but the incident exposed fundamental risks in delegatecall-based proxy architectures and broad token approval models.

Connected Entities

7 entities · 60 linked investigations
Relationships
  • Cream Financementioned withEthereum(70%)
  • SushiSwapmentioned withEthereum(60%)
  • SushiSwapmentioned withUniswap(70%)
  • SushiSwapmentioned withPolygon(65%)
  • Uniswapmentioned withEthereum(80%)
  • Uniswapmentioned withSushiSwap(60%)
  • Furucombomentioned withEthereum(80%)
  • Furucombomentioned withSushiSwap(60%)
  • Furucombomentioned withUniswap(60%)
  • Furucombomentioned withAave(70%)
  • + 6 more
Have evidence about Furucombo?

Timeline(8 events)

March 2020

Furucombo launches on Ethereum mainnet as a DeFi composability and transaction batching platform.

27 February 2021

At approximately 16:47 UTC, an attacker deploys an evil contract and exploits Furucombo's proxy via an uninitialized Aave v2 upgradeable proxy, draining approximately $14–15 million in ETH and ERC-20 tokens from 22 user addresses in under one hour.

27 February 2021

Cream Finance confirms its treasury lost $1.1 million in the Furucombo attack via a public Twitter post.

27 February 2021

At approximately 17:46 UTC, Furucombo removes the Aave v2 lending pool from its registry contract, halting the attack approximately 59 minutes after it began.

27 February 2021

Attacker begins moving stolen funds through Tornado Cash to obscure on-chain trail. Attacker address 0xb624e2b10b84a41687caec94bdd484e48d76b212 holds ~4,560 ETH and ~$7M in ERC-20 tokens post-attack.

March 2021

Furucombo publishes post-mortem, acknowledges vulnerability, commits to compensating all affected users, and deploys replacement proxy contract at 0xA013AfbB9A92cEF49e898C87C060e6660E050569.

8 March 2021

Furucombo announces iouCOMBO token compensation plan: 5 million iouCOMBO tokens (1M from core team, 4M from community fund) subject to a 360-day linear vesting schedule starting March 1, 2021.

April 2021

iouCOMBO tokens scheduled for distribution to hack victims following completion of security audits. COMBO token price had fallen approximately 18.7% within 24 hours of the compensation announcement.

Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event). 15 of 17 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 5/4/2026, 2:54:58 AM

last updated: 8/30/2026, 4:47:13 PM

4 views

avoid.net — verified advice for a post-truth world