Skip to main content
Sign in
GemPad1 decision on this page

Audit log

Every state-changing event for GemPad: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions carry three independent witnesses — the original source, an Internet Archive snapshot taken at submission time, and a Solana memo signed by our publicly-disclosed publisher key.

  1. #1publishby system:backfill
    2026-05-27 17:32:28Z
    Score: ?? (no score change)
    anchoranchored
    chain
    mainnet-betaslot 422,548,209
    sig
    55QwAWdT96Zs…qZy41Krvexplorer ↗
    hash
    6jnxEXugNoM7…Zby3dS58sha256 → base58
    verifying row…full verify ↗
    canonical bytes (5094 B) ▸
    {"actor":"system:backfill","investigation_id":"be6f7944-4394-45ff-9345-d520127dadc7","kind":"publish","page_slug":"gempad","published_at":"2026-05-27T17:32:28.773Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"GemPad","sections":[{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://iq.wiki/wiki/gempad","type":"other","url":""},{"credibility":3,"name":"https://www.bitbond.com/resources/gempad-launchpad-review/","type":"other","url":""},{"credibility":3,"name":"https://gempad.app/","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://rekt.news/gempad-rekt","type":"other","url":""},{"credibility":3,"name":"https://www.halborn.com/blog/post/explained-the-gempad-hack-december-2024","type":"other","url":""},{"credibility":3,"name":"https://cryptorank.io/news/feed/07a70-gem-pad-token-launchpad-exploited-2m","type":"other","url":""},{"credibility":3,"name":"https://theholycoins.com/blog/gempad-exploit-up-to-usd2-2-million-lost-to-reentrancy-vulnerability-27-projects-impacted-a","type":"other","url":""},{"credibility":3,"name":"https://howdylittlecrypto.com/gempads-december-crisis-technical-breakdown-of-the-2-2m-smart-contract-breach/","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://www.halborn.com/blog/post/explained-the-gempad-hack-december-2024","type":"other","url":""},{"credibility":3,"name":"https://howdylittlecrypto.com/gempads-december-crisis-technical-breakdown-of-the-2-2m-smart-contract-breach/","type":"other","url":""},{"credibility":3,"name":"https://www.cyberscope.io/audits/gems","type":"other","url":""},{"credibility":3,"name":"https://cryptorank.io/news/feed/07a70-gem-pad-token-launchpad-exploited-2m","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://rekt.news/gempad-rekt","type":"other","url":""},{"credibility":3,"name":"https://theholycoins.com/blog/gempad-exploit-up-to-usd2-2-million-lost-to-reentrancy-vulnerability-27-projects-impacted-a","type":"other","url":""},{"credibility":3,"name":"https://x.com/MunchToken/status/1869762866066100699","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://www.scam-detector.com/validator/gempad-app-review/","type":"other","url":""},{"credibility":3,"name":"https://www.coingecko.com/en/coins/gempad","type":"other","url":""},{"credibility":3,"name":"https://coinlaunch.space/launchpads/gempad/","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://www.halborn.com/blog/post/explained-the-gempad-hack-december-2024","type":"other","url":""},{"credibility":3,"name":"https://rekt.news/gempad-rekt","type":"other","url":""},{"credibility":3,"name":"https://cryptorank.io/news/feed/07a70-gem-pad-token-launchpad-exploited-2m","type":"other","url":""}]}],"sources_used":[],"summary":"GemPad is a multi-chain no-code token launchpad and crowdfunding platform operating primarily on BNB Smart Chain, Ethereum, and Base, launched around 2021. On December 17, 2024, a reentrancy vulnerability in its LP Locker V2 smart contract was exploited across three chains, draining approximately $1.9–$2.2 million in locked liquidity from at least 27 dependent projects. Stolen funds were routed through Tornado Cash, and GemPad issued no public compensation plan for affected projects.","timeline":[{"date":"2021-08-01","event":"GemPad mainnet launches, initially on BNB Smart Chain as a no-code token launchpad","source":""},{"date":"2022-04-30","event":"GemPad and the GEMS token listed on CoinMarketCap; GEMS native token launched on BSC","source":""},{"date":"2022-12-31","event":"GEMS token ends year down approximately 78.5%, tracking broader 2022 crypto market decline","source":""},{"date":"2023-01-01","event":"Community dissatisfaction reports emerge regarding fund allocation and governance transparency; team initiates community vote","source":""},{"date":"2024-01-31","event":"GemPad releases 'Evolution Update,' expanding platform to include Linear and OTC Sales","source":""},{"date":"2024-12-17","event":"Attacker (0xFDd9b0A7e7e16b5Fd48a3D1e242aF362bC81bCaa) exploits reentrancy vulnerability in GemPad LP Locker V2 across Ethereum, BNB Chain, and Base; approximately $1.9–$2.2 million drained from 27 projects including Munch Protocol, AnonFi, BPay, Nutcoin, and FOMO Network","source":""},{"date":"2024-12-17","event":"Stolen funds swapped to ETH and BNB; majority routed through Tornado Cash mixer, approximately 400 ETH sent from Nutcoin's drained Ethereum liquidity to Tornado Cash","source":""},{"date":"2024-12-17","event":"GemPad disables Locker service and acknowledges exploit; no compensation plan announced for affected projects","source":""},{"date":"2024-12-18","event":"Munch Protocol posts community update on X describing its own recovery plan following the GemPad incident","source":""}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 6a5fc0dd-f923-4c08-bc4c-6562b5e16548
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.