← Hyperdrive HL3 decisions on this page
Audit log
Every state-changing event for Hyperdrive HL: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-05-29 16:12:55ZScore: ? → ? (no score change)anchoranchored
- chain
- ●mainnet-betaslot 422,972,345
- sig
5p64ueVh4gJH…y2neBt87explorer ↗- hash
GSXxkG9FUkWf…SRRGjA2Vsha256 → base58
verifying row…full verify ↗canonical bytes (6218 B) ▸
{"actor":"system:backfill","investigation_id":"dd592b49-5cdd-4dcf-b6aa-39f2c6ac9a89","kind":"publish","page_slug":"hyperdrive-hl","published_at":"2026-05-29T16:12:55.106Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Hyperdrive HL","sections":[{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://www.cmointern.com/2025/05/hyperdrive-secures-6m-series-led-by.html","type":"other","url":""},{"credibility":3,"name":"https://defillama.com/protocol/hyperdrive-hl","type":"other","url":""},{"credibility":3,"name":"https://x.com/hyperdrivedefi/status/1925944813427302528","type":"other","url":""},{"credibility":3,"name":"https://hyperdrive-2.gitbook.io/hyperdrive/for-developers/security-audits","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://x.com/CertiKAlert/status/1972117426893738341","type":"other","url":""},{"credibility":3,"name":"https://www.theblock.co/post/372662/hyperliquid-based-hyperdrive-loses-782000-after-smart-contract-exploit","type":"other","url":""},{"credibility":3,"name":"https://crypto.news/hyperliquid-hyperdrive-resumes-services-700k-hack-2025/","type":"other","url":""},{"credibility":3,"name":"https://www.web3isgoinggreat.com/single/hyperdrive-exploit","type":"other","url":""},{"credibility":3,"name":"https://coincentral.com/hyperdrive-loses-782000-in-tokens-after-smart-contract-exploit-attack/","type":"other","url":""},{"credibility":3,"name":"https://cryptonews.com.au/news/hyperdrive-exploit-drains-us782k-in-third-major-hyperliquid-security-breach-131037/","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://www.ainvest.com/news/exploit-days-exposes-hyperliquid-security-weaknesses-2509/","type":"other","url":""},{"credibility":3,"name":"https://cryptonews.com.au/news/hyperdrive-exploit-drains-us782k-in-third-major-hyperliquid-security-breach-131037/","type":"other","url":""},{"credibility":3,"name":"https://www.ccn.com/news/crypto/hackers-hit-hyperliquid-twice-stolen-hyperdrive-exploit/","type":"other","url":""},{"credibility":3,"name":"https://www.arringtoncapital.com/blog/hyperliquids-tipping-point-three-things-they-must-do-now/","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://hyperdrive-2.gitbook.io/hyperdrive/for-developers/security-audits","type":"other","url":""},{"credibility":3,"name":"https://www.theblock.co/post/372662/hyperliquid-based-hyperdrive-loses-782000-after-smart-contract-exploit","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://crypto.news/hyperliquid-hyperdrive-resumes-services-700k-hack-2025/","type":"other","url":""},{"credibility":3,"name":"https://www.mitrade.com/insights/news/live-news/article-3-1155419-20250929","type":"other","url":""},{"credibility":3,"name":"https://x.com/hyperdrivedefi/status/1972095669403111519","type":"other","url":""},{"credibility":3,"name":"https://coincentral.com/hyperdrive-loses-782000-in-tokens-after-smart-contract-exploit-attack/","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://x.com/CertiKAlert/status/1972117426893738341","type":"other","url":""},{"credibility":3,"name":"https://www.web3isgoinggreat.com/single/hyperdrive-exploit","type":"other","url":""},{"credibility":3,"name":"https://www.theblock.co/post/372662/hyperliquid-based-hyperdrive-loses-782000-after-smart-contract-exploit","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://medium.com/@hyperdrive_fi/hyperdrive-token-airdrop-miles-hlp-and-hype-lst-5417f1d78544","type":"other","url":""},{"credibility":3,"name":"https://airdrops.io/hyperdrive/","type":"other","url":""},{"credibility":3,"name":"https://markets.coinpedia.org/hyperdrive/","type":"other","url":""},{"credibility":3,"name":"https://www.cmointern.com/2025/05/hyperdrive-secures-6m-series-led-by.html","type":"other","url":""}]}],"sources_used":[],"summary":"Hyperdrive HL (formerly Ambit Finance) is a stablecoin lending and liquid-staking protocol deployed on Hyperliquid EVM, which raised a $6 million Series A in May 2025 led by Hack VC and Arrington Capital. On September 27, 2025, an attacker exploited an arbitrary-call vulnerability in the protocol's router contract, draining approximately $782,000 in USDT0 and thBILL tokens across two markets. The team paused operations, patched the vulnerability, and compensated affected users before resuming, though the incident occurred within a broader wave of security breaches across the Hyperliquid ecosystem.","timeline":[{"date":"2025-05-24","event":"Hyperdrive HL (formerly Ambit Finance) closes $6 million Series A funding round led by Hack VC and Arrington Capital.","source":""},{"date":"2025-05-27","event":"Hyperdrive HL officially launches on Hyperliquid EVM with stablecoin lending, HYPED liquid staking, and HLP vault tokenization products.","source":""},{"date":"2025-09-26","event":"HyperVault, a separate Hyperliquid-based protocol, suffers an alleged $3.6 million loss in a suspected rug pull, with project social media disappearing.","source":""},{"date":"2025-09-27","event":"Attacker exploits an arbitrary-call vulnerability in Hyperdrive HL's router contract, draining 672,934 USDT0 and 110,244 thBILL tokens (~$782,000) from two markets. Stolen funds are bridged to Ethereum and BNB Chain via deBridge.","source":""},{"date":"2025-09-27","event":"CertiK publishes on-chain alert identifying the arbitrary call vulnerability in Hyperdrive's router contract. Hyperdrive team announces market pause and ongoing investigation on X.","source":""},{"date":"2025-09-27","event":"Hyperdrive team reports identifying the root cause and fixing the vulnerability. Team announces compensation plan for affected accounts.","source":""},{"date":"2025-09-29","event":"Hyperdrive team confirms all affected accounts have been remediated and market functions have been restored. Post-mortem report promised.","source":""}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 1c9e3511-5fb1-44eb-8147-18030c377cfb - #2reviewby reviewerreviewer2026-08-27 11:02:39ZScore: 45 → 45 (no score change)Every atomic claim actually made by the summary and timeline (16 total) is independently corroborated by multiple outside sources covering the May 2025 Series A raise and the September 27, 2025 router-contract exploit; no contradictions or link rot were found among the sources reachable. However, the page's sources_used array is empty and all 7 sections have empty content, so 'confirmed' here reflects verification against the outside world rather than against any evidence the page itself supplies — the page currently asserts facts without citing anything to back them, despite listing source names under each (contentless) section. The most significant substantive gap is that the page omits Hyperdrive's own pre-exploit audit history, which is directly relevant to assessing the exploit's severity and the protocol's security posture.anchoranchored
- chain
- ●mainnet-betaslot 443,525,551
- sig
2vcG9Qx4uuFh…N1W9wVegexplorer ↗- hash
AqfkkCuQDVAb…gTkZwP1Jsha256 → base58
verifying row…full verify ↗canonical bytes (1190 B) ▸
{"actor":"reviewer","decided_at":"2026-08-27T11:02:39.020Z","decision":"review","investigation_id":"dd592b49-5cdd-4dcf-b6aa-39f2c6ac9a89","new_score":45,"page_slug":"hyperdrive-hl","prev_score":45,"reason":"Every atomic claim actually made by the summary and timeline (16 total) is independently corroborated by multiple outside sources covering the May 2025 Series A raise and the September 27, 2025 router-contract exploit; no contradictions or link rot were found among the sources reachable. However, the page's sources_used array is empty and all 7 sections have empty content, so 'confirmed' here reflects verification against the outside world rather than against any evidence the page itself supplies — the page currently asserts facts without citing anything to back them, despite listing source names under each (contentless) section. The most significant substantive gap is that the page omits Hyperdrive's own pre-exploit audit history, which is directly relevant to assessing the exploit's severity and the protocol's security posture.","score_delta":0,"sequence_num":2,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}Verify offline (run on your own machine)python -m src.verify_decision 8683a9bf-566a-46e8-bb71-012d70b06991 - #3review reviseby judgejudge2026-08-27 11:02:39ZScore: 45 → 35 (-10)Every checkable claim on this page held up: the reviewer verified all 16 factual statements in the summary and timeline against outside reporting and found zero disputed or unverifiable items, so disputed_pct computes to 0.0%. But the review also flagged, at high priority, that the page itself contains no actual written content -- all seven sections are empty and cite no supporting sources (coverage_gaps[0]) -- and that it omits a materially relevant fact from a source it lists: Hyperdrive's contracts had passed multiple audits before the exploit that later drained the protocol, and the page never says so (coverage_gaps[1]). A page can have a perfect factual record and still fail to inform readers of the most decision-relevant thing its own cited source contains. That gap, not any false statement, is why this page does not clear a clean approval.anchoranchored
- chain
- ●mainnet-betaslot 443,525,572
- sig
3ayhPkAgZXhs…VV9advXVexplorer ↗- hash
13N6pV3DfcSh…sSQdLpmJsha256 → base58
verifying row…full verify ↗canonical bytes (1213 B) ▸
{"actor":"judge","decided_at":"2026-08-27T11:02:39.020Z","decision":"review_revise","investigation_id":"dd592b49-5cdd-4dcf-b6aa-39f2c6ac9a89","new_score":35,"page_slug":"hyperdrive-hl","prev_score":45,"reason":"Every checkable claim on this page held up: the reviewer verified all 16 factual statements in the summary and timeline against outside reporting and found zero disputed or unverifiable items, so disputed_pct computes to 0.0%. But the review also flagged, at high priority, that the page itself contains no actual written content -- all seven sections are empty and cite no supporting sources (coverage_gaps[0]) -- and that it omits a materially relevant fact from a source it lists: Hyperdrive's contracts had passed multiple audits before the exploit that later drained the protocol, and the page never says so (coverage_gaps[1]). A page can have a perfect factual record and still fail to inform readers of the most decision-relevant thing its own cited source contains. That gap, not any false statement, is why this page does not clear a clean approval.","score_delta":-10,"sequence_num":3,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}Verify offline (run on your own machine)python -m src.verify_decision 5155fc8c-51a5-4cc0-b159-931755c91509
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.