Skip to main content
Sign in
Lodestar V01 decision on this page

Audit log

Every state-changing event for Lodestar V0: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions carry three independent witnesses — the original source, an Internet Archive snapshot taken at submission time, and a Solana memo signed by our publicly-disclosed publisher key.

  1. #1publishby system:backfill
    2026-05-28 15:02:22Z
    Score: ?? (no score change)
    anchoranchored
    chain
    mainnet-betaslot 422,743,546
    sig
    5Ktm2Hr53Zm6…qU6q9ueuexplorer ↗
    hash
    9r5bueA5tFfR…XNaqYEjRsha256 → base58
    verifying row…full verify ↗
    canonical bytes (6998 B) ▸
    {"actor":"system:backfill","investigation_id":"7a6a9a8c-cef4-4d72-89a6-e56479ac9e6f","kind":"publish","page_slug":"lodestar-v0","published_at":"2026-05-28T15:02:22.655Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Lodestar V0","sections":[{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://iq.wiki/wiki/lodestar-finance","type":"other","url":""},{"credibility":3,"name":"https://docs.lodestarfinance.io/","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://www.certik.com/resources/blog/TqTyq4vYHl8JzS7zyJye9-lodestar-finance-incident-analysis","type":"other","url":""},{"credibility":3,"name":"https://cointelegraph.com/news/lodestar-finance-exploited-in-flash-loan-attack","type":"other","url":""},{"credibility":3,"name":"https://www.halborn.com/blog/post/explained-the-lodestar-finance-hack-november-2022","type":"other","url":""},{"credibility":3,"name":"https://medium.com/@plutus.fi/official-statement-on-the-lodestar-finance-exploit-cf2b501647f5","type":"other","url":""},{"credibility":3,"name":"https://web3isgoinggreat.com/single/lodestar-finance-attacked","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://cointelegraph.com/news/hackers-copied-mango-markets-attacker-s-methods-to-exploit-lodestar-certik","type":"other","url":""},{"credibility":3,"name":"https://www.certik.com/resources/blog/TqTyq4vYHl8JzS7zyJye9-lodestar-finance-incident-analysis","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://www.certik.com/resources/blog/TqTyq4vYHl8JzS7zyJye9-lodestar-finance-incident-analysis","type":"other","url":""},{"credibility":3,"name":"https://x.com/LodestarFinance/status/1601687317604839424","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://iq.wiki/wiki/lodestar-finance","type":"other","url":""},{"credibility":3,"name":"https://claim.lodestarfinance.io/","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://x.com/LodestarFinance/status/1684418629297930240","type":"other","url":""},{"credibility":3,"name":"https://defillama.com/protocol/lodestar-finance","type":"other","url":""},{"credibility":3,"name":"https://defillama.com/protocol/lodestar-v1","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://www.halborn.com/blog/post/explained-the-lodestar-finance-hack-november-2022","type":"other","url":""}]}],"sources_used":[{"credibility":2,"name":"CertiK — Lodestar Finance Incident Analysis","type":"research","url":"https://www.certik.com/resources/blog/TqTyq4vYHl8JzS7zyJye9-lodestar-finance-incident-analysis"},{"credibility":2,"name":"CoinTelegraph — Lodestar Finance exploited in flash loan attack","type":"news_article","url":"https://cointelegraph.com/news/lodestar-finance-exploited-in-flash-loan-attack"},{"credibility":2,"name":"CoinTelegraph — Hackers copied Mango Markets attacker's methods to exploit Lodestar","type":"news_article","url":"https://cointelegraph.com/news/hackers-copied-mango-markets-attacker-s-methods-to-exploit-lodestar-certik"},{"credibility":2,"name":"Halborn — Explained: The Lodestar Finance Hack (November 2022)","type":"research","url":"https://www.halborn.com/blog/post/explained-the-lodestar-finance-hack-november-2022"},{"credibility":2,"name":"Web3 Is Going Great — Lodestar Finance attacked and drained","type":"community_report","url":"https://web3isgoinggreat.com/single/lodestar-finance-attacked"},{"credibility":2,"name":"PlutusDAO — Official Statement on the Lodestar Finance Exploit","type":"official","url":"https://medium.com/@plutus.fi/official-statement-on-the-lodestar-finance-exploit-cf2b501647f5"},{"credibility":2,"name":"IQ.wiki — Lodestar Finance","type":"research","url":"https://iq.wiki/wiki/lodestar-finance"},{"credibility":2,"name":"DeFiLlama — Lodestar Finance TVL","type":"on_chain","url":"https://defillama.com/protocol/lodestar-finance"},{"credibility":2,"name":"DeFiLlama — Lodestar V1 TVL","type":"on_chain","url":"https://defillama.com/protocol/lodestar-v1"},{"credibility":3,"name":"Lodestar Finance Twitter — Exploit acknowledgment and hacker outreach","type":"social_media","url":"https://x.com/LodestarFinance/status/1601687317604839424"},{"credibility":3,"name":"Lodestar Finance Twitter — V1 launch announcement","type":"social_media","url":"https://x.com/LodestarFinance/status/1684418629297930240"},{"credibility":2,"name":"Unchained Crypto — DeFi Lending Platform Lodestar Finance Loses $6.9M in Oracle Exploit","type":"news_article","url":"https://unchainedcrypto.com/defi-lending-platform-lodestar-finance-loses-6-9m-in-oracle-exploit/"},{"credibility":2,"name":"EigenPhi — $6.9M Lodestar Exploit: Oracle Manipulations","type":"research","url":"https://eigenphi.substack.com/p/69m-lodestar-exploit-oracle-manipulations"}],"summary":"Lodestar V0 is the original deployment of Lodestar Finance, an algorithmic money market lending protocol on Arbitrum. On December 10, 2022, the protocol suffered a critical flash loan exploit in which an attacker manipulated the plvGLP price oracle to drain approximately $6.9 million in user funds. The protocol was subsequently relaunched as Lodestar V1 in July 2023; V0 remains abandoned with negligible TVL (~$95K) and the attacker was never publicly identified.","timeline":[{"date":"2022-12-08","event":"Attacker wallet funded with approximately 1,500 ETH in preparation for the exploit.","source":""},{"date":"2022-12-10","event":"Flash loan oracle manipulation exploit executed against Lodestar V0 on Arbitrum; approximately $6.5–6.9 million drained from the protocol.","source":""},{"date":"2022-12-10","event":"Lodestar Finance team publicly acknowledged the exploit and appealed to the attacker for a white-hat agreement via Twitter.","source":""},{"date":"2022-12-10","event":"PlutusDAO published official statement clarifying the vulnerability was in Lodestar's oracle implementation, not the plvGLP contract.","source":""},{"date":"2022-12-11","event":"CertiK published incident analysis identifying attacker wallet 0xb50f...5db13 and detailing the on-chain attack flow.","source":""},{"date":"2022-12-12","event":"Halborn published post-mortem analysis classifying the exploit as a preventable oracle vulnerability.","source":""},{"date":"2023-04-08","event":"Lodestar Finance relaunched on Arbitrum, attracting over $30 million in TVL.","source":""},{"date":"2023-07-27","event":"Lodestar V1 launched; team announced migration of incentives from V0 to V1.","source":""},{"date":"2023-10-01","event":"Lodestar team reported approximately one-third of hack losses repaid to affected depositors; 750,000 esLODE tokens allocated for further compensation.","source":""}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 13afd34d-c108-440c-8e17-1646b287547d
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.