Fact-check findings
What an automated fact-checker found when it re-read Loopscale against the sources the page cites. Only the most recent review is shown.
These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.
“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.
Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.
disputed
1 claimThe reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.
- #16[disputed][awaiting moderator]in section: Broader DeFi Context
“By Q1 2025, the crypto industry had reportedly lost approximately $1.6 billion to DeFi attacks.”
reviewerBy Q1 2025, the crypto industry had reportedly lost approximately $1.6 billion to DeFi attacksThe page's cited source itself attributes the $1.6B figure primarily to a single centralized-exchange (Bybit) hack, not to DeFi protocol attacks; characterizing this as crypto industry losses 'to DeFi attacks' materially overstates DeFi's share of that total.Proposed correction (not yet applied)By Q1 2025, the crypto industry had reportedly lost approximately $1.6 billion to exchange hacks and smart contract exploits combined, according to PeckShield — over 90% of which was attributable to the single Bybit centralized-exchange hack rather than DeFi protocol attacks.
unverifiable
2 claimsNo source the reviewer could reach confirms or contradicts the claim.
- #18[unverifiable][awaiting moderator]in section: Broader DeFi Context
“No regulatory action or law enforcement outcome related to the Loopscale exploit has been publicly disclosed as of the time of this investigation.”
reviewerNo regulatory action or law enforcement outcome related to the Loopscale exploit has been publicly disclosedA negative claim (absence of any regulatory/law enforcement outcome) cannot be conclusively verified via search; no contradicting reports were found either. - #19[unverifiable][awaiting moderator]in the timeline
“Luke Truitt and Mary Gooneratne co-found Bridgesplit, focused on NFT fractionalization on Solana.”
reviewerLuke Truitt and Mary Gooneratne co-found Bridgesplit in February 2021, focused on NFT fractionalizationThe 2021 founding year and NFT-fractionalization focus are corroborated broadly, but the specific month (February 2021) in the timeline's date field has no cited source (source field is empty) and could not be independently confirmed.
stale
1 claimThe claim was accurate when written but events since have overtaken it.
- #15[stale][awaiting moderator]in section: Systemic Risk Factors
“As of early 2026, the protocol reported over $100 million in deposits and $38 million actively borrowed, suggesting continued user confidence following the incident, though the exploit remains a permanent part of the protocol's risk record.”
reviewerAs of early 2026, Loopscale reported over $100 million in deposits and $38 million actively borrowedThe $100M/$38M figures are real but originate from Loopscale's own Q3 2025 (~October 2025) recap, not 'early 2026' as the page states. More recent reporting (the page's own cited coincodecap.com source, and other Q1 2026 coverage) gives different, more current figures (~$95-141M deposits), making the page's date attribution stale/inaccurate.Proposed correction (not yet applied)As of Q3 2025 (roughly six months after launch), the protocol reported over $100 million in deposits and $38 million actively borrowed; by Q1 2026 deposits had grown further, to a reported $95-141 million depending on the source, suggesting continued user confidence following the incident, though the exploit remains a permanent part of the protocol's risk record.
confirmed
15 claimsThe cited evidence supports the claim as written.
- #1[confirmed][no action needed]in the summary
“Loopscale is a Solana-based DeFi lending protocol (formerly Bridgesplit) launched on April 10, 2025”
reviewerLoopscale launched on Solana on April 10, 2025Consistently corroborated across CoinMarketCap, Nasdaq, Rekt, and Halborn. - #2[confirmed][no action needed]in the summary
“On April 26, 2025 — just 16 days after launch — the protocol suffered a $5.8 million oracle pricing exploit affecting its Genesis Vaults”
reviewer$5.8 million oracle pricing exploit hit Loopscale's Genesis Vaults on April 26, 2025Widely corroborated by independent tier-2 sources. - #3[confirmed][no action needed]in the summary
“All stolen funds were ultimately recovered via negotiation with the exploiter, and user deposits suffered no permanent loss.”
reviewerAll stolen funds were recovered via negotiation and user deposits suffered no permanent lossCorroborated. - #4[confirmed][no action needed]in section: Protocol Background
“The protocol raised approximately $4.25 million in seed funding from Solana Labs, Coinbase Ventures, CoinFund, Jump Capital, and Solana Ventures, with total funding reaching an estimated $8.25 million ahead of its April 2025 launch.”
reviewerBridgesplit raised approximately $4.25 million in seed funding from Solana Labs, Coinbase Ventures, CoinFund, Jump Capital, and Solana VenturesThe $4.25M figure and investor list are independently confirmed by Bridgesplit's own funding announcement. Could not independently verify the $8.25M cumulative total figure from a primary source, but it is plausible given the seed round plus later funding. - #5[confirmed][no action needed]in section: The April 2025 Exploit
“the attacker was able to take out undercollateralized loans — borrowing more than the actual value of their deposited collateral — and withdraw approximately 5,726,725 USDC and 1,211 SOL across four separate transactions”
reviewerThe attacker drained approximately $5.8M / 5,726,725 USDC and 1,211 SOL in four transactions, ~12% of TVLPrecise figures independently corroborated. - #6[confirmed][no action needed]in section: The April 2025 Exploit
“The stolen USDC was subsequently converted to SOL (totalling approximately 39,474.5 SOL across attacker wallets) and partially bridged to Ethereum via Wormhole in three transactions totalling approximately $5.165 million.”
reviewerStolen USDC was converted to ~39,474.5 SOL and partially bridged to Ethereum via Wormhole in three transactions totaling ~$5.165 millionFigures are internally consistent with Rekt's staged-return breakdown. - #7[confirmed][no action needed]in section: The April 2025 Exploit
“Security researchers noted the attacker reverse-engineered Loopscale's functionality from its deployed binary, extracting the Interface Description Language and recreating internal operations locally — demonstrating that the protocol's closed-source code provided no meaningful security barrier.”
reviewerAttacker reverse-engineered Loopscale's functionality from the deployed binary, extracting the IDLDirect live fetch of ainvest.com returned 403 (bot-blocked), but content was corroborated via search engine cache/snippet and by a second independent source (Medium/Arcaze piece on reverse-engineering Solana closed programs). - #8[confirmed][no action needed]in section: Audit Failures and Pre-Launch Red Flags
“Loopscale's smart contracts were audited by OShield between January 16 and February 24, 2025. The audit identified three critical-severity issues, one high-severity issue, one medium-severity issue, and two informational issues. Critically, at least one identified issue concerned insufficient oracle validation: the audit specifically flagged that a malicious user could supply an oracle_account not present in the strategy's collateral map, allowing a custom account with manipulated pricing data to be injected. OShield's published report stated this issue was remediated by adding validation in the get_price() function against the oracle account stored in market_information.”
reviewerOShield audit (Jan 16 – Feb 24, 2025) found 3 critical, 1 high, 1 medium, 2 informational issues, and flagged a missing oracle_account validation issue remediated via get_price()/market_information checkDirectly verified against the primary audit report; wording in the page closely tracks the report's own language. - #9[confirmed][no action needed]in section: Audit Failures and Pre-Launch Red Flags
“A second audit by Sec3 was reportedly underway at the time of the exploit.”
reviewerA second audit by Sec3 was reportedly underway at the time of the exploitConfirmed via search corroboration across several outlets referencing the Sec3 audit. - #10[confirmed][no action needed]in section: Audit Failures and Pre-Launch Red Flags
“The Genesis Vaults launched with a $40 million deposit capacity despite the audit history, which Rekt News described as suggesting premature confidence in the protocol's security posture.”
reviewerGenesis Vaults launched with $40 million deposit capacity despite audit history, which Rekt News described as premature confidenceThis is a fair, non-cherry-picked paraphrase of Rekt's own framing. - #11[confirmed][no action needed]in section: Team Response and Fund Recovery
“Co-founder Mary Gooneratne publicly stated the team was 'fully mobilized to investigate and recover the stolen assets' and confirmed engagement with law enforcement.”
reviewerMary Gooneratne stated the team was 'fully mobilized to investigate and recover the stolen assets' and confirmed law enforcement engagementQuote substance confirmed directly against Gooneratne's own X post, found via search. - #12[confirmed][no action needed]in section: Team Response and Fund Recovery
“The exploiter countered, requesting a 20% bounty instead, and demonstrated alleged good faith by returning the smallest Wormhole-bridged tranche ($735,000) while retaining the larger amounts.”
reviewerLoopscale offered 90%/10% bounty with 24-hour deadline on April 27; attacker countered with 20% demand and returned the smallest $735,000 Wormhole tranche as good faithThis level of granular negotiation detail is confirmed specifically by Rekt News, which is the source cited for this section. - #13[confirmed][no action needed]in section: Team Response and Fund Recovery
“By April 29, 2025, all stolen assets (5,726,725 USDC and 1,211 SOL) had been returned in full. Loopscale confirmed no user deposits suffered permanent loss.”
reviewerBy April 29, 2025, all stolen assets had been fully returned and Loopscale confirmed no user deposits suffered permanent lossConfirmed. - #14[confirmed][no action needed]in section: Team Response and Fund Recovery
“The final bounty amount paid to the exploiter was not publicly disclosed by the team; Rekt News noted Loopscale remained 'suspiciously silent' on this point.”
reviewerThe final bounty amount was not publicly disclosed; Rekt News noted Loopscale remained 'suspiciously silent' on this pointQuote verified verbatim against source. - #17[confirmed][no action needed]in section: Broader DeFi Context
“On the same weekend as the Loopscale exploit, Term Finance — another DeFi lending protocol — also suffered a separate hack, with combined losses from both incidents exceeding $7 million.”
reviewerOn the same weekend as the Loopscale exploit, Term Finance also suffered a separate hack, with combined losses exceeding $7 millionConfirmed.