Summary
Maestro is a Telegram-based crypto trading bot developed by Gearlay Technologies Inc. (Canada) that enables sniping, copy-trading, and wallet management across 14 blockchains. On October 24, 2023, a critical access-control vulnerability in its MaestroRouter2 smart contract was exploited, draining approximately 280 ETH (~$500,000) from 106 user accounts; the team subsequently refunded all affected users with 610 ETH (~$1.1 million) sourced from its own revenue. The platform operates a partial-custody model in which user private keys are encrypted and stored on Maestro servers, representing a persistent systemic risk.
Connected Entities
1 entitiesTimeline(11 events)
2021-01-01
Gearlay Technologies Inc. founded in Canada by Abbas Abou Daya.
2022-07-27
Maestro bot launches as a Telegram-based DeFi trading tool.
2023-05-01
Maestro revenue peaks at approximately $4.8 million in a single month, according to DefiLlama data.
2023-10-13
Maestro deploys updated MaestroRouter2 smart contract containing an unverified access-control vulnerability.
2023-10-24
Attacker exploits the MaestroRouter2 transferFrom() vulnerability, draining approximately 280 ETH (~$500,000) from 106 user accounts across 11 token types.
2023-10-24
Maestro detects the exploit and upgrades the router contract to a benign counter contract within 30 minutes, halting further theft. Trading restored within 2 hours.
2023-10-24
PeckShield identifies stolen funds routed to Railgun cross-chain privacy protocol for obfuscation.
2023-10-25
MaestroBots announces full refund commitment for all 106 affected users.
2023-11-06
Maestro completes refund campaign within 10 hours of announcement, disbursing 610 ETH (~$1.1 million) from its own revenue — 120% of losses for two token types.
2023-11-01
CertiK confirms integrity of patched MaestroRouter2 following exploit resolution.
2025-01-01
Gearlay Technologies about page updated to describe Maestro as a platform the company 'previously built and sold,' suggesting a completed divestiture; no acquisition announcement identified in major media.
Decision Log
- hash: 7dCpAJzN9pCfPZXti3Na4qVNgMhoDRYKD5T1dXkk94yL
- hash: 65F4tog7WeP8Y3CDqUJVfaBDac1Q3DF3cuazJG7thZsr
- hash: 7ah6mZtPcmNPVB4EWXUuYYpLvrQob1gKZZ2Gh5crRXbN
This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.
model: claude-sonnet-4-6
generated: 5/4/2026, 2:54:37 AM
last updated: 6/9/2026, 11:23:03 PM
avoid.net — verified advice for a post-truth world