Skip to main content
Sign in
Makina Finance1 decision on this page

Audit log

Every state-changing event for Makina Finance: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-08-02 12:09:40Z
    Score: ?? (no score change)
    anchorpending
    chain
    hash
    3ZRZUhQdXqrw…uxaLfBuKsha256 → base58
    verifying row…
    canonical bytes (21866 B) ▸
    {"actor":"system:backfill","investigation_id":"ae5806de-d332-4745-a0b1-3e6eae151833","kind":"publish","page_slug":"makina-finance","published_at":"2026-08-02T12:09:40.061Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Makina Finance","sections":[{"content":"Makina Finance is a non-custodial DeFi execution engine headquartered in Grand Cayman, Cayman Islands, that allows asset managers, AI agents, yield funds, and crypto-native users to deploy institutional-grade yield strategies on-chain through entities called \"Machines\" (vaults). The protocol uses atomic execution and multi-chain \"Calibers\" to enable flexible strategy deployment without requiring new audits for each integration. Makina's DUSD (Dialectic USD) stablecoin was a core product, and the protocol operated three primary Machines: DUSD, DETH, and DBIT. At the time of the exploit, the protocol held approximately $100 million in total value locked according to DeFiLlama data.","heading":"Protocol Overview","severity":"low","sources":[{"credibility":2,"name":"Makina Finance Raises $3M to Power Institutional DeFi - CypherHunter","type":"news_article","url":"https://www.cypherhunter.com/en/e/makina-finance-raised-funding-2025-06-25/"},{"credibility":2,"name":"Makina has been exploited for $4.13 million, DUSD/USDC CurveStable pool drained - Cryptopolitan","type":"news_article","url":"https://www.cryptopolitan.com/makina-exploited-4-13-dusd-pool-drained/"}]},{"content":"Makina Finance closed a $3 million strategic funding round in June 2025. Disclosed investors include Hypernative Labs, Kiln, Bodhi Ventures, baseDAO, Steakhouse Financial, Cyber Fund, and Interop Ventures, alongside angel investors including Adrian Brink, Ryan Zurrer, Yaoqi Jia, Dan Reecer, and Jerome de Tychey. The company appointed Sath Ganesarajah, described as a veteran in the digital asset field, as non-executive chairman on June 30, 2025. Stated uses of the funding included the platform's official launch, AI integration, multi-chain expansion, vault product suite growth, and enhanced security measures including code audits and stress testing. The protocol also conducted an ICO on the Legion platform seeking additional capital.","heading":"Funding and Investors","severity":"low","sources":[{"credibility":2,"name":"Makina raised $3M Strategic Funding - CypherHunter","type":"news_article","url":"https://www.cypherhunter.com/en/e/makina-finance-raised-funding-2025-06-25/"},{"credibility":2,"name":"Institutional-level DeFi execution engine Makina completes $3 million strategic round - MEXC News","type":"news_article","url":"https://www.mexc.com/news/20992"},{"credibility":2,"name":"Makina Finance Raises $3M to Power Institutional DeFi","type":"news_article","url":"https://www.cmointern.com/2025/06/makina-finance-raises-3m-to-power.html?m=1"}]},{"content":"On January 20, 2026, at 03:40:35 UTC (Ethereum block 24,273,362), Makina Finance suffered an oracle manipulation exploit resulting in the loss of approximately 1,299 ETH valued at $4.13 million. The primary attack transaction was 0x569733b8016ef9418f0b6bde8c14224d9e759e79301499908ecbcd956a0651f5. The attacker (address 0x2F934B0Fd5c4f99BAb37d47604a3a1AEADEF1CCc) borrowed approximately 280 million USDC via flash loans sourced from Morpho and Aave V2. Approximately 170 million USDC was injected into the DUSD/USDC Curve stableswap pool to create severe imbalance, artificially inflating the MachineShareOracle share price by approximately 31%. The attacker then deposited remaining capital at the manipulated valuation and exited at a profit. The exploited vulnerability was the protocol's permissionless updateTotalAum() function, which allowed any caller to trigger a price update using the current manipulated spot price without time-weighted averaging, delays, or sanity checks against external benchmarks. An MEV builder (address 0xa6c2) front-ran the original exploit transaction and captured the majority of stolen funds before they could be extracted by the original attacker.","heading":"January 2026 Oracle Manipulation Exploit","severity":"critical","sources":[{"credibility":2,"name":"Makina - Rekt News","type":"research","url":"https://rekt.news/makina-rekt"},{"credibility":2,"name":"Analyzing the $4M Makina Finance Exploit - Verichains","type":"research","url":"https://blog.verichains.io/p/analyzing-the-4m-makina-finance-exploit"},{"credibility":2,"name":"Makina Incident Analysis - CertiK","type":"research","url":"https://www.certik.com/resources/blog/makina-incident-analysis"},{"credibility":1,"name":"Makina Finance suffers $5 million stablecoin pool exploit: CertiK - The Block","type":"news_article","url":"https://www.theblock.co/post/386202/makina-finance-pool-exploited"},{"credibility":1,"name":"Ethereum DeFi Platform Makina Hit by Flash Loan Exploit - Decrypt","type":"news_article","url":"https://decrypt.co/355132/ethereum-defi-platform-makina-hit-by-flash-loan-exploit-loses-4m-in-eth"},{"credibility":1,"name":"Makina loses $4.1 million in exploit tied to price-feed manipulation - Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/news/makina-loses-4-1-million-113520142.html"}]},{"content":"Security researchers identified three compounding architectural vulnerabilities that enabled the exploit. First, the protocol's oracle update function (updateTotalAum()) lacked access controls, allowing any external actor to trigger share price recalculation at an arbitrary moment, including mid-flash-loan when pool prices were maximally distorted. Second, the AUM and share price calculations relied on synchronous spot price reads from Curve pools using functions such as calc_withdraw_one_coin() and balance(), with no time-weighted average price (TWAP) mechanism, no delay, and no comparison against external price benchmarks such as Chainlink feeds. Third, the protocol's Weiroll scripting integration — used to enable flexible atomic transaction execution — maintained pre-approved command sets that included price-sensitive Curve functions, allowing an attacker to construct complex atomic transactions that manipulated the oracle state within a single block. The Caliber contract trusted Merkle-validated Weiroll instructions that could call Curve.finance's DAI/USDC/USDT Pool.balance() and MIM-3LP3CRV-f.calc_withdraw_one_coin() functions, whose outputs were used directly as multiplier terms in AUM calculations without validation.","heading":"Root Cause: Three Compounding Design Flaws","severity":"critical","sources":[{"credibility":2,"name":"Makina - Rekt News","type":"research","url":"https://rekt.news/makina-rekt"},{"credibility":2,"name":"Makina Incident Analysis - CertiK","type":"research","url":"https://www.certik.com/resources/blog/makina-incident-analysis"},{"credibility":2,"name":"Makina's $4M Hack (Oracle Manipulation - Explained) - QuillAudits","type":"research","url":"https://www.quillaudits.com/blog/hack-analysis/makina-4m-hack-explained"},{"credibility":2,"name":"Analyzing the $4M Makina Finance Exploit - Verichains","type":"research","url":"https://blog.verichains.io/p/analyzing-the-4m-makina-finance-exploit"}]},{"content":"Prior to the exploit, Makina Finance underwent six separate security reviews. These included: a fuzz and invariant testing engagement by Enigma Dark (July 2025), core and periphery audits by SigmaPrime (August 2025), two separate audits by ChainSecurity (September 2025), a competitive bug bounty review by Cantina (September-October 2025), and a core and periphery review by OtterSec (November 2025). Despite this extensive audit history, the specific vault initialization step that enabled the exploit — the deployment of the DUSD/USDC Curve pool integration — occurred after all security reviews concluded and was outside the scope of each engagement. Cantina's audit explicitly listed \"oracle price/liquidity pool manipulation with unchecked synchronous deposits\" as out of scope, which was precisely the attack vector deployed approximately three months later. The protocol's architectural flexibility, marketed as a strength allowing operators to deploy strategies without custom code or new audits per integration, created an exploitable gap between audited core contracts and live production integrations.","heading":"Audit History and Scope Gap","severity":"high","sources":[{"credibility":2,"name":"Makina - Rekt News","type":"research","url":"https://rekt.news/makina-rekt"},{"credibility":2,"name":"Makina Incident Analysis - CertiK","type":"research","url":"https://www.certik.com/resources/blog/makina-incident-analysis"}]},{"content":"The original attacker's exploit contract was decompiled and replicated by MEV searchers before execution completed, resulting in the majority of stolen funds being captured by MEV bots rather than the exploit originator. An MEV builder at address 0xa6c2 front-ran the exploit and captured approximately $4.14 million in total. The stolen ETH was redistributed across two MEV-associated wallets: address 0xbed26250Db2097318386F540fD546acEDf7bdE25 held approximately $3.3 million, and address 0x573Db3Aed219EfD4D2cDABC0D00366E7B80F910E held approximately $880,000 (the latter associated with Rocket Pool). As of January 22, 2026, no funds had been returned in response to Makina's bounty offer.","heading":"MEV Interception and Fund Distribution","severity":"high","sources":[{"credibility":2,"name":"Makina - Rekt News","type":"research","url":"https://rekt.news/makina-rekt"},{"credibility":2,"name":"Makina has been exploited for $4.13 million, DUSD/USDC CurveStable pool drained - Cryptopolitan","type":"news_article","url":"https://www.cryptopolitan.com/makina-exploited-4-13-dusd-pool-drained/"},{"credibility":2,"name":"Makina Finance Exploit Drains 1,299 ETH - Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/01/20/makina-finance-exploit-drains-1299-eth-in-major-defi-hack/"}]},{"content":"Makina Finance acknowledged the incident at approximately 6:42 AM UTC on January 20, 2026, stating the issue was isolated to DUSD LP positions on Curve and advising liquidity providers to withdraw their funds. The protocol activated \"security mode\" across all Machines, pausing operations to prevent further losses. Vulnerable positions, including MIM-3CRV, were unwound shortly after the incident. The team sent on-chain messages to MEV recipients offering a 10% whitehat bounty — approximately 102.3 ETH — under their SafeHarbor WhiteHat policy in exchange for return of approximately 920.7 ETH. On January 25, 2026, the team issued a demand for return of $513,994.89 USDC from a separate identified wallet (0xddf6f217951a1e484ee6b04d621c861bf38d0656), characterizing those profits as resulting from criminal actions and offering an amicable resolution before further escalation. Recovery Mode was subsequently disabled and the protocol executed a v1.1 upgrade audited by ChainSecurity. Machines returned to a normal state by January 26, 2026, with redemptions reactivated. Users holding over $100,000 in DUSD were required to complete AML/KYC screening via Discord before redemption. According to available reports, over $3.65 million was ultimately recovered and distributed to affected users. The DUSD/USDC Curve pool integration was deprecated, with planned migration to Uniswap.","heading":"Post-Exploit Response and Recovery","severity":"medium","sources":[{"credibility":2,"name":"Makina Protocol Upgrade and Re-Activation of Machines - Makina Substack","type":"official","url":"https://makinafi.substack.com/p/makina-protocol-upgrade-and-re-activation"},{"credibility":2,"name":"Makina Finance Seeks Return of $513,994 USDC from Exploit - Phemex News","type":"news_article","url":"https://phemex.com/news/article/makina-finance-demands-return-of-513994-usdc-from-exploit-profits-55868"},{"credibility":2,"name":"Makina - Rekt News","type":"research","url":"https://rekt.news/makina-rekt"},{"credibility":2,"name":"Flash loan exploit leads to USD 4 mln losses for Makina - The Paypers","type":"news_article","url":"https://thepaypers.com/fraud-and-fincrime/news/makina-finance-loses-usd-4-million-in-eth-after-flash-loan-exploit"}]},{"content":"Following the exploit, Makina Finance upgraded its core contracts from v1.0 to v1.1. Key security hardening measures included implementation of a \"restricted accounting mode\" that limits valuation updates to Operators, security councils, and pre-registered entities — directly addressing the permissionless oracle update vulnerability. Maximum price change parameters based on time elapsed since the previous update were also added, functioning as a circuit breaker against single-block manipulation. Bridge support was expanded via LayerZero's OFT standard for cross-chain deployment. The v1.1 upgrade underwent a security audit by ChainSecurity before reactivation. A full post-mortem was announced but had not been published as of the latest available reporting.","heading":"Protocol Upgrade and Security Hardening","severity":"low","sources":[{"credibility":2,"name":"Makina Protocol Upgrade and Re-Activation of Machines - Makina Substack","type":"official","url":"https://makinafi.substack.com/p/makina-protocol-upgrade-and-re-activation"}]},{"content":"The Makina Finance exploit was cited in broader analyses of DeFi hacks and exploits in 2026. The incident illustrates a pattern identified by security researchers in which protocols conducting extensive audits of core contracts remain vulnerable when integrations with external liquidity sources are deployed post-audit without equivalent security review. The pattern of oracle manipulation via flash loan-inflated Curve pools was previously documented in other DeFi exploits. The Makina case is notable for the role of MEV infrastructure in capturing exploit proceeds, effectively redirecting stolen funds from the original attacker to MEV searchers — complicating recovery and attribution efforts.","heading":"Broader DeFi Context","severity":"medium","sources":[{"credibility":2,"name":"Biggest DeFi Hacks and Exploits of 2026 - CCN","type":"news_article","url":"https://www.ccn.com/education/crypto/defi-hacks-exploits-causes-crypto-stolen-2026/"},{"credibility":2,"name":"Makina's $4M Hack due to Oracle Manipulation - Coinmonks / Medium","type":"research","url":"https://medium.com/coinmonks/makinas-4m-hack-8afca700c00c"},{"credibility":2,"name":"DeFi Protocol Makina Suffers Devastating $5M Flash Loan Hack - CryptoRank","type":"news_article","url":"https://cryptorank.io/news/feed/1e04f-makina-defi-protocol-hack"}]}],"sources_used":[{"credibility":2,"name":"Makina - Rekt News","type":"research","url":"https://rekt.news/makina-rekt"},{"credibility":2,"name":"Makina Incident Analysis - CertiK","type":"research","url":"https://www.certik.com/resources/blog/makina-incident-analysis"},{"credibility":2,"name":"Analyzing the $4M Makina Finance Exploit - Verichains","type":"research","url":"https://blog.verichains.io/p/analyzing-the-4m-makina-finance-exploit"},{"credibility":1,"name":"Makina Finance suffers $5 million stablecoin pool exploit - The Block","type":"news_article","url":"https://www.theblock.co/post/386202/makina-finance-pool-exploited"},{"credibility":1,"name":"Ethereum DeFi Platform Makina Hit by Flash Loan Exploit - Decrypt","type":"news_article","url":"https://decrypt.co/355132/ethereum-defi-platform-makina-hit-by-flash-loan-exploit-loses-4m-in-eth"},{"credibility":1,"name":"Makina loses $4.1 million in exploit tied to price-feed manipulation - Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/news/makina-loses-4-1-million-113520142.html"},{"credibility":2,"name":"Makina has been exploited for $4.13 million - Cryptopolitan","type":"news_article","url":"https://www.cryptopolitan.com/makina-exploited-4-13-dusd-pool-drained/"},{"credibility":2,"name":"Makina Finance Exploit Drains 1,299 ETH - Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/01/20/makina-finance-exploit-drains-1299-eth-in-major-defi-hack/"},{"credibility":2,"name":"Makina's $4M Hack (Oracle Manipulation - Explained) - QuillAudits","type":"research","url":"https://www.quillaudits.com/blog/hack-analysis/makina-4m-hack-explained"},{"credibility":2,"name":"Makina's $4M Hack due to Oracle Manipulation - Coinmonks","type":"research","url":"https://medium.com/coinmonks/makinas-4m-hack-8afca700c00c"},{"credibility":2,"name":"Makina Protocol Upgrade and Re-Activation - Makina Substack","type":"official","url":"https://makinafi.substack.com/p/makina-protocol-upgrade-and-re-activation"},{"credibility":2,"name":"Makina Finance Seeks Return of $513,994 USDC - Phemex News","type":"news_article","url":"https://phemex.com/news/article/makina-finance-demands-return-of-513994-usdc-from-exploit-profits-55868"},{"credibility":2,"name":"Makina raised $3M Strategic Funding - CypherHunter","type":"news_article","url":"https://www.cypherhunter.com/en/e/makina-finance-raised-funding-2025-06-25/"},{"credibility":2,"name":"Institutional-level DeFi execution engine Makina completes $3M round - MEXC News","type":"news_article","url":"https://www.mexc.com/news/20992"},{"credibility":2,"name":"Flash loan exploit leads to USD 4 mln losses for Makina - The Paypers","type":"news_article","url":"https://thepaypers.com/fraud-and-fincrime/news/makina-finance-loses-usd-4-million-in-eth-after-flash-loan-exploit"},{"credibility":2,"name":"DeFi Protocol Makina Suffers Devastating $5M Flash Loan Hack - CryptoRank","type":"news_article","url":"https://cryptorank.io/news/feed/1e04f-makina-defi-protocol-hack"},{"credibility":2,"name":"Biggest DeFi Hacks and Exploits of 2026 - CCN","type":"news_article","url":"https://www.ccn.com/education/crypto/defi-hacks-exploits-causes-crypto-stolen-2026/"},{"credibility":3,"name":"GitHub - Makina Hack CVE Report by pavondunbar","type":"research","url":"https://github.com/pavondunbar/Makina-Hack-Rekt-News-CVE-Report"}],"summary":"Makina Finance is an Ethereum-based DeFi execution engine marketed toward institutional asset managers and AI agents that raised $3 million in strategic funding in June 2025. On January 20, 2026, the protocol suffered a $4.13 million oracle manipulation exploit in which an attacker used a $280 million USDC flash loan to distort the MachineShareOracle via Makina's DUSD/USDC Curve pool, draining 1,299 ETH. The exploit targeted three compounding design flaws — permissionless oracle update functions, synchronous spot price reads with no TWAP, and pre-approved Weiroll execution paths including price-sensitive functions — in a vault deployment that fell outside the scope of the protocol's six prior security audits.","timeline":[{"date":"2025-02-01","event":"Makina Finance protocol launched on Ethereum mainnet.","source":"Cryptopolitan","source_url":"https://www.cryptopolitan.com/makina-exploited-4-13-dusd-pool-drained/"},{"date":"2025-07-01","event":"Enigma Dark completed fuzz and invariant testing security review of Makina core contracts.","source":"Rekt News","source_url":"https://rekt.news/makina-rekt"},{"date":"2025-08-01","event":"SigmaPrime completed core and periphery security audits.","source":"Rekt News","source_url":"https://rekt.news/makina-rekt"},{"date":"2025-09-01","event":"ChainSecurity completed two separate security audits. Cantina began competitive bug bounty review; oracle price/liquidity pool manipulation with unchecked synchronous deposits listed as out of scope.","source":"Rekt News","source_url":"https://rekt.news/makina-rekt"},{"date":"2025-06-25","event":"Makina Finance closed a $3 million strategic funding round with investors including Hypernative Labs, Kiln, Bodhi Ventures, Steakhouse Financial, Cyber Fund, and Interop Ventures.","source":"CypherHunter","source_url":"https://www.cypherhunter.com/en/e/makina-finance-raised-funding-2025-06-25/"},{"date":"2025-06-30","event":"Sath Ganesarajah appointed as non-executive chairman of Makina Finance.","source":"MEXC News","source_url":"https://www.mexc.com/news/20992"},{"date":"2025-10-01","event":"Cantina competitive bug bounty review concluded.","source":"Rekt News","source_url":"https://rekt.news/makina-rekt"},{"date":"2025-11-01","event":"OtterSec completed core and periphery security review — the final of six pre-exploit audits.","source":"Rekt News","source_url":"https://rekt.news/makina-rekt"},{"date":"2026-01-20","event":"Oracle manipulation exploit executed at 03:40:35 UTC (block 24,273,362). Attacker used 280 million USDC flash loan to drain 1,299 ETH (~$4.13 million) from DUSD/USDC Curve pool. MEV builders front-ran the original attacker and captured the majority of funds. Makina acknowledged the incident at 6:42 AM UTC.","source":"Rekt News / CertiK / Verichains","source_url":"https://rekt.news/makina-rekt"},{"date":"2026-01-22","event":"Makina offered 10% whitehat bounty to MEV fund recipients (~102.3 ETH) requesting return of approximately 920.7 ETH. As of this date no funds had been returned.","source":"Rekt News","source_url":"https://rekt.news/makina-rekt"},{"date":"2026-01-25","event":"Makina issued formal demand for return of $513,994.89 USDC from wallet 0xddf6f217951a1e484ee6b04d621c861bf38d0656, offering 10% bounty ($51,399.49 USDC) and a 24-hour deadline before further escalation.","source":"Phemex News","source_url":"https://phemex.com/news/article/makina-finance-demands-return-of-513994-usdc-from-exploit-profits-55868"},{"date":"2026-01-26","event":"Makina protocol upgraded to v1.1 (audited by ChainSecurity) with restricted accounting mode and maximum price change parameters. Recovery Mode disabled; redemptions reactivated. Users above $100,000 in DUSD required to complete AML/KYC before redemption.","source":"Makina Substack","source_url":"https://makinafi.substack.com/p/makina-protocol-upgrade-and-re-activation"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision ed163ab3-2e8f-4373-8eb3-7c83ff52f112
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.