Panoptic V1.1
Summary
Panoptic V1.1 is a permissionless, oracle-free perpetual options protocol built on Uniswap V3 liquidity positions, developed by Panoptic Labs and incubated by Advanced Blockchain AG. On August 25, 2025, a Cantina researcher disclosed a critical position-spoofing vulnerability rooted in the protocol's XOR-based fingerprinting system, placing approximately $4–5 million in user funds at risk. A coordinated whitehat rescue secured over 98% of remaining at-risk funds, and ZachXBT flagged the incident, contributing to reduced community trust in the V1.1 deployment.
Connected Entities
1 entities- + 4 more
Timeline(16 events)
2022-04-28
Guillaume Lambert publishes the Panoptic whitepaper on arXiv, establishing the theoretical basis for perpetual oracle-free options via Uniswap V3 LP positions.
2022-12-01
Panoptic closes a $4.5 million seed round led by gumi Cryptos Capital, with Uniswap Labs Ventures, Coinbase Ventures, and Jane Street participating.
2023-11-01
Panoptic launches its first Code4rena competitive audit.
2023-11-01
Panoptic closes a $7 million seed round led by Greenfield Capital, bringing total disclosed funding to $11.5 million.
2024-04-22
Code4rena April 2024 audit identifies 2 high-severity and 9 medium-severity findings, including two reports partially describing position list manipulation weaknesses.
2024-06-10
Code4rena June 2024 follow-up audit finds zero high- or medium-severity issues.
2024-10-10
Code4rena final V1.0 review finds no high or medium severity issues. Protocol prepares for mainnet launch.
2024-11-07
Cantina completes initial V1.1 protocol audit.
2024-11-20
Cantina completes final V1.1 protocol audit.
2025-01-28
Code4rena completes V1.1 protocol review with two independent wardens. No critical findings disclosed publicly.
2025-08-25
A Cantina researcher reports a critical position-spoofing vulnerability to the Panoptic team. The flaw involves XOR-based fingerprinting susceptible to polynomial-time collision attacks. Panoptic confirms feasibility within four hours and begins emergency user notifications.
2025-08-26
Approximately $2.35 million is voluntarily withdrawn by users following emergency notifications.
2025-08-27
Approximately $1.6 million remains at risk. Team continues outreach via Discord and SEAL 911.
2025-08-28
Primary whitehat rescue executed on Ethereum mainnet at block 23242436 at 5:55 PM EDT. Subsequent rescues completed on Base and Unichain. Over 98% of remaining at-risk funds secured. All recovered assets transferred to vault.panoptic.eth.
2025-08-28
Cantina researcher awarded $250,000 maximum bug bounty for responsible disclosure.
2025-09-01
Panoptic publishes the position-spoofing post-mortem and September newsletter detailing the incident, technical root cause, and fund recovery process.
Decision Log
- hash: 8LJNjKyQ4YeWtb32DiKkxRDU4NnWGh6uLgf6UTnwex1Z
This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.
model: claude-sonnet-4-6
generated: 5/4/2026, 2:54:16 AM
last updated: 5/28/2026, 7:07:05 PM
avoid.net — verified advice for a post-truth world