← Sharwa.Finance1 decision on this page
Audit log
Every state-changing event for Sharwa.Finance: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions carry three independent witnesses — the original source, an Internet Archive snapshot taken at submission time, and a Solana memo signed by our publicly-disclosed publisher key.
- #1publishby system:backfill2026-05-29 16:12:59ZScore: ? → ? (no score change)anchoranchored
- chain
- ●mainnet-betaslot 422,972,367
- sig
WzxSXUbhTv7V…BYoH9hCfexplorer ↗- hash
7UmjMUmuLsPC…PjT77iFmsha256 → base58
verifying row…full verify ↗canonical bytes (5150 B) ▸
{"actor":"system:backfill","investigation_id":"833401a1-ffcb-4c74-95d6-404dedd094a9","kind":"publish","page_slug":"sharwafinance","published_at":"2026-05-29T16:12:59.826Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Sharwa.Finance","sections":[{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://defillama.com/protocol/sharwa.finance","type":"other","url":""},{"credibility":3,"name":"https://sharwa.finance/app.html","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://blog.verichains.io/p/vulnerability-analysis-deconstructing","type":"other","url":""},{"credibility":3,"name":"https://getfailsafe.com/sharwafinance-exploit-analysis/","type":"other","url":""},{"credibility":3,"name":"https://quadrigainitiative.com/casestudy/sharwafinancemargintradingsandwichattacksolvencyflaw.php","type":"other","url":""},{"credibility":3,"name":"https://blockthreat.com/blockthreat-week-43-2025/","type":"other","url":""},{"credibility":3,"name":"https://de.fi/blog/defi-rekt-report-october-2025-38-6-million-lost-across-9-exploits","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://github.com/pashov/audits/blob/master/team/md/SharwaFinance-security-review.md","type":"other","url":""},{"credibility":3,"name":"https://blog.verichains.io/p/vulnerability-analysis-deconstructing","type":"other","url":""},{"credibility":3,"name":"https://quadrigainitiative.com/casestudy/sharwafinancemargintradingsandwichattacksolvencyflaw.php","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://defillama.com/protocol/sharwa.finance","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://blockthreat.com/blockthreat-week-43-2025/","type":"other","url":""},{"credibility":3,"name":"https://de.fi/blog/defi-rekt-report-october-2025-38-6-million-lost-across-9-exploits","type":"other","url":""},{"credibility":3,"name":"https://x.com/SharwaFinance","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://defillama.com/protocol/sharwa.finance","type":"other","url":""},{"credibility":3,"name":"https://blog.verichains.io/p/vulnerability-analysis-deconstructing","type":"other","url":""},{"credibility":3,"name":"https://quadrigainitiative.com/casestudy/sharwafinancemargintradingsandwichattacksolvencyflaw.php","type":"other","url":""}]}],"sources_used":[],"summary":"Sharwa.Finance is an on-chain portfolio margin trading protocol deployed on Arbitrum, enabling leveraged spot and options trading with cross-margin collateral. The protocol suffered a $147,000 exploit in October 2025 via a flash loan price-oracle manipulation attack, a vulnerability class that had been explicitly identified and reported by the Pashov Audit Group over one year prior to the incident. The protocol was flagged by on-chain security researchers including ZachXBT-adjacent monitoring networks, and a second oracle manipulation incident resulting in approximately $32,850 in losses was recorded in May 2026.","timeline":[{"date":"2024-06-17","event":"Pashov Audit Group publishes security review of SharwaFinance/MarginTrading, identifying four critical-severity findings including C-01 Uniswap Spot Price Manipulation, explicitly warning that reliance on Uniswap V3 spot prices enables flash loan exploitation.","source":""},{"date":"2025-10-02","event":"Sharwa.Finance deploys a new version of the FacadeTradeRouter contract (18 days before the exploit), reportedly without re-applying the oracle fix recommended in the Pashov audit.","source":""},{"date":"2025-10-20","event":"Sharwa.Finance exploited on Arbitrum via flash loan price oracle manipulation. Attackers use a large USDC flash loan from Morpho to manipulate a Uniswap V3 pool and withdraw excess value through the FacadeTradeRouter contract. Total losses approximately $147,000.","source":""},{"date":"2025-10-23","event":"FailSafe publishes exploit analysis identifying two separate attackers, attributing approximately $61,000 and $85,000 in profits respectively to an absence of insolvency checks in the MarginTrading swap function.","source":""},{"date":"2025-10-27","event":"Sharwa.Finance team posts attack post-mortem on X, commits to 100% reimbursement of affected users, and implements Reduce-Only mode blocking new positions.","source":""},{"date":"2025-10-27","event":"Additional exploit transactions documented on Arbitrum network; $40,000 of stolen funds recovered.","source":""},{"date":"2025-10-27","event":"Verichains publishes vulnerability analysis of the Sharwa Finance exploit, confirming the oracle manipulation vector and noting the prior Pashov audit finding.","source":""},{"date":"2026-05-01","event":"Sharwa.Finance suffers a second security incident attributed to oracle price manipulation on Arbitrum, resulting in approximately $32,850 in losses according to DefiLlama protocol data.","source":""}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 198b1d04-6350-4d14-8b1f-491101e0376f
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.