Skip to main content
Sign in
ThalaSwap3 decisions on this page

Audit log

Every state-changing event for ThalaSwap: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-05-20 03:37:11Z
    Score: ?? (no score change)
    anchoranchored
    chain
    mainnet-betaslot 420,905,951
    sig
    25TqELSxkYPm…oE9WqDHfexplorer ↗
    hash
    HALS5dXKqGfB…ECj4r5FAsha256 → base58
    verifying row…full verify ↗
    canonical bytes (5565 B) ▸
    {"actor":"system:backfill","investigation_id":"9ef17dd6-b7aa-4c1a-ae5c-c52a6a15cc62","kind":"publish","page_slug":"thalaswap","published_at":"2026-05-20T03:37:11.036Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"ThalaSwap","sections":[{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"","type":"other","url":"https://www.theblock.co/post/177279/parafi-backs-thala-labs-6-million-raise-to-build-defi-stack-on-aptos-exclusive"},{"credibility":3,"name":"","type":"other","url":"https://defillama.com/protocol/thalaswap"},{"credibility":3,"name":"","type":"other","url":"https://www.signum.capital/blog/why-we-invested-in-thala-labs/"},{"credibility":3,"name":"","type":"other","url":"https://aptosnetwork.com/currents/ecosystem-spotlight-thala-building-defi-primitives-on-aptos"}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"","type":"other","url":"https://thalalabs.medium.com/thala-nov-15-post-mortem-5aea82bb3916"},{"credibility":3,"name":"","type":"other","url":"https://www.halborn.com/blog/post/explained-the-thala-hack-november-2024"},{"credibility":3,"name":"","type":"other","url":"https://x.com/ThalaLabs/status/1857703541089120541"},{"credibility":3,"name":"","type":"other","url":"https://cointelegraph.com/news/thala-recovers-25-million-exploiter-hacker-caught"}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"","type":"other","url":"https://thalalabs.medium.com/thala-nov-15-post-mortem-5aea82bb3916"},{"credibility":3,"name":"","type":"other","url":"https://quadrigainitiative.com/casestudy/thalalabsv1farmingcontractvulnerability.php"},{"credibility":3,"name":"","type":"other","url":"https://cointelegraph.com/news/thala-recovers-25-million-exploiter-hacker-caught"}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"","type":"other","url":"https://thalalabs.medium.com/thala-nov-15-post-mortem-5aea82bb3916"},{"credibility":3,"name":"","type":"other","url":"https://cointelegraph.com/news/thala-recovers-25-million-exploiter-hacker-caught"},{"credibility":3,"name":"","type":"other","url":"https://www.theblock.co/post/326937/defi-protocol-thala-recovers-25-million-following-successful-hacker-negotiation"},{"credibility":3,"name":"","type":"other","url":"https://cybernews.com/crypto/hacked-crypto-project-thala-paid-to-recover-millions/"}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"","type":"other","url":"https://www.theblock.co/post/177279/parafi-backs-thala-labs-6-million-raise-to-build-defi-stack-on-aptos-exclusive"},{"credibility":3,"name":"","type":"other","url":"https://www.signum.capital/blog/why-we-invested-in-thala-labs/"},{"credibility":3,"name":"","type":"other","url":"https://whitestarcapital.com/companies/thala-labs/"}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"","type":"other","url":"https://www.halborn.com/blog/post/explained-the-thala-hack-november-2024"},{"credibility":3,"name":"","type":"other","url":"https://quadrigainitiative.com/casestudy/thalalabsv1farmingcontractvulnerability.php"},{"credibility":3,"name":"","type":"other","url":"https://defillama.com/protocol/thalaswap"},{"credibility":3,"name":"","type":"other","url":"https://thalalabs.medium.com/thala-nov-15-post-mortem-5aea82bb3916"}]}],"sources_used":[],"summary":"ThalaSwap is the decentralized exchange component of Thala Labs, an Aptos-based DeFi protocol offering an AMM, the Move Dollar (MOD) overcollateralized stablecoin, liquid staking, and a launchpad. On November 15, 2024, an input-validation bug introduced in a two-line patch to the v1 farming contract allowed an attacker to drain $25.5 million in liquidity pool tokens; funds were fully recovered within hours after SEAL 911 identified the exploiter via on-chain evidence and the attacker returned assets in exchange for a $300,000 bounty.","timeline":[{"date":"2022-10-25","event":"Thala Labs raises $6 million seed round co-led by ParaFi Capital, White Star Capital, and Shima Capital","source":""},{"date":"2023-04-06","event":"Thala protocol launches on Aptos mainnet; reaches $10M TVL within days","source":""},{"date":"2024-11-01","event":"Two-line patch deployed to v1 farming contract, introducing the unstake_max input-validation bug that bypassed standard security review","source":""},{"date":"2024-11-15","event":"Exploit begins at 4:46 AM PST from address 0xf7…; second larger drain completed at 7:10 AM PST from address 0x80…; total $25.5M in LP tokens stolen","source":""},{"date":"2024-11-15","event":"TVL alerts trigger at 5:12 AM PST; vulnerability identified by 7:30 AM PST; all relevant contracts paused; $11.5M in Thala assets frozen","source":""},{"date":"2024-11-15","event":"SEAL 911 and Ogle identify attacker via on-chain evidence within minutes; on-chain message sent to attacker at 9:34 AM PST","source":""},{"date":"2024-11-15","event":"Attacker agrees to return all funds by 10:13 AM PST in exchange for $300,000 protocol bounty and $40,000 personal payment; full recovery confirmed by 11:13 AM PST","source":""},{"date":"2024-11-16","event":"Thala Labs publishes post-mortem on Medium detailing root cause, timeline, and remediation steps including OtterSec re-audit and withdrawal rate limits","source":""},{"date":"2025-01-01","event":"ThalaSwap V3 (CLMM concentrated liquidity) becomes primary liquidity venue; protocol remains operational with $2.23M TVL as of mid-2026","source":""}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 085b024f-bdb6-4ca0-84eb-38ae395118b6
  2. #2reviewby reviewerreviewer
    2026-08-19 04:00:06Z
    Score: 4242 (no score change)
    This page is unusually well-sourced: nearly every timeline claim about the November 15, 2024 exploit — including exact PST timestamps, wallet-address prefixes, dollar figures, and the two-line-patch root cause — was verified verbatim against Thala Labs' own post-mortem (retrieved via Wayback Machine) and corroborated by independent security-firm and news coverage. No unhedged allegations of wrongdoing were found; the page consistently frames the incident as an exploit the protocol suffered, not fraud it committed, and it accurately reports the full, same-day recovery of all $25.5M. Two minor defects were found: the claimed November 16 publication date for the detailed Medium post-mortem conflicts with that article's own self-reported November 26, 2024 byline, and the 'mid-2026 $2.23M TVL' figure, while traceable to a real data point, reflects unusually volatile TVL (which has since roughly halved on the same listing) rather than a stable current state. This review could not audit the page's actual section prose because the input supplied blank section content.
    anchorpending
    chain
    hash
    A7HPJvsFmATq…Txv8amYVsha256 → base58
    verifying row…
    canonical bytes (1421 B) ▸
    {"actor":"reviewer","decided_at":"2026-08-19T04:00:06.482Z","decision":"review","investigation_id":"9ef17dd6-b7aa-4c1a-ae5c-c52a6a15cc62","new_score":42,"page_slug":"thalaswap","prev_score":42,"reason":"This page is unusually well-sourced: nearly every timeline claim about the November 15, 2024 exploit — including exact PST timestamps, wallet-address prefixes, dollar figures, and the two-line-patch root cause — was verified verbatim against Thala Labs' own post-mortem (retrieved via Wayback Machine) and corroborated by independent security-firm and news coverage. No unhedged allegations of wrongdoing were found; the page consistently frames the incident as an exploit the protocol suffered, not fraud it committed, and it accurately reports the full, same-day recovery of all $25.5M. Two minor defects were found: the claimed November 16 publication date for the detailed Medium post-mortem conflicts with that article's own self-reported November 26, 2024 byline, and the 'mid-2026 $2.23M TVL' figure, while traceable to a real data point, reflects unusually volatile TVL (which has since roughly halved on the same listing) rather than a stable current state. This review could not audit the page's actual section prose because the input supplied blank section content.","score_delta":0,"sequence_num":2,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 86db9a8e-8a51-426a-9ba6-b9719d1e7eac
  3. #3review approve with notesby judgejudge
    2026-08-19 04:00:06Z
    Score: 4262 (+20)
    This is a calibration-only adjudication; the content review found no disputed claims (claim_findings show 10 confirmed, 2 partially_supported, 1 unverifiable, 0 disputed, disputed_pct 0.08), so the page's factual accuracy is not in question. The score is the problem: the incident is a suffered exploit (attribution 'b' per calibration_assessment.incident_attributions[0]) with an engineering-process failure as root cause, no evidence of insider misconduct, same-day full recovery of all $25.5M, a transparent public post-mortem, an OtterSec re-audit, and structural remediation (withdrawal rate limits). Per the rubric, a 'suffered' attribution caps the entity at CAUTIONARY (50-69), not WARNING (20-49); the current score of 42 (WARNING) misclassifies a well-handled, fully-recovered exploit as if it carried an own-conduct penalty. I agree with the reviewer's recommended band (CAUTIONARY) and score (62), which reflects strong incident response and remediation offset by the process failure that allowed an unreviewed patch to ship and by currently volatile, declining TVL. Notes: (Reconcile the Nov 16 post-mortem publication date in timeline[7] with the Medium article's own displayed byline of Nov 26, 2024; consider splitting into a Nov 16 announcement/tweet event and a separate Nov 26 detailed post-mortem event.) (Reframe the 'mid-2026 $2.23M TVL' figure in timeline[8] to note TVL volatility (ranged ~$5.3M-$2.2M within May 2026 alone, ~$613K on the v1/v2 listing as of review date) rather than presenting a single day's snapshot as a stable current state.) (Populate the blank section `content` and `heading` fields — the supplied page input had empty prose for every section, so editorial-language and causal-framing auditing could not be performed against actual reader-facing text.) (Consider adding coverage of: whether Thala's founders are publicly identified, whether a bug-bounty program (e.g., Immunefi) was established post-incident, and any MOD stablecoin peg-stability history independent of the exploit.)
    anchorpending
    chain
    hash
    D3SExuLJdW5K…vQ2MJpq6sha256 → base58
    verifying row…
    canonical bytes (2392 B) ▸
    {"actor":"judge","decided_at":"2026-08-19T04:00:06.482Z","decision":"review_approve_with_notes","investigation_id":"9ef17dd6-b7aa-4c1a-ae5c-c52a6a15cc62","new_score":62,"page_slug":"thalaswap","prev_score":42,"reason":"This is a calibration-only adjudication; the content review found no disputed claims (claim_findings show 10 confirmed, 2 partially_supported, 1 unverifiable, 0 disputed, disputed_pct 0.08), so the page's factual accuracy is not in question. The score is the problem: the incident is a suffered exploit (attribution 'b' per calibration_assessment.incident_attributions[0]) with an engineering-process failure as root cause, no evidence of insider misconduct, same-day full recovery of all $25.5M, a transparent public post-mortem, an OtterSec re-audit, and structural remediation (withdrawal rate limits). Per the rubric, a 'suffered' attribution caps the entity at CAUTIONARY (50-69), not WARNING (20-49); the current score of 42 (WARNING) misclassifies a well-handled, fully-recovered exploit as if it carried an own-conduct penalty. I agree with the reviewer's recommended band (CAUTIONARY) and score (62), which reflects strong incident response and remediation offset by the process failure that allowed an unreviewed patch to ship and by currently volatile, declining TVL. Notes: (Reconcile the Nov 16 post-mortem publication date in timeline[7] with the Medium article's own displayed byline of Nov 26, 2024; consider splitting into a Nov 16 announcement/tweet event and a separate Nov 26 detailed post-mortem event.) (Reframe the 'mid-2026 $2.23M TVL' figure in timeline[8] to note TVL volatility (ranged ~$5.3M-$2.2M within May 2026 alone, ~$613K on the v1/v2 listing as of review date) rather than presenting a single day's snapshot as a stable current state.) (Populate the blank section `content` and `heading` fields — the supplied page input had empty prose for every section, so editorial-language and causal-framing auditing could not be performed against actual reader-facing text.) (Consider adding coverage of: whether Thala's founders are publicly identified, whether a bug-bounty program (e.g., Immunefi) was established post-incident, and any MOD stablecoin peg-stability history independent of the exploit.)","score_delta":20,"sequence_num":3,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision adf968ca-cef2-488b-9a01-cb8ceb24f6e9
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.