Skip to main content
AVOID.NET
ThalaSwapreviewed 2026-09-07 · 25 claims checked

Fact-check findings

What an automated fact-checker found when it re-read ThalaSwap against the sources the page cites. Only the most recent review is shown.

Read this first

These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.

“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.

Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.

disputed

5 claims

The reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.

  1. #12[disputed][awaiting moderator]in section: On-Chain Evidence
    SEAL 911 and researcher Ogle identified the attacker within minutes of the breach based on on-chain wallet connections, without needing extended forensic analysis.
    reviewerSEAL 911 and researcher Ogle identified the attacker within minutes of the breach, without needing extended forensic analysisThe page's own cited primary source timeline places attacker identification roughly 3-4 hours after exploit start, not 'within minutes' as stated.
    Proposed correction (not yet applied)
    SEAL 911 and researcher Ogle helped identify the attacker within hours of the breach based on on-chain wallet connections.
  2. #18[disputed][awaiting moderator]in section: Team
    Individual founder names are not prominently disclosed in official materials or the major press coverage reviewed for this investigation, which limits independent verification of specific claimed credentials.
    reviewerIndividual founder names are not prominently disclosed in official materials or the major press coverage reviewed for this investigationThe page's own cited source directly names two individuals in named roles, contradicting the claim that founder names are not disclosed in the press coverage reviewed for this investigation.
    Proposed correction (not yet applied)
    Founder Adam Cader and CTO Carl Hua are named in press coverage cited by this investigation (The Block, 2022), though further biographical detail is not prominently disclosed in official materials or the major press coverage reviewed for this investigation, which limits independent verification of specific claimed credentials.
  3. #20[disputed][awaiting moderator]in section: Team
    The protocol is headquartered without a disclosed jurisdiction.
    reviewerThe protocol is headquartered without a disclosed jurisdictionMultiple business-intelligence sources, including the page's own cited White Star Capital portfolio page, disclose Toronto, Ontario, Canada as the headquarters location.
    Proposed correction (not yet applied)
    Business databases and an investor's own portfolio page list Thala Labs as headquartered in Toronto, Ontario, Canada.
  4. #23[disputed][awaiting moderator]in the timeline
    ThalaSwap V3 (CLMM concentrated liquidity) becomes primary liquidity venue; protocol remains operational with $2.23M TVL as of mid-2026
    reviewerThalaSwap V3 (CLMM) becomes primary liquidity venue in 2025; protocol remains operational with $2.23M TVL as of mid-2026The timeline entry is dated 2025 but its text also asserts a mid-2026 TVL figure, conflating two distinct time periods in one dated record; the mid-2026 TVL fact belongs in its own entry with a 2026 date.
    Proposed correction (not yet applied)
    ThalaSwap V3 (CLMM concentrated liquidity) becomes primary liquidity venue
  5. #24[disputed][awaiting moderator]in the timeline
    2024-11-16
    reviewerThala Labs publishes post-mortem on Medium on November 16, 2024The publish date shown on the cited Medium post itself is November 26, 2024, ten days later than the date recorded in this timeline entry.
    Proposed correction (not yet applied)
    2024-11-26

unverifiable

1 claim

No source the reviewer could reach confirms or contradicts the claim.

  1. #11[unverifiable][awaiting moderator]in section: On-Chain Evidence
    The on-chain footprint of the attack was described by blockchain security group SEAL 911 as providing obvious links to the exploiter's real-world identity.
    reviewerSEAL 911 described the on-chain footprint as providing obvious links to the exploiter's real-world identityCould not locate a source attributing this specific characterization to SEAL 911; the general fact that on-chain data led to identification is supported, but this precise framing is not traceable to any source reviewed.

partially supported

2 claims

The cited evidence supports part of the claim but not all of it.

  1. #19[partially supported][awaiting moderator]in section: Team
    The organization states that contributors hold backgrounds from Google, Dapper Labs, BitGo, Terraform Labs, ParaFi Capital, MakerDAO, NEAR, Twitter, Apple, and Amazon.
    reviewerContributors hold backgrounds from Google, Dapper Labs, BitGo, Terraform Labs, ParaFi Capital, MakerDAO, NEAR, Twitter, Apple, and AmazonNone of the three sources cited for this section mention MakerDAO, NEAR, Twitter, Apple, or Amazon as team backgrounds; these five appear to be unsupported additions beyond what the cited sources state.
  2. #25[partially supported][awaiting moderator]in the summary
    the attacker returned assets in exchange for a $300,000 bounty
    reviewerThe attacker returned assets in exchange for a $300,000 bounty (per the page summary)The summary understates the total consideration paid to the attacker; the page's own Recovery section correctly discloses an additional $40,000 personal payment omitted from the summary.

confirmed

17 claims

The cited evidence supports the claim as written.

  1. #1[confirmed][no action needed]in section: Background
    The protocol launched on Aptos mainnet in April 2023 and within days accumulated $10 million in total value locked (TVL) with nearly $1 million in daily swap volume.
    reviewerThala Labs launched on Aptos mainnet in April 2023 and accumulated $10M TVL within days with nearly $1M daily swap volumeMultiple independent sources confirm the launch timeframe and early TVL/volume figures.
  2. #2[confirmed][no action needed]in section: Background
    At peak, Thala reached approximately $250 million in TVL and consistently accounted for more than 30% of spot trading volume on Aptos.
    reviewerAt peak, Thala reached approximately $250 million in TVLVerified directly against DefiLlama's historical TVL time series for the parent Thala protocol.
  3. #3[confirmed][no action needed]in section: Background
    The native governance token is THL, with a fixed supply of 100,000,000.
    reviewerTHL has a native governance token with a fixed supply of 100,000,000Corroborated by multiple independent tokenomics trackers.
  4. #4[confirmed][no action needed]in section: Background
    Thala Labs raised a $6 million seed round on October 25, 2022, co-led by ParaFi Capital, White Star Capital, and Shima Capital, with additional participation from BECO Capital, LedgerPrime, Saison Capital, and Infinity Ventures Crypto.
    reviewerThala Labs raised a $6 million seed round on October 25, 2022 co-led by ParaFi Capital, White Star Capital, and Shima Capital with additional listed participantsAmount, date, and investor list confirmed across two independent sources.
  5. #5[confirmed][no action needed]in section: Background
    The team comprises approximately 13 members with stated backgrounds from Google, Dapper Labs, BitGo, Terraform Labs, and ParaFi Capital.
    reviewerThe team comprises approximately 13 members with stated backgrounds from Google, Dapper Labs, BitGo, Terraform Labs, and ParaFi CapitalExact match to the cited source.
  6. #6[confirmed][no action needed]in section: The Exploit
    The vulnerability was introduced on November 1, 2024, by a two-line patch that bypassed the standard security review process due to its perceived simplicity.
    reviewerA two-line patch introduced Nov 1, 2024 bypassed standard security review and caused the input-validation bugDirectly confirmed against the primary post-mortem text.
  7. #7[confirmed][no action needed]in section: The Exploit
    The initial phase began at 4:46 AM PST from attacker address 0xf7…, with a second, larger drain completed at 7:10 AM PST by a related address 0x80….
    reviewerExploit began 4:46 AM PST from 0xf7..., second larger drain completed 7:10 AM PST by 0x80..., total $25.5M in LP tokens drained across MOD/USDC, MOD/THL, THAPT/APTPrecise timestamps and addresses match the primary post-mortem exactly.
  8. #8[confirmed][no action needed]in section: The Exploit
    TVL alerts within the protocol triggered at 5:12 AM PST, and the vulnerability was identified by 7:30 AM PST. All relevant smart contracts were paused and $11.5 million in Thala-related assets — comprising approximately $9 million in MOD tokens and $2.5 million in THL tokens — were frozen by the team.
    reviewerTVL alerts triggered 5:12 AM PST; vulnerability identified by 7:30 AM PST; $11.5M frozen ($9M MOD + $2.5M THL)Exact match to primary source.
  9. #9[confirmed][no action needed]in section: The Exploit
    The THL token dropped nearly 40% in value in the hours following the announcement.
    reviewerThe THL token dropped nearly 40% in value in the hours following the announcementReported figures at the time ranged roughly 35%-42%; 'nearly 40%' falls within the reported range across multiple outlets, though exact figure varies by source and snapshot time.
  10. #10[confirmed][no action needed]in section: The Exploit
    Security firm Halborn noted that Move's decompilability facilitated the attacker's ability to locate the vulnerability, though it also aided post-incident analysis.
    reviewerHalborn noted that Move's decompilability facilitated the attacker locating the vulnerability but also aided post-incident analysisConfirmed via search-summarized Halborn content (direct fetch was rate-limited but corroborated by independent secondary coverage of the same analysis).
  11. #13[confirmed][no action needed]in section: On-Chain Evidence
    The protocol team communicated with the attacker via an on-chain message at 9:34 AM PST on November 15. The attacker agreed to return all funds by 10:13 AM PST and full recovery was confirmed by 11:13 AM PST, approximately six hours after the initial exploit transaction.
    reviewerOn-chain message sent to attacker at 9:34 AM PST; attacker agreed to return funds by 10:13 AM PST; full recovery confirmed by 11:13 AM PSTExact match to the primary post-mortem timeline.
  12. #14[confirmed][no action needed]in section: On-Chain Evidence
    The Quadriga Initiative case study noted the absence of a bug bounty program prior to the exploit as a contributing factor that may have discouraged responsible disclosure.
    reviewerThe Quadriga Initiative case study noted the absence of a bug bounty program as a contributing factor that may have discouraged responsible disclosureClose paraphrase of the cited source's actual finding.
  13. #15[confirmed][no action needed]in section: Recovery
    Thala negotiated a $300,000 protocol bounty payment plus an additional $40,000 personal payment to the founding team in exchange for the full return of $25.5 million.
    reviewerThe attacker, described as a white hat actor in some reporting, reached out voluntarily and agreed to return all stolen assets; Thala negotiated a $300,000 bounty plus $40,000 personal payment for the full $25.5M returnBoth the bounty structure and the white-hat characterization are independently corroborated.
  14. #16[confirmed][no action needed]in section: Recovery
    CoinTelegraph and The Block both confirmed the successful recovery via statements from the Thala team.
    reviewerThe exploit-to-recovery narrative was confirmed by both CoinTelegraph and The Block via Thala team statementsBoth cited outlets independently reported the recovery.
  15. #17[confirmed][no action needed]in section: Recovery
    Following recovery, the protocol implemented several security improvements: mandatory comprehensive test coverage for all code changes; an end-to-end re-audit of contracts by OtterSec; protocol-wide withdrawal rate limits capping withdrawals from farming pools, LSD redemptions, and select ThalaSwap pools within defined timeframes; elimination of emergency patches in favor of full release cycles; enhanced alerting and incident response protocols; capability-based access control models; and self-custody receipts replacing asset escrow.
    reviewerPost-recovery, Thala implemented mandatory test coverage, an OtterSec re-audit, protocol-wide withdrawal rate limits, elimination of emergency patches, enhanced alerting, capability-based access control, and self-custody receiptsDirectly matches the post-mortem's stated remediation list.
  16. #21[confirmed][no action needed]in section: Team
    No regulatory actions, OFAC designations, or law enforcement proceedings against Thala Labs or named team members were identified in the sources reviewed for this investigation.
    reviewerNo regulatory actions, OFAC designations, or law enforcement proceedings against Thala Labs or named team members were identifiedThis is a negative/absence claim; no contradicting evidence was found in independent searches, consistent with the page's framing.
  17. #22[confirmed][no action needed]in section: Risk Assessment
    TVL as of mid-2026 stands at approximately $2.23 million, a significant decline from the pre-hack peak of approximately $250 million, suggesting sustained user trust erosion.
    reviewerTVL as of mid-2026 stands at approximately $2.23 million, down from the pre-hack peak of approximately $250 millionVerified directly against DefiLlama's historical time series for the specific ThalaSwap protocol (not the combined Thala parent protocol).
How this fits together. The reviewer reads the published page and its cited sources and records one finding per claim. A human moderator decides whether each proposed correction is applied; those decisions, and the score changes they cause, appear in the audit log. Earlier review runs are not shown here; only the latest reflects the page as it stands.