Skip to main content
AVOID.NET
← Veda Protocol1 decision on this page

Audit log

Every state-changing event for Veda Protocol: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-10-03 08:12:53Z
    Score: ? → ? (no score change)
    anchoranchored
    chain
    ●mainnet-betaslot 452,876,132
    sig
    65poFta4W7Cx…h9jXJ9vbexplorer ↗
    hash
    C9GFrZDunJTm…V9WPQDCmsha256 → base58
    verifying row…full verify ↗
    canonical bytes (14891 B) ▸
    {"actor":"system:backfill","investigation_id":"9720f17f-8bfb-46ce-aab1-9a35ce6e9b42","kind":"publish","page_slug":"veda-protocol","published_at":"2026-10-03T08:12:53.347Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Veda Protocol","sections":[{"content":"Veda (Veda Labs) is a DeFi infrastructure protocol, launched in 2024, that describes itself as a non-custodial 'vault primitive' for pricing, accounting, securing, and automating onchain capital. It underpins large third-party vaults including Ether.fi's Liquid product, Mantle's cmETH, and the Lombard DeFi Vault. In June 2025, Veda announced an $18 million funding round led by CoinFund, with participation from Coinbase Ventures, GSR, Animoca Ventures, BitGo, Mantle EcoFund, and others; angel investors reportedly included Anchorage CEO Nathan McCauley, Ether.fi co-founder Mike Silagadze, and Polygon co-founder Sandeep Nailwal. At the time of that raise, Veda reported overseeing more than $3.7 billion in value across more than 100,000 user deposits. As of October 2026, DefiLlama data cited in third-party sources put Veda's TVL at approximately $1.87-1.92 billion, operating across roughly a dozen chains including Ethereum, Ink, OP Mainnet, and Hyperliquid L1. These indicators point to an operating, institutionally-backed protocol rather than an anonymous or fraudulent project.","heading":"Background and Legitimacy Indicators","severity":"low","sources":[{"credibility":2,"name":"Veda Raises $18M Led by CoinFund to Bring Institutional-Grade DeFi Yield to Consumer Apps (The Block)","type":"news_article","url":"https://www.theblock.co/post/359183/veda-raises-18-million-coinfund-coinbase-ventures-gsr-onchain-yield-products-without-defi-complexity"},{"credibility":2,"name":"Veda Raises $18M to Expand DeFi Vault Infrastructure Powering Over $3.7B in Assets (CoinDesk)","type":"news_article","url":"https://www.coindesk.com/business/2025/06/23/veda-raises-usd18m-to-expand-defi-vault-infrastructure-powering-over-usd3-7b-in-assets"},{"credibility":2,"name":"Veda Introduces Multi-Chain Yield Infrastructure After TVL Roars Past $1B (The Defiant)","type":"news_article","url":"https://thedefiant.io/news/defi/veda-introduces-multi-chain-yield-infrastructure-after-tvl-roars-past-usd1b"},{"credibility":2,"name":"Veda TVL, Fees & Revenue (DefiLlama)","type":"on_chain","url":"https://defillama.com/protocol/veda"}]},{"content":"On 2 October 2026, a post titled 'Flash Loan Attack Vector Analysis: Veda' was published on the DEV Community blogging platform under the author handle 'dannydoes_2abdf9c.' The post assigns Veda an overall flash-loan risk score of 8/10 (High) against a stated ~$1.92 billion TVL, and alleges that it identified six flash-loan-compatible attack vectors. It alleges that public entry points including borrow(), liquidate(), vote(), selfLiquidate(), and receiveCollateral(), along with governance-adjacent functions such as setOracle() and setLiquidationPenalty(), are callable within a flash-loan context without re-entrancy guards. It further alleges that Veda's collateral pricing relies on a single on-chain AMM time-weighted average price (TWAP) with a 30-minute window that updates once per block, which it characterizes as manipulable within a single transaction, and describes a scenario in which borrowed tokens could be used to cast governance votes and be repaid within one atomic transaction ('flash-vote'). The post estimates a worst-case single-transaction loss of roughly $300 million and recommends a 10-12 week remediation program centered on multi-source oracle validation and re-entrancy protections. These are allegations from a single external analysis and have not been independently corroborated by an audit firm, Veda itself, or on-chain evidence of an actual exploit.","heading":"October 2026 Flash-Loan Risk Allegations","severity":"high","sources":[{"credibility":3,"name":"Flash Loan Attack Vector Analysis: Veda (DEV Community)","type":"research","url":"https://dev.to/dannydoes_2abdf9c/flash-loan-attack-vector-analysis-veda-14jg"}]},{"content":"Several factors weigh against treating the October 2026 flash-loan analysis as a rigorous, protocol-specific security audit. The analysis is self-published on a personal DEV Community blog account rather than released by a named audit firm, and the same author account has published a series of near-identically titled 'Flash Loan Attack Vector Analysis' posts covering a wide range of unrelated projects, including the Uniswap V3 AMM, the USDT0 stablecoin bridge, and centralized exchanges such as Gate and Bitstamp. Centralized exchanges do not expose smart-contract functions to atomic flash-loan composition in the way DeFi protocols do, which suggests the series may follow a templated or automatically generated format rather than bespoke code review of each subject. Separately, Veda's own documentation and third-party coverage describe it as a 'vault primitive' focused on deposit accounting, strategist-executed allocations, and Merkle-root-verified actions, rather than as a traditional collateralized lending market with borrow/liquidate mechanics or on-chain token-weighted governance voting. The specific function names alleged in the analysis (e.g., liquidate(), vote(), selfLiquidate()) do not clearly correspond to the vault-based architecture Veda describes publicly, raising the possibility that some or all of the named functions do not exist in Veda's actual deployed contracts. AVOID.NET was unable to verify the claims against Veda's contract source code or an independent audit. Readers should treat the specific technical allegations as unverified and low-confidence pending confirmation from Veda, an independent auditor, or on-chain analysis.","heading":"Source Credibility Concerns","severity":"medium","sources":[{"credibility":3,"name":"Flash Loan Attack Vector Analysis: Veda (DEV Community)","type":"research","url":"https://dev.to/dannydoes_2abdf9c/flash-loan-attack-vector-analysis-veda-14jg"},{"credibility":3,"name":"Flash Loan Attack Vector Analysis: Bitstamp (DEV Community)","type":"research","url":"https://dev.to/dannydoes_2abdf9c/flash-loan-attack-vector-analysis-bitstamp-57c4"},{"credibility":3,"name":"Flash Loan Attack Vector Analysis: Gate (DEV Community)","type":"research","url":"https://dev.to/dannydoes_2abdf9c/flash-loan-attack-vector-analysis-gate-4cpn"},{"credibility":2,"name":"Smart Contract Security (Veda documentation)","type":"official","url":"https://docs.veda.tech/security-and-risk-controls/smart-contract-security"}]},{"content":"Veda operates a public bug bounty program on Immunefi covering its smart contracts, with rewards ranging from $10,000 to $1,000,000 for critical vulnerabilities, reportedly live since 21 January 2026. Immunefi stated the program covers Veda's smart contracts as part of an ecosystem that 'protects 70% of DeFi TVL.' Veda's own documentation describes additional controls including Merkle-root verification for strategist-executed actions and third-party on-chain monitoring intended to detect malicious behavior targeting its contracts and the underlying protocols its vaults are exposed to. The existence of an active, well-funded bug bounty program is a mitigating factor against the severity of the October 2026 allegations, though it does not by itself confirm or refute the specific claims made in that analysis.","heading":"Existing Security Program","severity":"low","sources":[{"credibility":2,"name":"Immunefi Veda Bug Bounty","type":"official","url":"https://immunefi.com/bug-bounty/veda/information/"},{"credibility":2,"name":"Immunefi announcement of Veda bug bounty launch (X/Twitter)","type":"social_media","url":"https://x.com/immunefi/status/2015722621493444828"},{"credibility":2,"name":"Smart Contract Security (Veda documentation)","type":"official","url":"https://docs.veda.tech/security-and-risk-controls/smart-contract-security"}]},{"content":"The October 2026 Veda allegations surface against a backdrop of a broader, well-documented rise in DeFi oracle and price-manipulation exploits in 2026. Industry reporting citing blockchain intelligence firm TRM Labs counted 32 price-manipulation exploits in 2026, a record high, with price manipulation accounting for roughly one in eight crypto hacks compared to one in seventeen in 2022. Cited examples include an alleged $75 million exploit of Tectonic in which an attacker reportedly manipulated the TONIC token price approximately 100-fold within about 20 minutes, an alleged $8.7 million exploit of Moonwell via MAMO collateral manipulation, and an alleged $9.05 million exploit of Bonzo Lend via manipulated SAUCE pricing. These incidents involve different protocols than Veda and are cited here only as general industry context showing that oracle-manipulation risk is an active, recurring problem in DeFi lending broadly in 2026, not as evidence of a Veda-specific incident.","heading":"Broader 2026 DeFi Price-Manipulation Context","severity":"medium","sources":[{"credibility":2,"name":"DeFi Lending Faces a Price Manipulation Crisis as 32 Exploits Hit in 2026 (KuCoin)","type":"news_article","url":"https://www.kucoin.com/blog/defi-lending-price-manipulation-exploits-2026"}]},{"content":"As of 3 October 2026, no confirmed hack, exploit, or loss of funds affecting Veda has been identified in news coverage, security-firm incident trackers, or on-chain data reviewed for this report. The October 2026 flash-loan analysis itself states that no exploit had occurred as of its publication date and frames its findings as a disclosure of a 'narrowing' theoretical threat window rather than a report of an actual attack. This status should be monitored, particularly given Veda's scale (roughly $1.9 billion in TVL) and its role as infrastructure underlying other major DeFi products.","heading":"Current Status","severity":"medium","sources":[{"credibility":3,"name":"Flash Loan Attack Vector Analysis: Veda (DEV Community)","type":"research","url":"https://dev.to/dannydoes_2abdf9c/flash-loan-attack-vector-analysis-veda-14jg"}]}],"sources_used":[{"credibility":3,"name":"Flash Loan Attack Vector Analysis: Veda (DEV Community)","type":"research","url":"https://dev.to/dannydoes_2abdf9c/flash-loan-attack-vector-analysis-veda-14jg"},{"credibility":3,"name":"Flash Loan Attack Vector Analysis: Bitstamp (DEV Community)","type":"research","url":"https://dev.to/dannydoes_2abdf9c/flash-loan-attack-vector-analysis-bitstamp-57c4"},{"credibility":3,"name":"Flash Loan Attack Vector Analysis: Gate (DEV Community)","type":"research","url":"https://dev.to/dannydoes_2abdf9c/flash-loan-attack-vector-analysis-gate-4cpn"},{"credibility":2,"name":"DeFi Lending Faces a Price Manipulation Crisis as 32 Exploits Hit in 2026 (KuCoin)","type":"news_article","url":"https://www.kucoin.com/blog/defi-lending-price-manipulation-exploits-2026"},{"credibility":2,"name":"Veda Raises $18M Led by CoinFund to Bring Institutional-Grade DeFi Yield to Consumer Apps (The Block)","type":"news_article","url":"https://www.theblock.co/post/359183/veda-raises-18-million-coinfund-coinbase-ventures-gsr-onchain-yield-products-without-defi-complexity"},{"credibility":2,"name":"Veda Raises $18M to Expand DeFi Vault Infrastructure Powering Over $3.7B in Assets (CoinDesk)","type":"news_article","url":"https://www.coindesk.com/business/2025/06/23/veda-raises-usd18m-to-expand-defi-vault-infrastructure-powering-over-usd3-7b-in-assets"},{"credibility":2,"name":"Veda Introduces Multi-Chain Yield Infrastructure After TVL Roars Past $1B (The Defiant)","type":"news_article","url":"https://thedefiant.io/news/defi/veda-introduces-multi-chain-yield-infrastructure-after-tvl-roars-past-usd1b"},{"credibility":2,"name":"Veda TVL, Fees & Revenue (DefiLlama)","type":"on_chain","url":"https://defillama.com/protocol/veda"},{"credibility":2,"name":"Immunefi Veda Bug Bounty","type":"official","url":"https://immunefi.com/bug-bounty/veda/information/"},{"credibility":2,"name":"Immunefi announcement of Veda bug bounty launch (X/Twitter)","type":"social_media","url":"https://x.com/immunefi/status/2015722621493444828"},{"credibility":2,"name":"Smart Contract Security (Veda documentation)","type":"official","url":"https://docs.veda.tech/security-and-risk-controls/smart-contract-security"}],"summary":"Veda is a venture-backed DeFi vault infrastructure protocol, launched in 2024, that underpins yield products for Ether.fi, Mantle, and Lombard and reports roughly $1.9-3.7 billion in total value locked depending on the measurement date. In October 2026, a third-party blog post assigned Veda's smart contracts a flash-loan risk score of 8/10, alleging unguarded borrow, liquidate, and governance-vote entry points and a manipulable single-source price oracle; no exploit of Veda has been confirmed as of this writing, and the source's credibility is uncertain given its templated, cross-protocol publishing pattern.","timeline":[{"date":"2024","event":"Veda protocol launched as DeFi vault infrastructure for tokenizing liquid staking tokens, yield-bearing accounts, and stablecoins.","source":"The Block / CoinDesk coverage of Veda's funding round","source_url":"https://www.theblock.co/post/359183/veda-raises-18-million-coinfund-coinbase-ventures-gsr-onchain-yield-products-without-defi-complexity"},{"date":"2025-06","event":"Veda announced an $18 million funding round led by CoinFund, with Coinbase Ventures, GSR, Animoca Ventures, BitGo, and others participating; TVL reported above $3.7 billion at the time.","source":"CoinDesk","source_url":"https://www.coindesk.com/business/2025/06/23/veda-raises-usd18m-to-expand-defi-vault-infrastructure-powering-over-usd3-7b-in-assets"},{"date":"2026-01","event":"Veda launched a public bug bounty program on Immunefi covering its smart contracts, with rewards up to $1,000,000 for critical vulnerabilities.","source":"Immunefi / Immunefi announcement","source_url":"https://immunefi.com/bug-bounty/veda/information/"},{"date":"2026-10-02","date_evidence":"The analysis is dated \"2 Oct 2026\"","event":"A third-party blog post ('Flash Loan Attack Vector Analysis: Veda') was published alleging a flash-loan risk score of 8/10 for Veda, citing unguarded borrow/liquidate/vote entry points and a single-source AMM TWAP oracle as the primary weaknesses, against a stated $1.92 billion TVL.","source":"DEV Community","source_url":"https://dev.to/dannydoes_2abdf9c/flash-loan-attack-vector-analysis-veda-14jg"},{"date":"2026-10","date_original":"2026-10-03","event":"No confirmed exploit of Veda has been identified as of this date; the protocol continues to operate with the alleged vulnerabilities unconfirmed and unresolved publicly.","source":"AVOID.NET research (absence of corroborating incident reports)","source_url":"https://dev.to/dannydoes_2abdf9c/flash-loan-attack-vector-analysis-veda-14jg"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 172e424b-8723-4148-aa1a-9b88fd62b9c1
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.