Skip to main content
AVOID.NET

Veil Cash

avoid.net/veil-cash38/100·72% conf.
[AI-DRAFTED · AWAITING VERIFICATION][src:defillama]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·2xYzi8…FLVH

Summary

Veil Cash is a zero-knowledge privacy protocol deployed on Coinbase's Base L2 network, enabling anonymous ETH and USDC transfers via zk-SNARK proofs and a UTXO model. In February 2026 the protocol's legacy pools were exploited due to an incomplete Groth16 trusted-setup ceremony, resulting in 2.9 ETH being drained before funds were returned by the exploiter. The incident attracted industry attention because the same misconfiguration pattern was subsequently replicated in a larger $2.26 million exploit of FoomCash, raising broader questions about cryptographic setup hygiene across ZK DeFi protocols.

Connected Entities

7 entities · 60 linked investigations
Relationships
  • Ethereummentioned withCoinbase(60%)
  • ZachXBTmentioned withEthereum(70%)
  • ZachXBTmentioned withBinance(60%)
  • Binancementioned withEthereum(65%)
  • Coinbasementioned withBase(70%)
  • Coinbasementioned withZachXBT(70%)
  • Ethereummentioned withVitalik Buterin(80%)
  • Veil Cashmentioned withVitalik Buterin(80%)
  • Vitalik Buterinmentioned withEthereum(65%)
  • Vitalik Buterinmentioned withZachXBT(70%)
  • + 7 more

Connected Through

6 shared actors · 606 investigations

Distinct actors this investigation shares with others — holders, traders, and named parties. Shared infrastructure (exchanges, pools) is excluded.

Have evidence about Veil Cash?

Timeline(10 events)

2024

Veil Cash protocol launches on Base L2 with zk-SNARK privacy pools for ETH and USDC.

June 2024

Coinbase EAS (Ethereum Attestation Service) integration introduced, allowing Coinbase-verified users auto-approval into verified pools.

2025

Pashov Audit Group completes a security review of Veil Cash smart contracts; the Groth16 verifier contract is explicitly listed out of scope.

21 February 2026

Attacker exploits the Groth16 verifier misconfiguration (delta == gamma) in Veil Cash's legacy Base pool, executing 29 fraudulent withdrawals and draining 2.9 ETH in a single transaction.

21 February 2026

DefimonAlerts (Decurity security firm) intervenes and rescues remaining pool funds from the legacy pools.

21 February 2026

Exploiter returns all drained funds unprompted at approximately 22:05 UTC; 100% of Veil Cash user funds recovered.

22 February 2026

Public proof-of-concept for the Veil Cash Groth16 exploit published on GitHub by researcher DK27ss. Rekt.news covers incident as 'The Unfinished Proof'.

22 February 2026

Pashov Audit Group publicly confirms on X that the verifier was out of scope for their audit engagement.

26 February 2026

FoomCash suffers a $2.26 million exploit using the identical Groth16 misconfiguration pattern first publicly documented in the Veil Cash incident.

March 2026

CryptoTimes and Halborn publish post-mortems linking the FoomCash exploit directly to the Veil Cash incident as the originating template.

Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (4 events). 13 of 18 cited source URLs have an Internet Archive snapshot.

Fact-checked 2026-09-0934 claims checked5 corrections pending0 applied⛓ anchoredSee findings →

model: claude-sonnet-4-6

generated: 5/4/2026, 2:54:13 AM

last updated: 9/11/2026, 12:56:57 AM

21 views

avoid.net — verified advice for a post-truth world