Skip to main content
AVOID.NET
Veil Cashreviewed 2026-09-09 · 34 claims checked

Fact-check findings

What an automated fact-checker found when it re-read Veil Cash against the sources the page cites. Only the most recent review is shown.

Read this first

These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.

“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.

Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.

disputed

5 claims

The reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.

  1. #7[disputed][awaiting moderator]in section: Protocol Logic Incident — Groth16 Misconfiguration (February 2026)
    On approximately February 21, 2026, an attacker exploited a critical cryptographic misconfiguration in Veil Cash's legacy privacy pool on Base.
    reviewerOn approximately February 21, 2026, an attacker exploited the Groth16 verifier misconfiguration in Veil Cash's legacy Base pool.Multiple independent technical write-ups (Darknavy's block-level analysis, contemporaneous news synthesis) place the exploit transaction on February 20, 2026 UTC, not February 21. This same date error recurs in three timeline entries.
    Proposed correction (not yet applied)
    On approximately February 20, 2026, an attacker exploited a critical cryptographic misconfiguration in Veil Cash's legacy privacy pool on Base.
  2. #23[disputed][awaiting moderator]in section: Token Economics and Market Data
    As of late May 2026, the token traded at approximately $0.026–$0.086 with a market capitalization between $1.85 million and $2.1 million fully diluted.
    reviewerAs of late May 2026, VEIL traded at approximately $0.026-$0.086 with a $1.85-$2.1 million fully diluted market cap.The market-cap range in this sentence checks out against CoinGecko's own historical data, but the price range's upper bound ($0.086) is roughly double the actual May 2026 peak; the cited source itself contradicts this figure.
    Proposed correction (not yet applied)
    As of late May 2026, the token traded at approximately $0.016–$0.043 with a market capitalization between $1.85 million and $2.1 million fully diluted.
  3. #30[disputed][awaiting moderator]in the timeline
    2026-02-21
    reviewerAttacker exploits the Groth16 verifier misconfiguration, executing 29 fraudulent withdrawals and draining 2.9 ETH in a single transaction, on 2026-02-21.Same underlying date error as the section-2 finding; the exploit transaction occurred February 20, 2026, not February 21.
    Proposed correction (not yet applied)
    2026-02-20
  4. #31[disputed][awaiting moderator]in the timeline
    2026-02-21
    reviewerDefimonAlerts (Decurity) intervenes and rescues remaining pool funds from the legacy pools, on 2026-02-21.Same underlying date error; rescue occurred hours after the Feb 20 exploit, not on Feb 21.
    Proposed correction (not yet applied)
    2026-02-20
  5. #32[disputed][awaiting moderator]in the timeline
    2026-02-21
    reviewerExploiter returns all drained funds unprompted at approximately 22:05 UTC; 100% of Veil Cash user funds recovered, on 2026-02-21.Same underlying date error as the other two timeline entries and the section-2 prose.
    Proposed correction (not yet applied)
    2026-02-20

unverifiable

7 claims

No source the reviewer could reach confirms or contradicts the claim.

  1. #3[unverifiable][awaiting moderator]in section: Protocol Overview
    The protocol charges a 0.5% fee on deposits, with revenue eventually distributed to stakers of the native VEIL token.
    reviewerThe protocol charges a 0.5% fee on deposits, with revenue eventually distributed to VEIL stakers.Could not independently confirm the 0.5% figure from the pages actually retrieved, but nothing contradicts it either.
  2. #4[unverifiable][awaiting moderator]in section: Protocol Overview
    A token-gating mechanism requires users of verified pools to hold at least 2,500 VEIL tokens.
    reviewerA token-gating mechanism requires users of verified pools to hold at least 2,500 VEIL tokens.No corroboration found in search results or fetched docs pages for this specific numeric threshold; also no contradiction.
  3. #15[unverifiable][awaiting moderator]in section: Audit History and Security Posture
    The protocol's operational resilience score was rated at 30%.
    reviewerThe protocol's operational resilience score was rated at 30%.Could not confirm the specific historical 30% figure; live figure today is 35%, a plausible amount of drift rather than clear evidence the original figure was fabricated.
  4. #25[unverifiable][awaiting moderator]in section: Token Economics and Market Data
    24-hour trading volume was approximately $61,199, with 98.29% sourced from decentralized exchanges. Approximately 110,617 token holders exist with very low concentration risk (0.89% held by major wallets). Staked VEIL amounted to approximately $292,930, representing 15.7% of market cap.
    reviewer24-hour trading volume was approximately $61,199 (98.29% DEX-sourced); ~110,617 holders with 0.89% concentration; staked VEIL ~$292,930 (15.7% of market cap).Volume figure is plausible given the range found; holder count, concentration percentage, and staking figures could not be independently checked (no historical snapshot of holder distribution was accessible).
  5. #27[unverifiable][awaiting moderator]in section: Team and Transparency
    The lack of public team information was a contributing factor to ZachXBT flagging the entity, consistent with his investigative focus on unverified teams operating financial protocols.
    reviewerThe lack of public team information was a contributing factor to ZachXBT flagging the entity, consistent with his investigative focus on unverified teams.No source is cited for this sub-claim anywhere in the section's source list, and an extensive search turned up zero corroboration of ZachXBT ever commenting on Veil Cash. This is the most concerning claim on the page: it attributes a specific action to a named, real public investigator without any locatable citation.
  6. #28[unverifiable][awaiting moderator]in the timeline
    Veil Cash protocol launches on Base L2 with zk-SNARK privacy pools for ETH and USDC.
    reviewerVeil Cash protocol launched on Base L2 with zk-SNARK privacy pools for ETH and USDC in 2024.No source is attached to this timeline entry (source field is empty) and no independent launch announcement was located to confirm the precise year.
  7. #29[unverifiable][awaiting moderator]in the timeline
    Pashov Audit Group completes a security review of Veil Cash smart contracts; the Groth16 verifier contract is explicitly listed out of scope.
    reviewerPashov Audit Group completed a security review of Veil Cash smart contracts in 2025, with the Groth16 verifier explicitly out of scope.The out-of-scope fact is confirmed elsewhere on the page; the specific year of the audit engagement is unverifiable from available sources.

partially supported

3 claims

The cited evidence supports part of the claim but not all of it.

  1. #5[partially supported][awaiting moderator]in section: Protocol Overview
    As of May 2026 the protocol's total value locked stood at approximately $20,736 according to DefiLlama, placing it 13th in the privacy protocol category.
    reviewerAs of May 2026 Veil Cash's TVL stood at approximately $20,736 per DefiLlama, ranking 13th in the privacy protocol category.The dollar figure is well supported by DefiLlama's historical TVL series; the 13th-place category rank could not be confirmed for the specific May 2026 date (current rank is 14th, but ranks fluctuate), so no specific correction is proposed.
  2. #14[partially supported][awaiting moderator]in section: Audit History and Security Posture
    CertiK Skynet assigned Veil Cash a score of 71.36 (BBB rating) as of early 2026, noting zero CertiK audit coverage, unverified team identity, and no bug bounty.
    reviewerCertiK Skynet assigned Veil Cash a score of 71.36 (BBB rating) as of early 2026.The qualitative findings in this sentence (no CertiK audit, unverified team, no bug bounty) are independently confirmed by the live Skynet page. The specific numeric score and letter grade could not be verified for the 'early 2026' timestamp; the current live score differs (68.92/BB), so no correction is proposed absent a confirmed historical value.
  3. #34[partially supported][awaiting moderator]in the timeline
    2026-03
    reviewerCryptoTimes and Halborn publish post-mortems linking the FoomCash exploit to the Veil Cash incident, dated 2026-03.Halborn's monthly recap would plausibly publish in early March per its usual cadence, but CryptoTimes' piece specifically dates to Feb 26. The single '2026-03' date bundles two sources with different actual publish dates; the proposed correction dates this entry to the earlier, independently confirmed CryptoTimes date, though a cleaner fix would split this into two timeline entries.

confirmed

19 claims

The cited evidence supports the claim as written.

  1. #1[confirmed][no action needed]in section: Protocol Overview
    Veil Cash is a non-custodial privacy protocol operating on the Base L2 blockchain. It allows users to deposit ETH or USDC into shielded pools and withdraw to different addresses without creating a traceable on-chain link.
    reviewerVeil Cash is a non-custodial privacy protocol on Base L2 using shielded pools for ETH/USDC with no traceable on-chain link between deposit and withdrawal addresses.Matches the protocol's own documentation and third-party description in Bankless.
  2. #2[confirmed][no action needed]in section: Protocol Overview
    The protocol uses a UTXO model secured by Groth16 zero-knowledge proofs and Poseidon hashing.
    reviewerVeil Cash uses a UTXO model secured by Groth16 zero-knowledge proofs and Poseidon hashing, with relay infrastructure removing the need for depositors to hold gas.Directly confirmed by fetching docs.veil.cash.
  3. #6[confirmed][no action needed]in section: Protocol Overview
    The project is distinct from the earlier Veil (veil-project.com), a standalone privacy coin launched in 2019.
    reviewerVeil Cash (the Base L2 protocol) is distinct from the earlier Veil (veil-project.com), a standalone privacy coin launched in 2019.The two projects are indeed unrelated; disambiguation is accurate.
  4. #8[confirmed][no action needed]in section: Protocol Logic Incident — Groth16 Misconfiguration (February 2026)
    The Groth16 zk-SNARK verifier contract at address 0x1E65C075989189E607ddaFA30fa1a0001c376cfd had its delta and gamma parameters set identically to the BN254 G2 generator — the default placeholder value produced by the snarkjs Phase 2 toolchain — because the CLI command required to generate distinct random values for these constants was never executed before deployment.
    reviewerThe Groth16 verifier at 0x1E65C075989189E607ddaFA30fa1a0001c376cfd had delta and gamma both set to the BN254 G2 generator, breaking the pairing soundness check and letting the attacker forge withdrawal proofs.Root-cause explanation is accurate and corroborated by two independent technical sources beyond the ones cited.
  5. #9[confirmed][no action needed]in section: Protocol Logic Incident — Groth16 Misconfiguration (February 2026)
    The attacker contract at 0x5F68aD46F500949FA7E94971441F279A85cB3354 executed 29 sequential fraudulent withdrawals in a single transaction on Base block 42,410,815, identified by the exploit transaction 0x5ff6dbc33e77fab8dc086bb9ea3c88f1ba81df198d24ec9fc0c5b50fb1a4a17d, using nullifier hashes that followed the pattern 0xdead0000 through 0xdead001c.
    reviewerThe attacker executed 29 fraudulent withdrawals in tx 0x5ff6dbc33e77fab8dc086bb9ea3c88f1ba81df198d24ec9fc0c5b50fb1a4a17d at Base block 42,410,815, draining 2.9 ETH from pool 0xD3560eF60Dd06E27b699372c3da1b741c80B7D90 to recipient 0x49A7CA88094B59b15EaA28C8c6d9BFAb78d5F903, using nullifier hashes 0xdead0000-0xdead001c.All on-chain identifiers (tx hash, pool contract, recipient address, nullifier range) check out against the cited GitHub PoC. Block number has a trivial 2-block variance across secondary write-ups but matches the page's own citation.
  6. #10[confirmed][no action needed]in section: Protocol Logic Incident — Groth16 Misconfiguration (February 2026)
    Security monitoring firm DefimonAlerts (Decurity) intervened and rescued the remaining pool funds. The exploiter subsequently returned all drained assets unprompted at approximately 22:05 UTC, and 100% of user funds were ultimately recovered.
    reviewerDefimonAlerts (Decurity) intervened and rescued the remaining pool funds, and the exploiter returned all drained assets unprompted at approximately 22:05 UTC with 100% of user funds recovered.Confirmed by both the protocol's own post-mortem and independent security journalism.
  7. #11[confirmed][no action needed]in section: Protocol Logic Incident — Groth16 Misconfiguration (February 2026)
    Separately, the Halborn February 2026 DeFi hacks recap estimated the Veil Cash incident at approximately $427,000 in notional exposure, though the final net loss to users was zero given the return of funds.
    reviewerThe Halborn February 2026 DeFi hacks recap estimated the Veil Cash incident at approximately $427,000 in notional exposure, though final net user loss was zero.Could not directly render the Halborn page (repeated 429s), but corroborating search-index snippets independently agree on the $427k Veil Cash figure, matching the page's claim.
  8. #12[confirmed][no action needed]in section: Protocol Logic Incident — Groth16 Misconfiguration (February 2026)
    Rekt.news covered the incident under the title 'The Unfinished Proof,' characterizing it as the direct template for the subsequent $2.26 million FoomCash exploit.
    reviewerRekt.news covered the incident under the title 'The Unfinished Proof,' characterizing it as the direct template for the subsequent $2.26 million FoomCash exploit.Directly confirmed by fetching the article.
  9. #13[confirmed][no action needed]in section: Audit History and Security Posture
    Pashov publicly confirmed on X (post ID 2025598503255167195) that the misconfigured Groth16 verifier contract was explicitly listed as out of scope in their engagement, meaning the critical vulnerability was never reviewed.
    reviewerPashov Audit Group confirmed on X that the misconfigured Groth16 verifier contract was listed out of scope in their engagement with Veil Cash.Exact tweet text and ID confirmed.
  10. #16[confirmed][no action needed]in section: Systemic Risk: FoomCash Copycat Exploit
    On February 26, 2026, an attacker used the technique documented in the Veil Cash post-mortem to drain approximately $2.26 million from FoomCash across Ethereum and Base.
    reviewerThe Veil Cash incident preceded and enabled a ~$2.26 million FoomCash exploit on February 26, 2026 using the identical Groth16 verifier misconfiguration.Well corroborated across multiple independent outlets.
  11. #17[confirmed][no action needed]in section: Systemic Risk: FoomCash Copycat Exploit
    Rekt.news noted that the Veil Cash incident served as a public template: 'someone read that post-mortem, identified a larger target, and scaled it up by several orders of magnitude.'
    reviewerRekt.news characterized the FoomCash exploit as: 'someone read that post-mortem, identified a larger target, and scaled it up by several orders of magnitude.'Direct quote verified.
  12. #18[confirmed][no action needed]in section: Systemic Risk: FoomCash Copycat Exploit
    Decurity's whitehat entity rescued approximately $1.84 million on Ethereum; the Base-side attacker retained approximately $320,000–$330,000 under the protocol's own stated 'code is law' bounty rules. The FoomCash incident resulted in a net user loss of approximately $420,000.
    reviewerDecurity's whitehat rescued approximately $1.84 million on Ethereum; the Base-side attacker retained approximately $320,000-$330,000 under FoomCash's 'code is law' bounty rules; net user loss was approximately $420,000.All dollar figures confirmed against the directly-fetched Rekt article.
  13. #19[confirmed][no action needed]in section: Compliance Framework and Regulatory Risk
    Deposits not meeting those criteria are forwarded to 0xbow, a compliance provider co-founded by Ameen Soleimani, Nathaniel Fried, and Zak Cole, which implements Privacy Pools research originally described by Vitalik Buterin.
    reviewer0xbow, the compliance provider handling declined deposits, was co-founded by Ameen Soleimani, Nathaniel Fried, and Zak Cole, and implements Privacy Pools research originated by Vitalik Buterin.Founders and research lineage both confirmed.
  14. #20[confirmed][no action needed]in section: Compliance Framework and Regulatory Risk
    The protocol claims backing from Coinbase Ventures and the Base Ecosystem Fund, giving it institutional credibility within the Coinbase ecosystem, though no formal press release from Coinbase Ventures confirming an investment was independently verified by this investigation.
    reviewerVeil Cash claims backing from Coinbase Ventures and the Base Ecosystem Fund, though no formal press release confirming the investment was independently verified.The page's own hedge (no independently-verified formal press release) is itself accurate and appropriately cautious; this is a well-calibrated claim.
  15. #21[confirmed][no action needed]in section: Compliance Framework and Regulatory Risk
    the same evolving regulatory environment that resulted in OFAC sanctioning Tornado Cash in 2022
    reviewerOFAC sanctioned Tornado Cash in 2022, illustrating the evolving regulatory risk facing privacy protocols like Veil Cash.Well-established historical fact, though not cited to a specific source in this section.
  16. #22[confirmed][no action needed]in section: Token Economics and Market Data
    The VEIL token is deployed on Base at address 0x767a739d1a152639e9ea1d8c1bd55fdc5b217d7f.
    reviewerThe VEIL token is deployed on Base at 0x767a739d1a152639e9ea1d8c1bd55fdc5b217d7f.Contract address confirmed via CoinGecko API and third-party token listings.
  17. #24[confirmed][no action needed]in section: Token Economics and Market Data
    Its all-time high was $0.31 and all-time low was $0.015, indicating significant drawdown from peak.
    reviewerVEIL's all-time high was $0.31 and all-time low was $0.015.ATL figure matches closely against independently pulled historical data; ATH figure matches the coin's currently-listed all-time-high value exactly.
  18. #26[confirmed][no action needed]in section: Team and Transparency
    The founding team of Veil Cash (the Base L2 protocol, not the 2019 Veil privacy coin) has not been publicly identified in major crypto media as of May 2026. CertiK Skynet's assessment notes that team identity has not been verified by CertiK or any known third party.
    reviewerThe founding team of Veil Cash has not been publicly identified, and CertiK notes team identity is unverified; no corporate registration or jurisdiction is publicly known.Confirmed by the live CertiK page and by absence of any team disclosure found in searches.
  19. #33[confirmed][no action needed]in the timeline
    FoomCash suffers a $2.26 million exploit using the identical Groth16 misconfiguration pattern first publicly documented in the Veil Cash incident.
    reviewerFoomCash suffers a $2.26 million exploit using the identical Groth16 misconfiguration pattern, on 2026-02-26.Date and figure confirmed against the cited article's own URL date-stamp.
How this fits together. The reviewer reads the published page and its cited sources and records one finding per claim. A human moderator decides whether each proposed correction is applied; those decisions, and the score changes they cause, appear in the audit log. Earlier review runs are not shown here; only the latest reflects the page as it stands.