Skip to main content
AVOID.NET

v2 → v3

Scores

trust_score6262
severity_base
score_modifier00

Sections

Protocol Overview

unchanged

Insider Theft by Team Member 'Gabagool' (August 2022)

unchanged

DNS / Frontend Compromise — November–December 2023

unchanged

DNS / Frontend Compromise — November 2025 (NameSilo Insider Threat)

unchanged

On-Chain Attacker Addresses (2023 Incident)

unchanged

Smart Contract Security and Audits

unchanged

Persistent Frontend / Web2 Attack Surface Risk

unchanged

Protocol Overview → DNS/Frontend Social-Engineering Attack (November–December 2023)

- Velodrome Finance launched on June 2, 2022, on the Optimism Layer 2 blockchain. The protocol was developed by former members of veDAO and the Information Token (IT) project, with Alexander Cutler identified as a core team member and co-founder. Velodrome implements a ve(3,3) mechanism inspired by Andre Cronje's Solidly Exchange on Fantom: users lock VELO tokens to receive veVELO NFTs, which grant governance voting rights over emissions to liquidity pools and entitle holders to a share of trading fees and bribes. Within 45 days of launch Velodrome had accumulated over $60 million in total value locked (TVL); by February 2023 TVL reached over $315 million, making it the leading DEX on Optimism. A V2 upgrade launched in June 2023. Velodrome subsequently spawned Aerodrome Finance, a sister protocol on the Base chain that uses the same architecture.+ On November 28–29, 2023, attackers carried out a social engineering campaign against Velodrome's domain registrar, bypassing two-factor authentication through fabricated identity verification ('invalid ID verification') to seize control of the velodrome.finance and aerodrome.finance domain names. The attackers changed nameservers to redirect legitimate traffic to malicious clones of both sites. These cloned sites prompted users to connect wallets and sign transactions that authorized asset transfers to attacker-controlled wallets on multiple chains. A second attack wave was executed on December 1–2, 2023. Velodrome's incident report published on Medium identifies four attacker wallet addresses: 0xf64fcedfce714bbe835761e54d7067f2f8231443, 0x02ba13f39d7df9c3f7592257b636ed6c7cc4ae78, 0x554b54b6691e1f90a5902bf46d24d7f316e33b11, and 0x927e18fd7c854f43ae9f3c6ec4d03de28ab092dc. A Dune Analytics query tracking affected wallets was published at https://dune.com/queries/3249843. Total user losses from both attacks were estimated at up to $250,000. Velodrome's TVL fell by over $10 million in the days following the incident. First mitigation began approximately 39 minutes after the initial user reports; the first attack's domain was restored within approximately 36 hours, and the second attack was mitigated within approximately 1.5 hours. Smart contracts were not compromised; losses were entirely the result of users interacting with the fraudulent front end.

Insider Theft by Team Member 'Gabagool' (August 2022) → NameSilo Registrar Insider Attack (November 2025)

- On August 4, 2022, a Velodrome operating wallet — used for team salaries and operational expenses — was drained of $350,000. An internal investigation revealed the theft was perpetrated by a team member operating under the pseudonym 'Gabagool' (Twitter: Gabagool.eth), described publicly as a well-known on-chain investigator. Gabagool had access to the wallet's private key, which Velodrome had distributed to five team members — a practice the project subsequently discontinued. According to Gabagool's own admission, he withdrew $350,000 in various cryptocurrencies, converted the funds to Ether (ETH), and routed them through Tornado Cash in an attempt to cover personal trading losses suffered during the 2022 crypto market downturn. He described the action as 'delusional' and apologized publicly. The funds were ultimately recovered in full, and Velodrome severed ties with Gabagool. The project subsequently moved to Gnosis Safe multisig wallets for all treasury operations, eliminating individual private key access. In April 2025, Velodrome co-founder Alex Cutler encountered Gabagool — then operating as 'ProxyStudio' and employed at the Base AI launchpad Clanker — at an in-person Farcaster/Clanker event. Cutler confronted him and threatened public disclosure; ProxyStudio subsequently resigned from Clanker. Clanker CEO Jack Dishman confirmed the separation and stated there was no evidence of misconduct during ProxyStudio's time at Clanker.+ On November 21–22, 2025, the velodrome.finance and aerodrome.finance domains were hijacked a second time. According to the post-incident report published by the teams, the root cause was an internal compromise at the NameSilo registrar: a compromised insider at NameSilo bypassed multisig controls in the 3DNS system, removed DNSSEC protections, and redirected both domains to malicious pages. Users visiting the sites were presented with two-stage signature requests that appeared to be routine but contained unlimited approval grants for ETH, WETH, USDC, and other tokens. Losses across both Velodrome and Aerodrome are estimated at approximately $700,000 in signed phishing approvals per the teams' report, while early on-chain community analysis suggested over $1 million was drained within one hour of the attack going live. Major wallet providers including MetaMask and Coinbase Wallet issued warnings within approximately two minutes of the first known malicious transaction. Both protocols directed users to ENS-based mirrors (e.g., aero-drome.eth.limo) while centralized domains remained compromised. Full remediation was completed within approximately four hours. Security partners involved in containment included Blockaid, SEAL, and FTI Consulting. The teams subsequently announced plans to migrate domain infrastructure and develop a grant program for affected users.

DNS/Frontend Social-Engineering Attack (November–December 2023) → Impersonation Scams and Phishing Sites

- On November 28–29, 2023, attackers carried out a social engineering campaign against Velodrome's domain registrar, bypassing two-factor authentication through fabricated identity verification ('invalid ID verification') to seize control of the velodrome.finance and aerodrome.finance domain names. The attackers changed nameservers to redirect legitimate traffic to malicious clones of both sites. These cloned sites prompted users to connect wallets and sign transactions that authorized asset transfers to attacker-controlled wallets on multiple chains. A second attack wave was executed on December 1–2, 2023. Velodrome's incident report published on Medium identifies four attacker wallet addresses: 0xf64fcedfce714bbe835761e54d7067f2f8231443, 0x02ba13f39d7df9c3f7592257b636ed6c7cc4ae78, 0x554b54b6691e1f90a5902bf46d24d7f316e33b11, and 0x927e18fd7c854f43ae9f3c6ec4d03de28ab092dc. A Dune Analytics query tracking affected wallets was published at https://dune.com/queries/3249843. Total user losses from both attacks were estimated at up to $250,000. Velodrome's TVL fell by over $10 million in the days following the incident. First mitigation began approximately 39 minutes after the initial user reports; the first attack's domain was restored within approximately 36 hours, and the second attack was mitigated within approximately 1.5 hours. Smart contracts were not compromised; losses were entirely the result of users interacting with the fraudulent front end.+ Multiple fraudulent websites impersonating Velodrome Finance have been documented by security researchers. The most widely reported is the 'Velodrome Finance VELO Vote Rewards Scam,' which operates from domains such as governance-velo[.]finance and mimics the legitimate Velodrome governance interface. These sites promise VELO token rewards or early allocations to users who connect their wallets and 'vote,' deploying cryptocurrency wallet-drainer smart contracts upon connection. The scam was flagged on October 7, 2025, and has been identified by security vendors including Google SafeBrowsing, Kaspersky, and Sophos. Fraudulent sites are distributed primarily through compromised or fake social media accounts on X/Twitter and Facebook, phishing emails, and rogue advertising networks. Additional lookalike domains include web-velodrome[.]finance and velodrome-finance[.]app. These impersonation campaigns are separate from the DNS hijacking incidents and represent ongoing third-party fraud targeting Velodrome users.

NameSilo Registrar Insider Attack (November 2025) → Smart Contract Audit Findings

- On November 21–22, 2025, the velodrome.finance and aerodrome.finance domains were hijacked a second time. According to the post-incident report published by the teams, the root cause was an internal compromise at the NameSilo registrar: a compromised insider at NameSilo bypassed multisig controls in the 3DNS system, removed DNSSEC protections, and redirected both domains to malicious pages. Users visiting the sites were presented with two-stage signature requests that appeared to be routine but contained unlimited approval grants for ETH, WETH, USDC, and other tokens. Losses across both Velodrome and Aerodrome are estimated at approximately $700,000 in signed phishing approvals per the teams' report, while early on-chain community analysis suggested over $1 million was drained within one hour of the attack going live. Major wallet providers including MetaMask and Coinbase Wallet issued warnings within approximately two minutes of the first known malicious transaction. Both protocols directed users to ENS-based mirrors (e.g., aero-drome.eth.limo) while centralized domains remained compromised. Full remediation was completed within approximately four hours. Security partners involved in containment included Blockaid, SEAL, and FTI Consulting. The teams subsequently announced plans to migrate domain infrastructure and develop a grant program for affected users.+ Prior to launch, Velodrome Finance underwent a competitive audit on Code4rena (May 23–30, 2022) with a prize pool of up to $75,000. The audit identified 23 unique vulnerabilities: 6 high-severity, 17 medium-severity, and 50 low/non-critical findings. Notable high-severity issues included: (H-01) a governance manipulation vulnerability allowing unlimited vote accumulation through repeated NFT minting and burning without clearing delegations; (H-03) a checkpoint indexing error causing all reward accrual to stop for users across all gauges; (H-04) bribe rewards deposited in the first epoch becoming permanently unclaimable due to a dependency on base token rewards; (H-05) a vote timing exploit allowing users to claim rewards without maintaining required vote positions; and (H-06) a LayerZero message-handling flaw enabling permanent blocking of cross-chain functionality. These findings were disclosed prior to mainnet launch. For V2, Spearbit conducted an audit published in June 2023. A CertiK audit was also conducted, finding no serious or moderate issues. A Code4rena audit for V2 was conducted in June 2023. No documented exploits of the smart contracts themselves have been reported as of May 2026.

Impersonation Scams and Phishing Sites → Team Background and Governance

- Multiple fraudulent websites impersonating Velodrome Finance have been documented by security researchers. The most widely reported is the 'Velodrome Finance VELO Vote Rewards Scam,' which operates from domains such as governance-velo[.]finance and mimics the legitimate Velodrome governance interface. These sites promise VELO token rewards or early allocations to users who connect their wallets and 'vote,' deploying cryptocurrency wallet-drainer smart contracts upon connection. The scam was flagged on October 7, 2025, and has been identified by security vendors including Google SafeBrowsing, Kaspersky, and Sophos. Fraudulent sites are distributed primarily through compromised or fake social media accounts on X/Twitter and Facebook, phishing emails, and rogue advertising networks. Additional lookalike domains include web-velodrome[.]finance and velodrome-finance[.]app. These impersonation campaigns are separate from the DNS hijacking incidents and represent ongoing third-party fraud targeting Velodrome users.+ Velodrome Finance was built by members of veDAO, a project that had itself been incubated through the Information Token (IT) ecosystem with the mandate of engaging with Andre Cronje's Solidly protocol on Fantom. Alexander Cutler is identified in multiple sources as a key team member and co-founder, and was instrumental in the August 2022 internal investigation that identified Gabagool and in the April 2025 in-person confrontation that led to Gabagool's public unmasking. The team operates pseudonymously for the most part. Governance is conducted via veVELO holders who vote on weekly emissions distributions to liquidity pools. Protocols and projects can submit 'bribes' to incentivize veVELO voters to direct emissions to their pools, creating an explicit vote-buying market that is a core feature of the ve(3,3) model rather than a vulnerability, though it creates structural incentives that critics of the model have noted can concentrate governance power among large token holders.

Smart Contract Audit Findings → (section 13)

- Prior to launch, Velodrome Finance underwent a competitive audit on Code4rena (May 23–30, 2022) with a prize pool of up to $75,000. The audit identified 23 unique vulnerabilities: 6 high-severity, 17 medium-severity, and 50 low/non-critical findings. Notable high-severity issues included: (H-01) a governance manipulation vulnerability allowing unlimited vote accumulation through repeated NFT minting and burning without clearing delegations; (H-03) a checkpoint indexing error causing all reward accrual to stop for users across all gauges; (H-04) bribe rewards deposited in the first epoch becoming permanently unclaimable due to a dependency on base token rewards; (H-05) a vote timing exploit allowing users to claim rewards without maintaining required vote positions; and (H-06) a LayerZero message-handling flaw enabling permanent blocking of cross-chain functionality. These findings were disclosed prior to mainnet launch. For V2, Spearbit conducted an audit published in June 2023. A CertiK audit was also conducted, finding no serious or moderate issues. A Code4rena audit for V2 was conducted in June 2023. No documented exploits of the smart contracts themselves have been reported as of May 2026.+ 

Team Background and Governance → (section 14)

- Velodrome Finance was built by members of veDAO, a project that had itself been incubated through the Information Token (IT) ecosystem with the mandate of engaging with Andre Cronje's Solidly protocol on Fantom. Alexander Cutler is identified in multiple sources as a key team member and co-founder, and was instrumental in the August 2022 internal investigation that identified Gabagool and in the April 2025 in-person confrontation that led to Gabagool's public unmasking. The team operates pseudonymously for the most part. Governance is conducted via veVELO holders who vote on weekly emissions distributions to liquidity pools. Protocols and projects can submit 'bribes' to incentivize veVELO voters to direct emissions to their pools, creating an explicit vote-buying market that is a core feature of the ve(3,3) model rather than a vulnerability, though it creates structural incentives that critics of the model have noted can concentrate governance power among large token holders.+ 

Timeline events

No timeline changes.

Accepted submissions

No changes to accepted submissions.

Each version is bound to the decision event that created it. Verify the chain anchor for either via the audit log.

v2 hash: 69c7b0c0b051c01d61469c169b6ac72f32eb63767264ae6ef203dfe6601d4187
v3 hash: 6bd801a32cc7d08da7296b748c572d1828faecb5c410e3bf15aea0f26d713dd3