v3 → v4
Scores
trust_score62 → 42
severity_base— → —
score_modifier0 → 0
Sections
Protocol Overview
unchanged
Insider Theft by Team Member 'Gabagool' (August 2022)
unchanged
DNS / Frontend Compromise — November–December 2023
unchanged
DNS / Frontend Compromise — November 2025 (NameSilo Insider Threat)
unchanged
On-Chain Attacker Addresses (2023 Incident)
unchanged
Smart Contract Security and Audits
unchanged
Persistent Frontend / Web2 Attack Surface Risk
unchanged
DNS/Frontend Social-Engineering Attack (November–December 2023) → Impersonation Scams and Phishing Sites
- On November 28–29, 2023, attackers carried out a social engineering campaign against Velodrome's domain registrar, bypassing two-factor authentication through fabricated identity verification ('invalid ID verification') to seize control of the velodrome.finance and aerodrome.finance domain names. The attackers changed nameservers to redirect legitimate traffic to malicious clones of both sites. These cloned sites prompted users to connect wallets and sign transactions that authorized asset transfers to attacker-controlled wallets on multiple chains. A second attack wave was executed on December 1–2, 2023. Velodrome's incident report published on Medium identifies four attacker wallet addresses: 0xf64fcedfce714bbe835761e54d7067f2f8231443, 0x02ba13f39d7df9c3f7592257b636ed6c7cc4ae78, 0x554b54b6691e1f90a5902bf46d24d7f316e33b11, and 0x927e18fd7c854f43ae9f3c6ec4d03de28ab092dc. A Dune Analytics query tracking affected wallets was published at https://dune.com/queries/3249843. Total user losses from both attacks were estimated at up to $250,000. Velodrome's TVL fell by over $10 million in the days following the incident. First mitigation began approximately 39 minutes after the initial user reports; the first attack's domain was restored within approximately 36 hours, and the second attack was mitigated within approximately 1.5 hours. Smart contracts were not compromised; losses were entirely the result of users interacting with the fraudulent front end.+
NameSilo Registrar Insider Attack (November 2025) → Team Background and Governance
- On November 21–22, 2025, the velodrome.finance and aerodrome.finance domains were hijacked a second time. According to the post-incident report published by the teams, the root cause was an internal compromise at the NameSilo registrar: a compromised insider at NameSilo bypassed multisig controls in the 3DNS system, removed DNSSEC protections, and redirected both domains to malicious pages. Users visiting the sites were presented with two-stage signature requests that appeared to be routine but contained unlimited approval grants for ETH, WETH, USDC, and other tokens. Losses across both Velodrome and Aerodrome are estimated at approximately $700,000 in signed phishing approvals per the teams' report, while early on-chain community analysis suggested over $1 million was drained within one hour of the attack going live. Major wallet providers including MetaMask and Coinbase Wallet issued warnings within approximately two minutes of the first known malicious transaction. Both protocols directed users to ENS-based mirrors (e.g., aero-drome.eth.limo) while centralized domains remained compromised. Full remediation was completed within approximately four hours. Security partners involved in containment included Blockaid, SEAL, and FTI Consulting. The teams subsequently announced plans to migrate domain infrastructure and develop a grant program for affected users.+
Impersonation Scams and Phishing Sites → (section 10)
- Multiple fraudulent websites impersonating Velodrome Finance have been documented by security researchers. The most widely reported is the 'Velodrome Finance VELO Vote Rewards Scam,' which operates from domains such as governance-velo[.]finance and mimics the legitimate Velodrome governance interface. These sites promise VELO token rewards or early allocations to users who connect their wallets and 'vote,' deploying cryptocurrency wallet-drainer smart contracts upon connection. The scam was flagged on October 7, 2025, and has been identified by security vendors including Google SafeBrowsing, Kaspersky, and Sophos. Fraudulent sites are distributed primarily through compromised or fake social media accounts on X/Twitter and Facebook, phishing emails, and rogue advertising networks. Additional lookalike domains include web-velodrome[.]finance and velodrome-finance[.]app. These impersonation campaigns are separate from the DNS hijacking incidents and represent ongoing third-party fraud targeting Velodrome users.+
Smart Contract Audit Findings → (section 11)
- Prior to launch, Velodrome Finance underwent a competitive audit on Code4rena (May 23–30, 2022) with a prize pool of up to $75,000. The audit identified 23 unique vulnerabilities: 6 high-severity, 17 medium-severity, and 50 low/non-critical findings. Notable high-severity issues included: (H-01) a governance manipulation vulnerability allowing unlimited vote accumulation through repeated NFT minting and burning without clearing delegations; (H-03) a checkpoint indexing error causing all reward accrual to stop for users across all gauges; (H-04) bribe rewards deposited in the first epoch becoming permanently unclaimable due to a dependency on base token rewards; (H-05) a vote timing exploit allowing users to claim rewards without maintaining required vote positions; and (H-06) a LayerZero message-handling flaw enabling permanent blocking of cross-chain functionality. These findings were disclosed prior to mainnet launch. For V2, Spearbit conducted an audit published in June 2023. A CertiK audit was also conducted, finding no serious or moderate issues. A Code4rena audit for V2 was conducted in June 2023. No documented exploits of the smart contracts themselves have been reported as of May 2026.+
Team Background and Governance → (section 12)
- Velodrome Finance was built by members of veDAO, a project that had itself been incubated through the Information Token (IT) ecosystem with the mandate of engaging with Andre Cronje's Solidly protocol on Fantom. Alexander Cutler is identified in multiple sources as a key team member and co-founder, and was instrumental in the August 2022 internal investigation that identified Gabagool and in the April 2025 in-person confrontation that led to Gabagool's public unmasking. The team operates pseudonymously for the most part. Governance is conducted via veVELO holders who vote on weekly emissions distributions to liquidity pools. Protocols and projects can submit 'bribes' to incentivize veVELO voters to direct emissions to their pools, creating an explicit vote-buying market that is a core feature of the ve(3,3) model rather than a vulnerability, though it creates structural incentives that critics of the model have noted can concentrate governance power among large token holders.+
Timeline events
+ added2022 — (no description)
+ added2022-08 — (no description)
+ added2023-11 — (no description)
+ added2024 — (no description)
+ added2024-11 — (no description)
+ added2025-10 — (no description)
+ added2025-11 — (no description)
- removed2022-05 — (no description)
- removed2022-06 — (no description)
- removed2022-06-02 — (no description)
- removed2022-08-04 — (no description)
- removed2022-08-13 — (no description)
- removed2022-08-14 — (no description)
- removed2022-08-15 — (no description)
- removed2023-06 — (no description)
- removed2023-11-28 — (no description)
- removed2023-11-29 — (no description)
- removed2023-12-02 — (no description)
- removed2023-12-03 — (no description)
- removed2025-04-30 — (no description)
- removed2025-10-07 — (no description)
- removed2025-11-21 — (no description)
~ changed2023-12: “” → “”
~ changed2025-05: “” → “”
~ changed2025-11-22: “” → “”
Accepted submissions
No changes to accepted submissions.
Each version is bound to the decision event that created it. Verify the chain anchor for either via the audit log.
v3 hash: 6bd801a32cc7d08da7296b748c572d1828faecb5c410e3bf15aea0f26d713dd3
v4 hash: 817e11a24dd1b9bfb1d9d612d0122ba08f14a43f2ea87af9e4c9a5f28aa06652