Verify a decision
Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.
How verification works
- We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (
payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction. - We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
- You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is
AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.
Decision
publish · Velodrome
- Sequence
- #1
- Score
- →
- Cluster
- mainnet-beta
- Slot
- 419744592
- Off-chain at
- 2026-05-14T18:53:48.956Z
- Anchored at
- —
- Block time
- —
Independent verification
- 1. Database (off-chain)
- 7Ndi71PHFgAqkTinrG2GG8iZjwLw9qngSGqg3sdev74p
- 2. Recomputed (your browser)
- computing…
- 3. On-chain (Solana memo)
- fetching…
Canonical bytes hashed (19230 chars)
{"actor":"system:backfill","investigation_id":"a2e62b81-3607-4a0a-b5da-cb39ef9f945d","kind":"publish","page_slug":"velodrome","published_at":"2026-05-14T18:53:48.898Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Velodrome","sections":[{"content":"Velodrome Finance launched on June 1, 2022 as an AMM on the Optimism Layer-2 network, modeled on Andre Cronje's Solidly Exchange design. The protocol uses a vote-escrow tokenomics model in which users stake VELO for veVELO, granting governance rights and a share of protocol fees. By mid-2023 Velodrome had accumulated over $236 million in total value locked (TVL), making it Optimism's dominant native DEX. A sister protocol, Aerodrome Finance, was subsequently deployed on the Base L2 network and shares domain infrastructure and certain team members with Velodrome. Both protocols operate under the same security posture for their centralized web frontends, a fact that has contributed to simultaneous compromise of both in multiple incidents.","heading":"Protocol Overview","severity":"low","sources":[{"credibility":3,"name":"What is Velodrome Finance and How Does It Work — OKX","type":"news","url":"https://www.okx.com/en-us/learn/what-is-velodrome-velo"},{"credibility":2,"name":"Velodrome crosses $100 million in TVL on Optimism — The Block","type":"news","url":"https://www.theblock.co/post/160078/velodrome-crosses-100-million-in-tvl-on-optimism"},{"credibility":1,"name":"Velodrome Finance official documentation","type":"official","url":"https://docs.velodrome.finance/"}]},{"content":"On August 4, 2022, approximately $350,000 was drained from a Velodrome operational wallet used to fund team salaries and operating expenses. An internal investigation by the Velodrome team identified the perpetrator as a team member operating under the pseudonym 'Gabagool' (Twitter/social handle: gabagool.eth), who had legitimate access to the wallet's private key as one of five keyholders. Gabagool converted the stolen funds — denominated in various tokens — to Ether (ETH) and transferred them to Tornado Cash, the on-chain privacy mixer, in an alleged effort to obscure the trail. The stated motivation was to recoup approximately $56,000 in personal losses suffered during the 2022 crypto bear market. On August 13, 2022, Velodrome publicly disclosed the incident and identified Gabagool as the responsible party. Gabagool subsequently released a public statement acknowledging the theft and claiming the decision to return the funds was driven by guilt. The full $350,000 was recovered. Following the incident, Velodrome revoked individual private key access from team members and migrated operational wallet controls to Gnosis Safe multisig infrastructure. The team stated it was working with attorneys on potential legal action. Notably, Gabagool had previously held a public reputation as an on-chain fraud investigator within the crypto community.","heading":"Insider Theft by Team Member 'Gabagool' (August 2022)","severity":"high","sources":[{"credibility":2,"name":"Velodrome says team member stole $350,000 from the project's wallet — The Block","type":"news","url":"https://www.theblock.co/post/163404/velodrome-says-team-member-stole-350000-from-the-projects-wallet"},{"credibility":2,"name":"Crypto Marketplace Alleges $350K Stolen by Insider 'Gabagool' — Blockworks","type":"news","url":"https://blockworks.co/news/crypto-marketplace-alleges-350k-stolen-by-insider-gabagool"},{"credibility":2,"name":"Velodrome recovers $350K stolen funds from team member Gabagool — CoinTelegraph","type":"news","url":"https://cointelegraph.com/news/velodrome-recovers-350k-stolen-funds-from-team-member-gabagool"},{"credibility":3,"name":"Velodrome Regains $350k Stolen by its Developer Gabagool — The Crypto Times","type":"news","url":"https://www.cryptotimes.io/2022/08/15/velodrome-regains-350k-stolen-by-its-developer-gabagool/"},{"credibility":3,"name":"Thief Returns $350K to Velodrome Finance — Run The Chain","type":"news","url":"https://runthechain.news/velodrome-finance-theft/"}]},{"content":"Between November 28 and December 2, 2023, the web frontends of both Velodrome Finance and Aerodrome Finance were compromised in two distinct attacks separated by approximately three days. The first attack ran from approximately November 28 at 1:58 AM ET to November 29 at 1:49 PM ET. A second attack occurred from December 1 at 9:42 PM ET to December 2 at 12:13 AM ET. In both cases, attackers used social engineering against the domain registrar to bypass two-factor authentication and gain control of the velodrome.finance and aerodrome.finance domain names. Nameservers were then redirected to attacker-controlled clones of the legitimate frontends. Users who connected wallets on the fraudulent sites were prompted to sign malicious transactions directing funds to attacker-controlled addresses. Velodrome's official incident report (published December 3, 2023 on Medium) documented four attacker wallet addresses: 0xf64fcedfce714bbe835761e54d7067f2f8231443, 0x02ba13f39d7df9c3f7592257b636ed6c7cc4ae78, 0x554b54b6691e1f90a5902bf46d24d7f316e33b11, and 0x927e18fd7c854f43ae9f3c6ec4d03de28ab092dc. The combined user loss across both attacks was estimated at approximately $250,000. Blockchain analyst ZachXBT reported on the incident and attributed the vulnerability to the domain registrar's security failures, including repeated susceptibility to social engineering. No smart contract code was compromised. Nameservers were restored on November 30 at 7:53 AM and full account recovery followed the same day; the second attack was separately mitigated. Following these incidents, the teams began migrating domain infrastructure and implemented additional security controls.","heading":"DNS / Frontend Compromise — November–December 2023","severity":"high","sources":[{"credibility":1,"name":"11/29/2023 Incident Report — Velodrome official Medium","type":"official","url":"https://medium.com/@VelodromeFi/11-29-2023-incident-report-92865dceb757"},{"credibility":2,"name":"Velodrome, Aerodrome websites compromised for second time in days — The Block","type":"news","url":"https://www.theblock.co/post/265776/velodrome-aerodrome-websites-compromised-for-second-time-in-days"},{"credibility":3,"name":"DeFi Protocols VelodromeFi and AerodromeFi Suffer Dual Hacks — DailyCoin","type":"news","url":"https://dailycoin.com/velodrome-and-aerodrome-suffer-dual-frontend-hacks-in-3-days/"},{"credibility":3,"name":"Twin DEXs Velodrome and Aerodrome Suffer Front-End Security Breach — CoinPedia","type":"news","url":"https://coinpedia.org/news/twin-dexs-velodrome-and-aerodrome-suffer-front-end-security-breach/"}]},{"content":"On November 21–22, 2025, the centralized domains of both Velodrome Finance and Aerodrome Finance were again compromised via DNS hijacking. According to a post-incident report published by the teams, the root cause was an insider threat at domain registrar NameSilo, operating in conjunction with the 3DNS system. Attackers bypassed multisig controls within the 3DNS infrastructure, removed DNSSEC protections from the affected domains, and redirected traffic to phishing pages that solicited wallet approvals and malicious transaction signatures. Users were prompted to sign transactions that appeared as '1' followed by unlimited token approval requests across multiple chains. Within two minutes of the first confirmed malicious transaction, major wallets including MetaMask and Coinbase Wallet began displaying warnings to users. Full remediation of the compromise, including patch distribution, was completed in under four hours. Estimated user losses ranged between $700,000 and over $1,000,000 depending on the source, with no official final figure published at time of writing. Security partners Blockaid, 0xGroomLake, SEAL, and FTI Consulting assisted in containment. Smart contracts for both protocols remained fully intact throughout the incident. The teams subsequently announced plans to migrate to decentralized domain infrastructure using ENS-based mirrors, directing users to aero-drome.eth.limo and equivalent ENS addresses as safe alternatives during the disruption.","heading":"DNS / Frontend Compromise — November 2025 (NameSilo Insider Threat)","severity":"critical","sources":[{"credibility":3,"name":"Aerodrome and Velodrome Published Report on NameSilo Hack — Incrypted","type":"news","url":"https://incrypted.com/en/aerodrome-and-velodrome-published-report-on-namesilo-hack/"},{"credibility":2,"name":"Top DEXs Aerodrome, Velodrome hit with front-end compromise — The Block","type":"news","url":"https://www.theblock.co/post/380037/top-dexs-aerodrome-velodrome-hit-with-front-end-compromise-urge-users-to-avoid-main-domains"},{"credibility":2,"name":"DNS Attack Strikes Aerodrome and Velodrome as Aero Merger Nears — Bitcoin News","type":"news","url":"https://news.bitcoin.com/dns-attack-strikes-aerodrome-and-velodrome-as-aero-merger-nears/"},{"credibility":2,"name":"Aerodrome Finance Hit by Front-End Attack — CoinDesk","type":"news","url":"https://www.coindesk.com/web3/2025/11/22/aerodrome-finance-hit-by-front-end-attack-users-urged-to-avoid-main-domain"},{"credibility":2,"name":"Explained: The Aerodrome Finance Hack (November 2025) — Halborn","type":"news","url":"https://www.halborn.com/blog/post/explained-the-aerodrome-finance-hack-november-2025"},{"credibility":2,"name":"Aerodrome and Velodrome suffer website takeovers, again — Web3 Is Going Great","type":"news","url":"https://www.web3isgoinggreat.com/?id=aerodrome-and-velodrome-website-takeovers"}]},{"content":"Velodrome's official November 29, 2023 incident report identified four wallet addresses associated with the attacker who redirected funds during the DNS hijack: 0xf64fcedfce714bbe835761e54d7067f2f8231443, 0x02ba13f39d7df9c3f7592257b636ed6c7cc4ae78, 0x554b54b6691e1f90a5902bf46d24d7f316e33b11, and 0x927e18fd7c854f43ae9f3c6ec4d03de28ab092dc. No attacker addresses have been publicly confirmed for the 2025 NameSilo incident at time of writing. No on-chain addresses attributable to the Gabagool insider theft have been publicly documented in available sources; Gabagool stated funds were sent to Tornado Cash but specific originating or receiving addresses were not disclosed in any sourced reporting.","heading":"On-Chain Attacker Addresses (2023 Incident)","severity":"high","sources":[{"credibility":1,"name":"11/29/2023 Incident Report — Velodrome official Medium","type":"onchain","url":"https://medium.com/@VelodromeFi/11-29-2023-incident-report-92865dceb757"}]},{"content":"In May 2022, prior to launch, Velodrome Finance ran a competitive audit on the Code4rena platform. The contest identified 23 unique vulnerabilities, of which 6 were rated HIGH severity and 17 rated MEDIUM severity. The team reported resolving all HIGH and MEDIUM findings before deployment, with one known issue (users able to claim rewards from ExternalBribe contracts more than once) noted as in progress. Velodrome also maintains a bug bounty program on Immunefi. In all three confirmed security incidents affecting the protocol, the underlying smart contracts were not exploited; losses in the 2023 and 2025 DNS events arose solely from users interacting with attacker-controlled phishing frontends. This distinction is material: the protocol's on-chain code has not been demonstrated to have critical exploitable vulnerabilities in production, though the frontend attack surface has proven repeatedly vulnerable.","heading":"Smart Contract Security and Audits","severity":"medium","sources":[{"credibility":1,"name":"Velodrome Finance contest Findings & Analysis Report — Code4rena","type":"official","url":"https://code4rena.com/reports/2022-05-velodrome"},{"credibility":1,"name":"Velodrome Finance Bug Bounties — Immunefi","type":"official","url":"https://immunefi.com/bug-bounty/velodromefinance/resources/"},{"credibility":1,"name":"Security — Velodrome Finance Docs","type":"official","url":"https://docs.velodrome.finance/security"}]},{"content":"Velodrome and its sister protocol Aerodrome have suffered verified DNS hijack or frontend compromise events in at least three distinct periods: August 2022 (insider wallet access), November–December 2023 (double DNS attack via social engineering of a domain registrar), and November 2025 (NameSilo insider threat). The recurrence of DNS-layer attacks within roughly two years, despite security changes implemented after each incident, indicates a structural vulnerability in the protocols' reliance on centralized domain registrar infrastructure. Researchers and commentators have noted that this attack surface is a systemic risk for DeFi protocols using traditional DNS rather than decentralized naming systems. The 2025 attack occurred despite the teams having experienced an identical attack category in 2023. The protocol has announced post-2025 plans to migrate toward ENS-based decentralized domain infrastructure. Users accessing either protocol through traditional browser URLs (velodrome.finance, aerodrome.finance) face documented historical risk of encountering phishing frontends during any future registrar-level compromise.","heading":"Persistent Frontend / Web2 Attack Surface Risk","severity":"high","sources":[{"credibility":2,"name":"Aerodrome/Velodrome Front-End Breach: Understanding the Web2 Attack Surface in Web3 Protocols — Credshields","type":"news","url":"https://discover.credshields.com/aerodrome-velodrome-front-end-breach-understanding-the-web2-attack-surface-in-web3-protocols/"},{"credibility":2,"name":"Base and Optimism's Top DEXs Suffer DNS Hijack in Repeat Attack Nearly Two Years Later — FinanceFeeds","type":"news","url":"https://financefeeds.com/base-and-optimisms-top-dexs-suffer-dns-hijack-in-repeat-attack-nearly-two-years-later/"}]}],"sources_used":[],"summary":"Velodrome Finance is an automated market maker (AMM) and decentralized exchange launched in June 2022 on the Optimism network, and is the protocol's leading liquidity hub. The project has suffered two categories of verified security incidents: an insider theft of approximately $350,000 by a pseudonymous team member in August 2022 (funds subsequently recovered), and two separate DNS/frontend compromise events in November–December 2023 and November 2025 that together resulted in an estimated $950,000 or more in user losses. Smart contract code has not been exploited in any confirmed incident, but repeated failures at the domain-infrastructure layer represent a persistent and unresolved operational risk.","timeline":[{"date":"2022-06","event":"Velodrome Finance launches on Optimism network as an AMM modeled on Solidly Exchange. VELO token issued with vote-escrow mechanics.","source":"OKX Learn — What is Velodrome Finance","source_url":"https://www.okx.com/en-us/learn/what-is-velodrome-velo"},{"date":"2022-05","event":"Pre-launch Code4rena competitive audit identifies 23 vulnerabilities (6 HIGH, 17 MEDIUM). Team reports all critical issues resolved before deployment.","source":"Code4rena — Velodrome Finance contest report","source_url":"https://code4rena.com/reports/2022-05-velodrome"},{"date":"2022-08-04","event":"Team member 'Gabagool' (gabagool.eth) steals approximately $350,000 from Velodrome operational wallet. Funds converted to ETH and sent to Tornado Cash.","source":"The Block — Velodrome says team member stole $350,000","source_url":"https://www.theblock.co/post/163404/velodrome-says-team-member-stole-350000-from-the-projects-wallet"},{"date":"2022-08-13","event":"Velodrome publicly identifies Gabagool as the thief. Gabagool publicly admits the theft and returns the full $350,000, citing guilt. Velodrome severs ties with Gabagool and retains attorneys.","source":"CoinTelegraph — Velodrome recovers $350K stolen funds from team member Gabagool","source_url":"https://cointelegraph.com/news/velodrome-recovers-350k-stolen-funds-from-team-member-gabagool"},{"date":"2022-08-15","event":"Velodrome confirms full fund recovery and announces security improvements: private key access revoked from individuals, Gnosis Safe multisig implemented.","source":"The Crypto Times — Velodrome Regains $350k Stolen by its Developer Gabagool","source_url":"https://www.cryptotimes.io/2022/08/15/velodrome-regains-350k-stolen-by-its-developer-gabagool/"},{"date":"2023-11-28","event":"First DNS hijack attack begins on velodrome.finance and aerodrome.finance domains. Social engineering of domain registrar bypasses 2FA. Phishing frontends deployed.","source":"Velodrome official incident report — Medium","source_url":"https://medium.com/@VelodromeFi/11-29-2023-incident-report-92865dceb757"},{"date":"2023-11-29","event":"Nameservers restored at 7:53 AM ET. Velodrome and Aerodrome warn users to avoid main domains. ZachXBT reports on incident, estimates losses over $100,000, attributes registrar failure.","source":"Velodrome official incident report — Medium","source_url":"https://medium.com/@VelodromeFi/11-29-2023-incident-report-92865dceb757"},{"date":"2023-12-01","event":"Second DNS hijack attack begins on the same domains at 9:42 PM ET, exploiting continued registrar vulnerability.","source":"Velodrome official incident report — Medium","source_url":"https://medium.com/@VelodromeFi/11-29-2023-incident-report-92865dceb757"},{"date":"2023-12-02","event":"Second attack mitigated by 12:13 AM ET. Combined user losses from both November/December 2023 attacks estimated at approximately $250,000. Four attacker wallet addresses documented on-chain.","source":"Velodrome official incident report — Medium","source_url":"https://medium.com/@VelodromeFi/11-29-2023-incident-report-92865dceb757"},{"date":"2023-12-03","event":"Velodrome publishes comprehensive post-incident report documenting attack timeline, attacker addresses, and planned security improvements.","source":"Velodrome official incident report — Medium","source_url":"https://medium.com/@VelodromeFi/11-29-2023-incident-report-92865dceb757"},{"date":"2025-11-21","event":"Third DNS compromise event begins. NameSilo insider threat actor bypasses 3DNS multisig controls and DNSSEC on Velodrome and Aerodrome domains. Phishing pages deployed across both protocols.","source":"CoinDesk — Aerodrome Finance Hit by Front-End Attack","source_url":"https://www.coindesk.com/web3/2025/11/22/aerodrome-finance-hit-by-front-end-attack-users-urged-to-avoid-main-domain"},{"date":"2025-11-22","event":"Attack confirmed and publicly disclosed. MetaMask and Coinbase Wallet display warnings within two minutes of first malicious transaction. Full remediation completed in under four hours. Estimated user losses between $700,000 and $1,000,000+.","source":"Bitcoin News — DNS Attack Strikes Aerodrome and Velodrome","source_url":"https://news.bitcoin.com/dns-attack-strikes-aerodrome-and-velodrome-as-aero-merger-nears/"},{"date":"2025-11-22","event":"Teams announce migration toward ENS-based decentralized domain infrastructure. Users directed to ENS mirrors as safe alternatives to centralized domains.","source":"Halborn — Explained: The Aerodrome Finance Hack (November 2025)","source_url":"https://www.halborn.com/blog/post/explained-the-aerodrome-finance-hack-november-2025"}]},"v":1}