Verify a decision
Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.
How verification works
- We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (
payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction. - We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
- You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is
AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.
Decision
publish · Demex Perp
- Sequence
- #1
- Score
- →
- Cluster
- mainnet-beta
- Slot
- 455648474
- Off-chain at
- 2026-10-11T12:18:08.008Z
- Anchored at
- 2026-10-11T12:18:23.324Z
- Block time
- —
Independent verification
- 1. Database (off-chain)
- 8r5vBh8ex8tgqTNJYapFFsQimEYueSBe7CwHkBS8Zokf
- 2. Recomputed (your browser)
- computing…
- 3. On-chain (Solana memo)
- fetching…
Canonical bytes hashed (14246 chars)
{"actor":"system:backfill","investigation_id":"4d0aa3b9-1dfa-4941-950f-58797d794734","kind":"publish","page_slug":"demex-perp","published_at":"2026-10-11T12:18:07.887Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Demex Perp","sections":[{"content":"According to Demex's own post-mortem, published on its official blog, the protocol's cross-chain bridge was exploited on 25 September 2026. The attacker exploited a trust gap between the bridge module and the on-chain contract system: the two subsystems accepted each other's reports without independent verification. Using a falsified deployment report submitted through Demex's generic execute flow, the attacker registered a pairing in the bridge registry that equated nLEND -- a low-value Demex-native synthetic token worth about $0.12 at the time -- with the canonical WETH and WBNB token contracts. Because the bridge released assets unit-for-unit against whatever pairing was registered, withdrawing roughly 87.27 nLEND (worth about $10) triggered payouts of 64.78 WETH (about $174,495) on Ethereum and 22.49 WBNB (about $17,434) on BNB Chain, for a combined loss the post-mortem states as 'roughly $191,929 in ETH and BNB.' DefiLlama's hacks database separately lists an entry for 'Demex Perp' dated to September 25, 2026, classified as 'Bridge & Cross-Chain' with technique 'Cross-Chain Message Spoofing' and an amount of $191,929, corroborating the independent financial figure.","heading":"The September 25, 2026 Bridge Exploit","severity":"critical","sources":[{"credibility":2,"name":"Demex official post-mortem: \"25 Sep 2026 Demex Exploit Post-Mortem\"","type":"official","url":"https://blog.dem.exchange/25-sep-2026-demex-exploit-post-mortem/"},{"credibility":2,"name":"DefiLlama Hacks Database (api.llama.fi/hacks) — \"Demex Perp\" entry","type":"research","url":"https://defillama.com/hacks"},{"credibility":3,"name":"demex: Sep 25 bridge exploit ($191,929) missing from hacks DB — DefiLlama-Adapters issue #21527","type":"community_report","url":"https://github.com/DefiLlama/DefiLlama-Adapters/issues/21527"}]},{"content":"Per the official post-mortem, the attacker spent several hours preparing before executing the exploit: beginning around 13:03 UTC on September 25, 2026, they bought roughly 95 nLEND tokens on Demex's own order book for about $60 and deployed a helper contract on Ethereum. Four attempts to get a falsified token-deployment report accepted by Demex's registry failed, including a direct request rejected at 18:22 UTC as unauthorized. A fifth attempt succeeded at 18:29 UTC, registering the nLEND-to-WETH pairing. The Ethereum-side WETH withdrawal, matching the entire balance held by the Ethereum gateway, went through at 19:09 UTC; a parallel sequence against WBNB on BNB Chain followed within about four minutes. The post-mortem identifies several compounding failures: a $50,000-per-24-hours withdrawal cap measured the token amount deducted rather than the dollar value released, so the roughly $192,000 in withdrawals was valued internally at only $10.47 and never triggered the cap; prior security audits and AI-assisted code reviews reportedly did not catch the flaw because it only manifested when the bridge module and contract system were reviewed together; and changes to the bridge registry were not independently monitored or alerted on. The team states it takes 'full responsibility' for these engineering and review gaps. The post-mortem also discloses that similar registration probes were detected and rejected in June 2026, though the team says it cannot confirm whether the same attacker was responsible.","heading":"Attack Mechanism and Technical Root Cause","severity":"high","sources":[{"credibility":2,"name":"Demex official post-mortem: \"25 Sep 2026 Demex Exploit Post-Mortem\"","type":"official","url":"https://blog.dem.exchange/25-sep-2026-demex-exploit-post-mortem/"}]},{"content":"Demex's admin multisignature account executed an emergency chain-halt transaction, which the post-mortem states occurred 52 minutes after the first exploit withdrawal (the same document elsewhere states the chain was halted 'within 37 minutes of confirmation,' an internal inconsistency in the published account that readers should note). The halt interrupted a parallel attack sequence the attacker had queued against Base at 19:47 UTC, before any funds could be drained on that chain. The post-mortem states that this response 'protected the $976,000 still held across Demex's bridge reserves.' As of the post-mortem's publication and at the time of this investigation, Demex remains halted 'until further notice,' with the team stating its immediate task is a full accounting of bridge-held tokens against reserves on each connected network. DefiLlama's protocol tracker for Demex Perp shows total value locked essentially frozen at roughly $185,000-$199,000 since the halt, with a reported 30-day decline of over 30%, consistent with trading activity having stopped.","heading":"Emergency Halt and Ongoing Shutdown","severity":"high","sources":[{"credibility":2,"name":"Demex official post-mortem: \"25 Sep 2026 Demex Exploit Post-Mortem\"","type":"official","url":"https://blog.dem.exchange/25-sep-2026-demex-exploit-post-mortem/"},{"credibility":3,"name":"demex: Sep 25 bridge exploit ($191,929) missing from hacks DB; demex-perp TVL frozen since halt","type":"community_report","url":"https://github.com/DefiLlama/DefiLlama-Adapters/issues/21527"}]},{"content":"The official post-mortem does not commit to a specific restart date or a concrete compensation plan for affected users or for depositors whose funds remain locked behind the halt. It states only that the team is 'evaluating the best path forward' and is 'optimistic that remediation of the lost funds will be possible.' Because the chain remains halted at the time of this report, depositors with funds in the protocol face an ongoing, live risk of inaccessible funds pending an unspecified restart, independent of whether their specific holdings were among those directly drained in the exploit. No independent regulatory or law-enforcement action related to this incident was found in available sources, and no major wire-service or large crypto-news outlet coverage (e.g., Reuters, CoinDesk, The Block) of this specific incident was identified in available search results; reporting currently rests on Demex's own disclosure and a DefiLlama-Adapters community tracking issue, which is a narrower evidentiary base than for larger, more widely covered exploits.","heading":"User Fund Risk and Absence of a Compensation Plan","severity":"high","sources":[{"credibility":2,"name":"Demex official post-mortem: \"25 Sep 2026 Demex Exploit Post-Mortem\"","type":"official","url":"https://blog.dem.exchange/25-sep-2026-demex-exploit-post-mortem/"}]},{"content":"This is not the first loss event associated with the Demex ecosystem. DefiLlama's hacks database separately lists a May 2025 incident attributed to 'Demex,' classified as oracle manipulation ('Spot Price Manipulation'), with a loss of $950,559 on the Arbitrum chain. A security newsletter from Olympix described this as an exploit of 'Nitron (on Demex),' in which an attacker donated fsGLP tokens to a low-liquidity dGLP vault, artificially inflating the reported price of dGLP, and then used the overpriced dGLP as collateral to borrow other assets at a profit. The recurrence of a second, unrelated class of exploit (cross-system trust/registry manipulation in September 2026, following oracle price manipulation in May 2025) within roughly sixteen months suggests a pattern of recurring security gaps in the Demex/Carbon ecosystem's cross-protocol integrations, though available sources do not establish a common root cause between the two incidents.","heading":"Prior Incident: Nitron/Demex Oracle Manipulation (May 2025)","severity":"medium","sources":[{"credibility":2,"name":"DefiLlama Hacks Database — \"Demex\" entry (May 2025, oracle manipulation)","type":"research","url":"https://defillama.com/hacks"},{"credibility":2,"name":"Olympix: \"96k could have been saved if only...\"","type":"research","url":"https://olympix.substack.com/p/96k-could-have-been-saved-if-only"}]},{"content":"Demex is a cross-chain perpetual futures and derivatives trading platform built on the Carbon protocol, a Cosmos SDK-based layer-2 trading infrastructure that was formerly known as Switcheo TradeHub. It is associated with Switcheo Labs, a Singapore-based company whose founders have been publicly identified in industry profiles as including Ivan Poon, Henry Chua, and Jack Yeu; Demex itself has been described in coverage as a non-custodial derivatives platform that went live on a public testnet in September 2020. CoinMarketCap listings describe Demex/Carbon as linked to multiple chains including Ethereum, BNB Chain, Neo, and Zilliqa, and some CoinMarketCap exchange listings for Demex are currently marked as delisted with no tracked trading volume, though it is not established in available sources whether that status is connected to the September 2026 halt.","heading":"Background: Demex and Switcheo Labs","severity":"low","sources":[{"credibility":2,"name":"The Defiant: \"Demex: Revolutionizing Perpetual Trading, Opens Up Market Making for Anyone\"","type":"news_article","url":"https://thedefiant.io/news/defi/demex-revolutionizing-perpetual-trading-opens-up-market-making-for-anyone"},{"credibility":3,"name":"CoinMarketCap: Demex exchange listing","type":"other","url":"https://coinmarketcap.com/exchanges/demex/"}]}],"sources_used":[{"credibility":2,"name":"Demex official post-mortem: \"25 Sep 2026 Demex Exploit Post-Mortem\"","type":"official","url":"https://blog.dem.exchange/25-sep-2026-demex-exploit-post-mortem/"},{"credibility":2,"name":"DefiLlama Hacks Database","type":"research","url":"https://defillama.com/hacks"},{"credibility":3,"name":"demex: Sep 25 bridge exploit ($191,929) missing from hacks DB — DefiLlama-Adapters issue #21527","type":"community_report","url":"https://github.com/DefiLlama/DefiLlama-Adapters/issues/21527"},{"credibility":2,"name":"Olympix: \"96k could have been saved if only...\"","type":"research","url":"https://olympix.substack.com/p/96k-could-have-been-saved-if-only"},{"credibility":2,"name":"The Defiant: \"Demex: Revolutionizing Perpetual Trading, Opens Up Market Making for Anyone\"","type":"news_article","url":"https://thedefiant.io/news/defi/demex-revolutionizing-perpetual-trading-opens-up-market-making-for-anyone"},{"credibility":3,"name":"CoinMarketCap: Demex exchange listing","type":"other","url":"https://coinmarketcap.com/exchanges/demex/"}],"summary":"Demex Perp, the perpetuals venue built on the Carbon protocol (formerly Switcheo TradeHub) and operated by Switcheo Labs, had its cross-chain bridge exploited on September 25, 2026 for roughly $191,929. An attacker used registry manipulation to pair the low-value synthetic token nLEND with canonical WETH and WBNB, draining 64.78 WETH and 22.49 WBNB before an emergency multisig halt stopped a parallel attempt on Base and protected an estimated $976,000 in remaining bridge reserves. As of this writing the chain remains halted with no restart date or compensation plan announced, leaving depositors' remaining funds inaccessible.","timeline":[{"date":"2026-06","event":"Demex detects and rejects registry-registration probes later believed, with low confidence, to possibly be connected to the same attacker who carried out the September exploit.","source":"Demex official post-mortem","source_url":"https://blog.dem.exchange/25-sep-2026-demex-exploit-post-mortem/"},{"date":"2025-05","date_evidence":"On May 16, the Nitron (on Demex) exploit on the Arbitrum chain resulted in a $951K loss due to a price manipulation attack.","date_original":"2025-05-16","event":"A prior exploit attributed to 'Demex' (Nitron, an associated lending protocol) results in a reported $950,559-$951,000 loss via oracle/spot-price manipulation on Arbitrum.","source":"DefiLlama Hacks Database; Olympix newsletter","source_url":"https://olympix.substack.com/p/96k-could-have-been-saved-if-only"},{"date":"2026-09","date_evidence":"On 25 September, Demex's bridge was exploited. Roughly $191,929 in ETH and BNB was taken from the contracts holding bridged funds.","date_original":"2026-09-25","event":"Attacker registers a falsified nLEND-to-WETH/WBNB pairing in Demex's bridge registry and withdraws 64.78 WETH and 22.49 WBNB (~$191,929 combined).","source":"Demex official post-mortem","source_url":"https://blog.dem.exchange/25-sep-2026-demex-exploit-post-mortem/"},{"date":"2026-09","date_evidence":"The admin multisignature account performed an emergency chain halt transaction 52 minutes after the first exploit withdrawal.","date_original":"2026-09-25","event":"Demex's admin multisig executes an emergency chain halt, stopping a parallel attack sequence queued against Base and protecting an estimated $976,000 in remaining bridge reserves.","source":"Demex official post-mortem","source_url":"https://blog.dem.exchange/25-sep-2026-demex-exploit-post-mortem/"},{"date":"2026-09","date_evidence":"article:published_time content=\"2026-09-29T10:00:02.000Z\"","date_original":"2026-09-29","event":"Demex publishes its official post-mortem of the exploit on its company blog.","source":"Demex official blog","source_url":"https://blog.dem.exchange/25-sep-2026-demex-exploit-post-mortem/"},{"date":"2026-10-09","date_evidence":"api.llama.fi/hacks (no Sep 2026 Demex entry, checked Oct 9 2026)","event":"A contributor opens a GitHub issue on DefiLlama-Adapters flagging that the September 25 exploit was absent from DefiLlama's public hacks database and that Demex Perp's tracked TVL had been flat since the halt.","source":"DefiLlama-Adapters GitHub issue #21527","source_url":"https://github.com/DefiLlama/DefiLlama-Adapters/issues/21527"},{"date":"2026-10","event":"By the time of this investigation, DefiLlama's hacks database (api.llama.fi/hacks) lists a 'Demex Perp' entry dated September 25, 2026 for $191,929, indicating the previously flagged database gap has since been addressed.","source":"DefiLlama Hacks Database","source_url":"https://defillama.com/hacks"}]},"v":1}