Skip to main content
Sign in
Wise Lending V21 decision on this page

Audit log

Every state-changing event for Wise Lending V2: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions carry three independent witnesses — the original source, an Internet Archive snapshot taken at submission time, and a Solana memo signed by our publicly-disclosed publisher key.

  1. #1publishby system:backfill
    2026-05-29 15:54:32Z
    Score: ?? (no score change)
    anchoranchored
    chain
    mainnet-betaslot 422,969,568
    sig
    cwWm9QUW2NHV…6cxi4VVQexplorer ↗
    hash
    XjLtCCFQqFp6…E9TaMoZZsha256 → base58
    verifying row…full verify ↗
    canonical bytes (5102 B) ▸
    {"actor":"system:backfill","investigation_id":"7bbe4d9d-74e7-4ff7-b64b-d7a630072930","kind":"publish","page_slug":"wise-lending-v2","published_at":"2026-05-29T15:54:32.049Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Wise Lending V2","sections":[{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://wiselending.com/","type":"other","url":""},{"credibility":3,"name":"https://defillama.com/protocol/wise-lending-v2","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://blog.solidityscan.com/wise-lending-hack-analysis-f652f389e397","type":"other","url":""},{"credibility":3,"name":"https://medium.com/@astrasec/wiselending-hack-root-cause-analysis-1a2762f52298","type":"other","url":""},{"credibility":3,"name":"https://www.fxstreet.com/cryptocurrencies/news/wise-lending-market-exploited-for-177-eth-in-a-flash-loan-attack-202401130252","type":"other","url":""},{"credibility":3,"name":"https://coincodecap.com/wise-lending-faces-440k-loss-in-suspected-flash-loan-exploit-of-crypto-assets","type":"other","url":""},{"credibility":3,"name":"https://www.infect3d.xyz/blog/wise-lending-post-mortem","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://cointelegraph.com/news/wise-lending-drained-440k-crypto-apparent-flash-loan-exploit","type":"other","url":""},{"credibility":3,"name":"https://coincodecap.com/wise-lending-faces-440k-loss-in-suspected-flash-loan-exploit-of-crypto-assets","type":"other","url":""},{"credibility":3,"name":"https://cryptorank.io/news/feed/62124-wise-lending-loses-400000-flash-loan-attack","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://code4rena.com/reports/2024-02-wise-lending","type":"other","url":""},{"credibility":3,"name":"https://code4rena.com/audits/2024-02-wise-lending","type":"other","url":""},{"credibility":3,"name":"https://github.com/code-423n4/2024-02-wise-lending","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://blog.solidityscan.com/wise-lending-hack-analysis-f652f389e397","type":"other","url":""},{"credibility":3,"name":"https://medium.com/@astrasec/wiselending-hack-root-cause-analysis-1a2762f52298","type":"other","url":""},{"credibility":3,"name":"https://www.infect3d.xyz/blog/wise-lending-post-mortem","type":"other","url":""},{"credibility":3,"name":"https://code4rena.com/reports/2024-02-wise-lending","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://defillama.com/protocol/wise-lending-v2","type":"other","url":""},{"credibility":3,"name":"https://code4rena.com/reports/2024-02-wise-lending","type":"other","url":""},{"credibility":3,"name":"https://cryptorank.io/news/feed/62124-wise-lending-loses-400000-flash-loan-attack","type":"other","url":""},{"credibility":3,"name":"https://coinpaper.com/3049/major-incidents-from-last-week-wise-lending-exploit-and-xai-token-rug-pull","type":"other","url":""}]}],"sources_used":[],"summary":"Wise Lending V2 is a decentralized lending and yield-farm aggregator protocol deployed on Ethereum and Arbitrum that allows users to supply crypto assets and earn variable yields. The protocol suffered two confirmed exploits: a price manipulation attack in October 2023 that caused approximately $260,000 in losses, followed by a more severe flash loan and share-inflation attack on January 12, 2024 that drained approximately $464,000. The January 2024 attack exploited a precision flaw in the protocol's ERC-4626-style share accounting logic, and a subsequent Code4rena audit in February 2024 identified 5 high-severity and 17 medium-severity vulnerabilities in the codebase.","timeline":[{"date":"2023-10-13","event":"Wise Lending suffers its first confirmed exploit — a price manipulation attack — resulting in approximately $260,000 in losses.","source":""},{"date":"2024-01-12","event":"Wise Lending V2 exploited via flash loan and ERC-4626 share inflation attack. Approximately 177 ETH (~$464,000) drained from the PLP-stETH-Dec2025 pool. Attacker contract: 0x91c49cc7fbfe8f70aceeb075952cd64817f9d82c. Exploit first reported on-chain by researcher Spreek.","source":""},{"date":"2024-02-21","event":"Code4rena competitive audit of Wise Lending V2 begins, covering 44 smart contracts and 6,326 lines of Solidity.","source":""},{"date":"2024-03-11","event":"Code4rena audit concludes. Report identifies 5 HIGH-severity and 17 MEDIUM-severity vulnerabilities.","source":""},{"date":"2024-03-11","event":"Code4rena audit report for Wise Lending V2 published, detailing 22 unique vulnerabilities in the protocol codebase.","source":""},{"date":"2026-02-28","event":"A $66,000 flash loan exploit affecting Wise Lending V2 on both Arbitrum and Ethereum chains is recorded by DeFiLlama's hack tracker. Independent news confirmation was not located at time of investigation.","source":""}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 2bbf992b-8721-4470-b394-8943fc13f19f
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.