Skip to main content
AVOID.NET

Cozy V2

avoid.net/cozy-v242/100·72% conf.
[AI-DRAFTED · AWAITING VERIFICATION][src:defillama]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·31xUDY…VoMR

Summary

Cozy V2 is a DeFi protection marketplace deployed on Optimism that allows users to buy or provide protection against smart contract hacks, depegs, and other on-chain risks. On August 29, 2025, the protocol suffered a $427,000 exploit caused by a missing caller verification check in its withdrawal logic, with funds subsequently bridged to Ethereum mainnet and deposited into Tornado Cash. The incident is notable for its irony: a protocol designed to insure against DeFi hacks was itself hacked through a preventable authorization flaw.

Connected Entities

1 entities
Organizations
Cozy V2
Relationships
    Have evidence about Cozy V2?
    0
    Accepted
    1
    Under review
    0
    Rejected / revoked

    Community submissions

    • Under reviewincriminatingWayback pending9/12/2026, 1:39:12 PM

      Confirmed second exploit (Sept 7, 2026) using the same unpatched UMA oracle attack surface as the first hack. Repeat-offense failure materially worsens the protocol's trust profile.

      avoid-scout

    Timeline(8 events)

    3 September 2020

    Cozy Finance announces $2M seed round led by Electric Capital; founders Tony Sheng and Payom Dousti publicly named.

    September 2021

    Cozy Finance V1 launches on Ethereum mainnet as an open-source protection market protocol.

    13 March 2023

    Euler Finance hacked for approximately $200M. Cozy V2 early-access Euler Finance market triggers and pays out to Protection Buyers, validating core trigger logic.

    2023

    Cozy V2 launches on Optimism (OP Mainnet) with redesigned permissionless protection marketplace architecture; V1 subsequently sunset.

    28 August 2025

    Victim initiates redemption of approximately $376,661 (redemption ID 6) on Cozy V2 on Optimism.

    29 August 2025

    Attacker exploits missing caller verification in `completeWithdraw` function, redirecting victim's redemption proceeds to attacker's address. Total loss reaches approximately $427,000.

    30 August 2025

    Decurity publicly reports the exploit on X, noting attacker bridged funds from Optimism to Ethereum mainnet and deposited into Tornado Cash.

    30 August 2025

    Verichains publishes detailed technical post-mortem of the Cozy Protocol incident, classifying the root cause as insufficient sender verification.

    Provenance & Audit Trail

    Decision Log

    This investigation is cryptographically anchored to the Solana blockchain (2 events). 5 of 10 cited source URLs have an Internet Archive snapshot.

    model: claude-sonnet-4-6

    generated: 5/4/2026, 2:54:21 AM

    last updated: 9/15/2026, 5:10:50 PM

    7 views

    avoid.net — verified advice for a post-truth world