Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·31xUDY…VoMRSummary
Cozy V2 is a DeFi protection marketplace deployed on Optimism that allows users to buy or provide protection against smart contract hacks, depegs, and other on-chain risks. On August 29, 2025, the protocol suffered a $427,000 exploit caused by a missing caller verification check in its withdrawal logic, with funds subsequently bridged to Ethereum mainnet and deposited into Tornado Cash. The incident is notable for its irony: a protocol designed to insure against DeFi hacks was itself hacked through a preventable authorization flaw.
Connected Entities
1 entitiesCommunity submissions
- Under reviewincriminatingWayback pending9/12/2026, 1:39:12 PM
“Confirmed second exploit (Sept 7, 2026) using the same unpatched UMA oracle attack surface as the first hack. Repeat-offense failure materially worsens the protocol's trust profile.”
— avoid-scout
Timeline(8 events)
3 September 2020
Cozy Finance announces $2M seed round led by Electric Capital; founders Tony Sheng and Payom Dousti publicly named.
September 2021
Cozy Finance V1 launches on Ethereum mainnet as an open-source protection market protocol.
13 March 2023
Euler Finance hacked for approximately $200M. Cozy V2 early-access Euler Finance market triggers and pays out to Protection Buyers, validating core trigger logic.
2023
Cozy V2 launches on Optimism (OP Mainnet) with redesigned permissionless protection marketplace architecture; V1 subsequently sunset.
28 August 2025
Victim initiates redemption of approximately $376,661 (redemption ID 6) on Cozy V2 on Optimism.
29 August 2025
Attacker exploits missing caller verification in `completeWithdraw` function, redirecting victim's redemption proceeds to attacker's address. Total loss reaches approximately $427,000.
30 August 2025
Decurity publicly reports the exploit on X, noting attacker bridged funds from Optimism to Ethereum mainnet and deposited into Tornado Cash.
30 August 2025
Verichains publishes detailed technical post-mortem of the Cozy Protocol incident, classifying the root cause as insufficient sender verification.
Decision Log
- hash: 2U1weMNkVD1SjSp6Lk556Vu1Gfn11fvxdJwW7FEGgfCq
- hash: BNmAMBMsxYZxW8E1mwwE7M2fRpL8W1HTyV1xD91AYoL4
This investigation is cryptographically anchored to the Solana blockchain (2 events). 5 of 10 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 5/4/2026, 2:54:21 AM
last updated: 9/15/2026, 5:10:50 PM
7 viewsavoid.net — verified advice for a post-truth world