Skip to main content
AVOID.NET

dForce Lending

avoid.net/dforce-lending28/100·82% conf.
[AI-DRAFTED · AWAITING VERIFICATION][src:defillama]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·9Q7gDt…f1nM

Summary

dForce Lending (operating as Lendf.Me) is a Chinese-founded DeFi lending protocol that suffered a landmark ~$25 million ERC-777 reentrancy exploit in April 2020 — one of the largest DeFi hacks of that year — and a second reentrancy attack in February 2023 that drained $3.65 million. In both incidents, stolen funds were ultimately returned after the attackers were identified or negotiated with. The protocol has also faced persistent allegations of plagiarizing Compound Finance's open-source smart contract code without attribution, and a 2021 ConsenSys Diligence audit flagged centralised owner controls capable of draining user funds. ZachXBT has flagged dForce as a high-risk entity.

Connected Entities

1 entities
Organizations
dForce Lending
Relationships
  • + 3 more
Have evidence about dForce Lending?

Timeline(12 events)

2018

dForce founded by Mindao Yang in China as an integrated open finance protocol.

2019

dForce Foundation established; Lendf.Me lending market launched.

2020

The Block reports that dForce's Lendf.Me contracts contain unattributed references to Compound Finance code; attribution later added after press inquiry.

14 April 2020

Multicoin Capital announces $1.5M seed investment in dForce, with Huobi Capital and CMBI as co-investors.

19 April 2020

Lendf.Me exploited via ERC-777 reentrancy attack; approximately $25 million in assets drained. dForce pauses contracts and takes website offline.

20 April 2020

1inch exchange reports the attacker exposed their Chinese IP address and device fingerprint. Attacker begins symbolic PAX token peace transactions totaling ~$250,000 to dForce, 1inch, and ParaSwap.

22 April 2020

Compound's Robert Leshner and Kava Labs' Brian Kerr publicly allege dForce copied Compound's code without authorization or understanding.

25 April 2020

Attacker returns full ~$25 million to dForce. Huobi-issued assets worth ~$2.6M were the first to be returned.

4 May 2020

dForce confirms 100% of recovered funds redistributed to affected Lendf.Me users.

9 April 2021

ConsenSys Diligence publishes dForce Lending Protocol audit, flagging Owner role as single point of failure with unchecked power to drain user funds, and governance transition as untested.

9 February 2023

dForce Lending exploited via read-only reentrancy on Curve wstETH/ETH vault on Arbitrum and Optimism; $3.65 million drained.

13 February 2023

Attacker self-identifies as a whitehat, returns all $3.65 million to dForce multi-sig wallets in exchange for a bug bounty; dForce drops threatened law enforcement action.

Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event). 18 of 22 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 5/4/2026, 2:55:01 AM

last updated: 9/11/2026, 4:14:52 PM

6 views

avoid.net — verified advice for a post-truth world