Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·3VQQu8…v41ZSummary
Lendf.me was a decentralized lending protocol built by dForce Network and launched in September 2019 as a fork of Compound v1. On April 19, 2020, an attacker exploited a reentrancy vulnerability involving ERC-777 tokens to drain approximately $25.2 million from the protocol — at the time representing 99.95% of its total value locked. The attacker returned nearly all funds within two days after inadvertently exposing identifying metadata, and the original Lendf.me contract was permanently deprecated following the incident.
Connected Entities
1 entitiesTimeline(9 events)
2018
Mindao Yang founds dForce Network in late 2018 as a China-based open finance protocol.
September 2019
Lendf.me lending protocol launches as a fork of Compound v1, initially supporting a limited set of Ethereum assets.
14 April 2020
dForce announces a $1.5 million strategic funding round led by Multicoin Capital, with Huobi Capital and CMBI participating.
19 April 2020
At approximately 12:58 AM UTC, attacker (EOA: 0xa9bf70a420d364e923c74448d9d817d3f2a77822) begins exploiting the ERC-777 reentrancy vulnerability. By 9:15 AM UTC+8, dForce discovers the attack. Lendf.me contracts are paused approximately one hour after the exploit begins. Approximately $25.2 million (~99.95% of TVL) is drained across 12 liquidity pools.
20 April 2020
dForce files a police report with Singapore authorities. The attacker's identifying metadata — including IP address and device fingerprint — is obtained from a CDN provider via subpoena. The attacker returns approximately $2.79 million as a first partial repayment.
21 April 2020
The attacker returns the remaining stolen funds, completing near-total restitution. dForce opens its Asset Recovery System for user withdrawals.
27 April 2020
dForce reports that over 90% of recovered assets have been redistributed to users and that 100% of affected users will be made whole.
May 2020
dForce publishes the 'Better Future' Proposal announcing 2,000,000 DF token airdrop to hack-affected users, creation of the dSAFU insurance fund with 50,000,000 DF tokens, and security improvement commitments. The original Lendf.me contract is permanently deprecated.
March 2021
Trail of Bits publishes a security audit of the redesigned dForce Lending protocol, reflecting post-incident security improvements.
Decision Log
- hash: 2o9JxGhJayJmNr6tKivQp5SNCEuLSUZYrYzr7qiiGGi3
This investigation is cryptographically anchored to the Solana blockchain (1 event). 14 of 21 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 5/4/2026, 2:55:00 AM
last updated: 9/1/2026, 4:16:58 AM
avoid.net — verified advice for a post-truth world