Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·4ZUJiZ…b2dZSummary
Qubit Finance was a Binance Smart Chain lending and cross-chain bridge protocol developed by South Korean firm Mound Inc., the same team behind PancakeBunny. On January 27, 2022, an attacker exploited a logic error in the QBridge Ethereum-BSC bridge to mint approximately 77,162 qXETH tokens without depositing any ETH, then drained roughly $80 million in protocol assets; no funds were ever recovered and the attacker was never identified.
Connected Entities
2 entities · 1 linked investigation- + 2 more
Connected Through
1 shared actor · 1 investigationDistinct actors this investigation shares with others — holders, traders, and named parties. Shared infrastructure (exchanges, pools) is excluded.
- ⌂Qubit Financeprotocolalso inQubit Finance·5
Timeline(16 events)
April 2021
Mound Inc. receives $1.6 million seed funding from Binance Labs
19 May 2021
PancakeBunny, Mound Inc.'s other protocol, suffers a $45 million flash loan exploit
23 November 2021
QBridge smart contract first deployed on Binance Smart Chain
29 November 2021
QBridge smart contract first deployed on Ethereum
27 January 2022
Attacker wallet (0xd01ae1a708614948b2b5e0b7ab5be6afa01325c7) funded via Tornado Cash at 9:18 PM UTC
27 January 2022
Attacker submits 16 fraudulent deposit() transactions to QBridge on Ethereum between 9:34 PM and 9:50 PM UTC with zero ETH attached
27 January 2022
BSC relayer processes 16 voteProposal transactions between 9:36 PM and 9:51 PM UTC, minting qXETH for attacker without any real deposit
27 January 2022
Attacker uses minted qXETH as collateral to borrow and extract approximately 206,809 BNB (~$80 million) from the protocol
28 January 2022
Qubit Finance disables all core protocol functions and publicly discloses the exploit
28 January 2022
Qubit team appeals to attacker to return funds, initially offering $250,000 bug bounty
29 January 2022
Qubit team increases bounty offer to $1 million; attacker does not respond publicly
31 January 2022
Bounty offer reported to have been raised to $2 million with no prosecution pledge
8 February 2022
Qubit Finance publishes compensation plan: Team Mound surrenders all tokens to community, commits to debt-funded $10M initial tranche
February 2022
Qubit Finance transfers governance authority to community DAO
8 February 2022
Qubit team announces $500,000 bounty for information identifying the attacker, files reports with international law enforcement
2022
Protocol ceases operations; no funds recovered; attacker never identified or charged
Decision Log
- hash: EhzA6kJzwANPU1nsX7VLiijA4Zunmn3G2VkmqBiUenj
This investigation is cryptographically anchored to the Solana blockchain (1 event). 15 of 23 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 5/4/2026, 2:54:51 AM
last updated: 9/1/2026, 7:26:08 AM
avoid.net — verified advice for a post-truth world