Team Finance
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·5LCWas…FkgqSummary
Team Finance is a DeFi token-locking and vesting platform operated by TrustSwap Inc. that suffered a critical $14.5 million exploit on October 27, 2022, when an attacker abused a validation flaw in its Uniswap V2-to-V3 migration function. The attacker ultimately returned approximately $7 million, retaining roughly 10% as a self-declared bug bounty; Team Finance subsequently switched auditors to CertiK and reported full user reimbursement by June 2023.
Connected Entities
1 entitiesTimeline(10 events)
2020
Team Finance founded as part of TrustSwap Inc., offering token locking and vesting smart contracts for DeFi projects.
19 January 2022
Hacken conducts smart contract audit of Team Finance's LockToken.sol and related contracts; migrate() function not yet in scope as it had not been added to the codebase.
29 April 2022
TrustSwap publishes press release stating Team Finance has secured over $6.5 billion in total value and serves more than 21,000 projects.
August 2022
Zokyo conducts audit of Team Finance contracts including the migrate() function, flagging two critical vulnerabilities related to arbitrary token address use and reentrancy. Team Finance dismisses findings as 'intended logic.'
27 October 2022
Exploit executed: attacker drains approximately $14.5–15.8 million from four LP pools (FEG, CAW, TSUKA, KNDX) locked on Team Finance via a manipulated Uniswap V2-to-V3 migration call. Team Finance immediately pauses all protocol activity.
28 October 2022
Team Finance publicly appeals to the attacker to return funds in exchange for a bounty. SlowMist, KALOS Security, and other firms publish on-chain analysis of the exploit.
29 October 2022
Attacker begins returning funds to affected projects via on-chain transactions, identifying themselves as a 'whitehat' hacker in embedded transaction messages.
31 October 2022
Approximately $7 million in tokens returned to the four affected project communities (Kondux, Tsuka, FEG, CAW). Attacker retains roughly 10% as a self-declared bug bounty. CoinDesk and CoinTelegraph report on the partial recovery.
June 2023
Team Finance representative states that all affected users have received the vast majority of their funds back. Platform reports CertiK engaged as new auditor and multiple security enhancements implemented.
July 2023
Jeff Kirdeikis transitions from CEO to Board Chairman of TrustSwap.
Decision Log
- hash: 77tcvKWd2r6gMByqisRDwNXVvcwkaVq7x78KFaaMFyoE
This investigation is cryptographically anchored to the Solana blockchain (1 event). 9 of 15 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 5/4/2026, 2:54:47 AM
last updated: 8/30/2026, 5:14:12 AM
avoid.net — verified advice for a post-truth world