Value DeFi Protocol
Summary
Value DeFi Protocol is a yield aggregation and automated market-making platform that operated on Ethereum and Binance Smart Chain, offering products including vSafe vaults, vSwap, and governance staking. The protocol suffered at least three major security exploits between November 2020 and May 2021, resulting in a combined estimated loss of approximately $23 million across multiple incidents. The protocol is notably remembered for having publicly claimed flash loan attack prevention the day before its first and most publicized exploit.
Connected Entities
1 entities · 10 linked investigationsTimeline(9 events)
2020-11-13
Value DeFi published a tweet (later deleted) claiming the protocol had the 'highest security' and was capable of preventing flash loan attacks. The MultiStables vault was launched.
Bitcoin News2020-11-14
Flash loan exploit drained approximately $7.4 million in DAI from the MultiStables vault. Attacker used 80,000 ETH from Aave and ~$116 million DAI from Uniswap to manipulate Curve 3pool oracle prices. Attacker returned $2 million and left on-chain message: 'do you really know flashloan?'
CoinDesk / PeckShield2020-11-15
Value DeFi published official post-mortem acknowledging two root cause vulnerabilities, halted MultiStables vault deposits, and announced IOU compensation mechanism for affected users.
Value DeFi Medium (Official)2020-11-16
Value DeFi announced integration with Chainlink's decentralized oracle network to replace the AMM-based Curve spot price oracle that was exploited.
Decrypt2021-05-05
Second major exploit on BSC: attacker re-initialized the vStake pool due to a missing 'initialized = true' guard in the initialize() function, assumed owner role, and called governanceRecoverUnsupported() to drain approximately $10 million.
rekt.news2021-05-07
Iron Finance, a partner protocol whose liquidity pools were affected by the Value DeFi vStake exploit, published an incident report confirming the impact.
Iron Finance Medium2021-05-08
Third exploit: Value DeFi's vSwap module on BSC was exploited via a flaw in the ensureConstantValue validation function, allowing an attacker to drain multiple liquidity pools using flash loans. SlowMist published an analysis.
SlowMist / Medium2021-05-08
Value DeFi became the first protocol to appear twice on the rekt.news REKT leaderboard following the successive May 2021 exploits.
rekt.newsDecision Log
- hash: CFJdwJgJzd7CYRnaWcz3QZ1nf8VcyjwX5Uca3FLiSEvQ
This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.
model: claude-sonnet-4-6
generated: 5/31/2026, 7:00:16 AM
last updated: 5/31/2026, 7:00:19 AM
avoid.net — verified advice for a post-truth world