Menu
Browse

Cyber Incident Victim: Team Finance

Date

Oct 2022

Location

United States of America

Status

Historical

Timeline
Occurred
Oct 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending
Summary

A decentralized finance platform suffered a security breach resulting in the loss of nearly $15 million in cryptocurrency due to an exploit targeting an audited contract migration function. The attacker exploited a code vulnerability during the platform's version upgrade process, prompting an immediate suspension of new lock creations and collaboration with multiple blockchain security firms to trace and recover funds. Despite outreach attempts, the perpetrator remained unresponsive, while external analyses confirmed the incident stemmed from a technical flaw despite prior audits and security measures. The platform expressed optimism regarding potential fund recovery while emphasizing its established safeguards.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On October 27, 2022, decentralized finance platform Team Finance suffered a security breach resulting in the loss of nearly $15 million in cryptocurrency. The attack exploited a vulnerability in the platform’s v2 to v3 migration function, which had undergone prior audits. Attackers manipulated this mechanism to drain funds from multiple token pools, including those of verified projects such as Lendora and SwapX. Team Finance detected the incident shortly after it began and immediately paused all new lock creation functions to prevent further unauthorized access. The platform confirmed the breach publicly, disclosing that the stolen funds comprised various cryptocurrencies converted by the attacker into approximately 4,646 ETH. Security firms PeckShield, SlowMist, and BlockSec independently analyzed blockchain transactions, tracing the attacker’s wallet address and confirming the exploit’s technical basis in flawed migration contract logic. Team Finance spokesperson Brett Fabian stated the organization attempted to contact the hacker through on-chain messages but received no response regarding fund return negotiations.

Cyber Incident Image

The incident disrupted Team Finance’s core locking and migration services, affecting projects relying on its infrastructure for liquidity management. In response, the platform collaborated with blockchain analytics firms and law enforcement to track the stolen assets while conducting internal code reviews. Team Finance emphasized its security protocols, noting the exploited migration function had passed multiple third-party audits before deployment. Concurrently, the breach occurred amid a series of October 2022 DeFi exploits, including attacks on Moola Market ($9 million loss) and Mango Markets ($100 million loss), though no direct connection between these incidents was established. No user wallet compromises occurred, as the attack exclusively targeted Team Finance’s protocol-level contracts. The platform committed to ongoing forensic analysis and recovery efforts while maintaining other system functionalities during the investigation.

Sources
Sources available to members
1 source