
Team Finance
HackedDeFi · born 2020 · ✝ 2022
The liquidity locker that couldn't lock itself.
Team Finance was a token-locking and liquidity-locking service that was exploited in October 2022. A flaw in its migrate function let an attacker drain locked liquidity from several projects' pools.
- Peak
- ~$15.8M stolen
- Cause
- Hacked
- Year of death
- 2022
☠️ Cause of death
A bug in the contract's migrate function allowed the attacker to move and drain locked liquidity that was meant to be inaccessible.
📓 Lessons left behind
- —A locker is a high-value target; its own code must be flawless.
- —Migration functions are dangerous escape hatches, audit them hard.
- —Formal verification fits invariant-critical custody contracts.
🌱 The idea that survived
Verifiable liquidity locks
Renewed scrutiny on the security of the very contracts projects rely on to prove locked liquidity.
#defi#liquidity#locker#logic-bug