Preview surface — demo data. Where real data exists today (e.g. RealT, BlackRock BUIDL, Lift Dollar) we render it; everywhere else we render synthetic enrichment generated deterministically from public signal and clearly marked Demo or Inferred. The Phase 3 roadmap replaces every synthetic source with live ingestion — see Methodology → Exposure Graph & Similarity Engine.

Goldfinch

Lending, Money Markets & CDPsmedium·risk 0.4834·TVL $1.3M·blast $1.3M·active
Static profile (Identity / Contract / Dependency / Governance / Reputation)

Identity

Sector
Lending, Money Markets & CDPs
Subsector tags
consumer_app, general_defi, infra_toolingDemo
Chain deployments
Ethereum
Website
https://www.goldfinch.xyzDemo
Launch date
Oct 24, 2021
Immutable
noDemo
Permissionless
yesDemo

Contract

Primary address
0xdab396ccf3d84cf2d07c4454e10c8a6f5b008d2b
Proxy pattern
none
Upgrade authority
UNKNOWN
Multisig threshold
Compiler
0.8.13
Uses assembly
noDemo
Bug bounty
noneDemo
Contract addresses
0xdab396ccf3d84cf2d07c4454e10c8a6f5b008d2bDemo
Audits tier
0

Dependency

Oracle providers
Bridge dependencies
Stablecoin dependencies
LST / LRT deps
Demo
DEX liquidity venues
balancerDemo
CEX listings
bybitDemo
Custodian
Demo
KMS provider
unknownDemo
RPC provider
self_hostedDemo
Frontend host
cloudflare_pagesDemo
npm lockfile sha
sha256:79085e4bf51a188bec32f4f778056f707acdb79a7e34883529f1b667e9120617Demo

Governance

Governance type
delegatedDemo
Governance token
0x1f6b7ec50dd982f08358fa40af77fa14c59d3466Demo
Treasury size
$8.6KDemo
Team size
25Demo
Jurisdiction
GBDemo
Incorporated entity
Goldfinch DAO LLCDemo
Anonymous team
noDemo
Security disclosure
noDemo
IR SLA (hours)
Demo

Reputation

GitHub
https://github.com/goldfinch/goldfinchDemo
Commit velocity (30d)
5Demo
Contributors
18Demo
Twitter
@goldfinchDemo
Discord
https://discord.gg/1ahvp44Demo
Last incident
Nov 21, 2025Demo
KYT screening
cleanDemo

Threat History

1 recorded incident
phishing drainerhuman opunattributed_criminalDemo
$1M

On 2025-11-21, Goldfinch suffered a phishing drainer incident resulting in approximately $1,045,627 in losses. The exploit targeted the human_op layer. Attribution: unattributed_criminal. This is a demonstration entry — not a real incident.

DEMO:AADAPT.TA0001DEMO:AADAPT.TA0040

Peer Incidents · Method B

10 root-cause predicate matches

Vulnerable to: reentrancy

Matches the reentrancy predicate

28 historical peer events
  • SommelierDemo
    $30.7M
  • Kyber NetworkDemo
    $2.1M
  • DeribitDemo
    $936K
  • Zora NetworkDemo
    $4.7M
  • Stader LabsDemo
    $16.1M
  • + 23 more

Vulnerable to: phishing drainer

Matches the phishing drainer predicate

17 historical peer events
  • BitgetDemo
    $739.9K
  • OrcaDemo
    $180.8K
  • Ether.fiDemo
    $443.4K
  • Alchemy PayDemo
    $334.2K
  • Curve FinanceDemo
    $755.7K
  • + 12 more

Vulnerable to: ice phishing approval

Matches the ice phishing approval predicate

16 historical peer events
  • deBridgeDemo
    $7.5M
  • EulerDemo
    $87.9K
  • Bend DAODemo
    $968.9K
  • Maple FinanceDemo
    $1.4M
  • BlurDemo
    $6.5M
  • + 11 more

Vulnerable to: frontend dns hijack

Matches the frontend dns hijack predicate

12 historical peer events
  • Bridge.xyz / StripeDemo
    $10.4M
  • UK FCA Digital SandboxDemo
    $3.6M
  • Three SigmaDemo
    $2.7M
  • CryptoQuantDemo
    $517.3K
  • Celsius (defunct)Demo
    $22M
  • + 7 more

Vulnerable to: rounding precision

Matches the rounding precision predicate

10 historical peer events
  • Frax EtherDemo
    $51.2K
  • BNY Mellon DigitalDemo
    $750K
  • RedStoneDemo
    $63.2K
  • Bend DAODemo
    $57.9K
  • Starknet BridgeDemo
    $784.1K
  • + 5 more

Vulnerable to: supply chain npm

Matches the supply chain npm predicate

10 historical peer events
  • Beefy FinanceDemo
    $176.2K
  • PowerledgerDemo
    $7.4M
  • UnichainDemo
    $8.8M
  • MEXCDemo
    $1M
  • Mango MarketsDemo
    $915.6K
  • + 5 more

Vulnerable to: dvn collapse

Matches the dvn collapse predicate

8 historical peer events
  • Blast, Blockdaemon Wallet +2Demo
    $93.6M
  • Fordefi, XSGDDemo
    $17M
  • Element Finance, QuantozDemo
    $1.1M
  • Mercado Bitcoin, SwellDemo
    $15.3M
  • Internet Computer (DFINITY), Mantle +1Demo
    $10.3M
  • + 3 more

Vulnerable to: signature malleability

Matches the signature malleability predicate

8 historical peer events
  • Ether.fiDemo
    $17.2M
  • Swell NetworkDemo
    $1.2M
  • Immutable protocolDemo
    $4M
  • The SandboxDemo
    $3.9M
  • PancakeSwapDemo
    $656.7K
  • + 3 more

Vulnerable to: governance proposal malicious

Matches the governance proposal malicious predicate

5 historical peer events
  • Stripe CryptoDemo
    $1.5M
  • Notional V3Demo
    $507.1K
  • Hong Kong Monetary Authority — Ethereum pilotsDemo
    $18.9M
  • FalconXDemo
    $4.8M
  • AvailDemo
    $30.8M

Vulnerable to: prompt injection agent

Matches the prompt injection agent predicate

4 historical peer events
  • LodestarDemo
    $3.2M
  • Ether.fi CashDemo
    $4.6M
  • HTX (Huobi)Demo
    $3.7M
  • SwellDemo
    $403K

Dependency Twins · Method A + B + C ensemble

Top 10 of 25 precomputed
#1

Unichain

Rollups, Data Availability & ZK Infra · high
Ensemble
0.506
A · Jaccard0.21
B · Overlap2
C · Cosine0.95
Matches on
  • kms_provider = unknown
  • frontend_host = cloudflare_pages
  • subsector_tags = general_defi, consumer_app
  • chain_deployments = Ethereum
#2

The Sandbox

Identity, NFTs, Gaming & Consumer Apps · low
Ensemble
0.462
A · Jaccard0.14
B · Overlap2
C · Cosine0.87
Matches on
  • kms_provider = unknown
  • subsector_tags = consumer_app, general_defi, infra_tooling
  • chain_deployments = Ethereum
  • method_b_root_causes = signature_malleability, ice_phishing_approval
#3

Lift Dollar (USDL)

Stablecoin Issuers & Synthetic Dollars · high
Ensemble
0.459
A · Jaccard0.17
B · Overlap2
C · Cosine0.83
Matches on
  • kms_provider = unknown
  • subsector_tags = general_defi, consumer_app
  • chain_deployments = Ethereum
  • method_b_root_causes = reentrancy, rounding_precision
#4

Immutable protocol

Stablecoin Issuers & Synthetic Dollars · medium
Ensemble
0.457
A · Jaccard0.18
B · Overlap2
C · Cosine0.81
Matches on
  • kms_provider = unknown
  • subsector_tags = consumer_app, general_defi, infra_tooling
  • chain_deployments = Ethereum
  • method_b_root_causes = signature_malleability
#5

Blur

Identity, NFTs, Gaming & Consumer Apps · high
Ensemble
0.457
A · Jaccard0.14
B · Overlap2
C · Cosine0.85
Matches on
  • kms_provider = unknown
  • subsector_tags = infra_tooling, general_defi, consumer_app
  • chain_deployments = Ethereum
  • method_b_root_causes = reentrancy, ice_phishing_approval
#6

BNY Mellon Digital

Institutional Custody & Prime Services · critical
Ensemble
0.446
A · Jaccard0.22
B · Overlap1
C · Cosine1.00
Matches on
  • kms_provider = unknown
  • frontend_host = cloudflare_pages
  • subsector_tags = consumer_app, infra_tooling, general_defi
  • chain_deployments = Ethereum
#7

API3

Oracles & Off-Chain Data Networks · medium
Ensemble
0.426
A · Jaccard0.21
B · Overlap1
C · Cosine0.95
Matches on
  • kms_provider = unknown
  • frontend_host = cloudflare_pages
  • subsector_tags = general_defi, consumer_app
  • chain_deployments = Ethereum
#8

Radiant Capital

Lending, Money Markets & CDPs · medium
Ensemble
0.422
A · Jaccard0.12
B · Overlap2
C · Cosine0.75
Matches on
  • kms_provider = unknown
  • subsector_tags = consumer_app, infra_tooling, general_defi
  • chain_deployments = Ethereum
  • method_b_root_causes = reentrancy, ice_phishing_approval
#9

Sanctum

Liquid Staking & Restaking · critical
Ensemble
0.415
A · Jaccard0.09
B · Overlap2
C · Cosine0.76
Matches on
  • kms_provider = unknown
  • subsector_tags = general_defi, consumer_app
  • method_b_root_causes = reentrancy
#10

Euler

Lending, Money Markets & CDPs · low
Ensemble
0.410
A · Jaccard0.11
B · Overlap2
C · Cosine0.73
Matches on
  • subsector_tags = general_defi, infra_tooling
  • chain_deployments = Ethereum
  • method_b_root_causes = signature_malleability, ice_phishing_approval