Goldfinch Finance Hack
What happened
On December 2, 2025, attackers exploited a legacy Goldfinch test contract deployed before the protocol's public launch, draining about $330,000 USDC through a false loan-repayment path that could draw against users' token allowances.
A legacy test contract retained a false-repayment path that could pull USDC from wallets with an allowance set for that contract. The vulnerable deployment remained live even though the issue had been fixed before Goldfinch's public launch.
Case & protocol details
Attack Timeline
Goldfinch's governance forum explains that a September 2020 test contract contained a critical issue that had been fixed before public launch but was never patched on the old deployment. The attacker could make a false loan repayment using a victim address and collect the resulting interest, allowing USDC to be taken up to each affected wallet's allowance for the contract. Goldfinch disabled the legacy contract after the incident and proposed using $250,000 from its bug-bounty budget toward victim reimbursement; that proposal is not recorded here as recovered funds.
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report x.com
- report Report x.com
- analysis Goldfinch Governance: GIP-85 Hack Response gov.goldfinch.finance
- analysis DefiLlama: Goldfinch incident record defillama.com
- analysis PeckShield Alert x.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.