Goldfinch Finance Hack

TOTAL LOST $330K
Low Access Control Attacks ethereum

What happened

On December 2, 2025, attackers exploited a legacy Goldfinch test contract deployed before the protocol's public launch, draining about $330,000 USDC through a false loan-repayment path that could draw against users' token allowances.

Technical Root Cause

A legacy test contract retained a false-repayment path that could pull USDC from wallets with an allowance set for that contract. The vulnerable deployment remained live even though the issue had been fixed before Goldfinch's public launch.

Case & protocol details

Classification Access Control / Token Approval Abuse
Protocol Type Exploit/Other
Smart Contract Language Solidity
Official Website www.goldfinch.finance/
Protocol Twitter/X @goldfinch_fi

Market Context at Time of Hack

Token Price at Hack $0.2525
Market Cap at Hack $23.5M
% of Market Cap Stolen 1.40%
Token Categories
Collectibles & NFTs Gaming Metaverse Play To Earn BNB Chain Ecosystem

Attack Timeline

Goldfinch's governance forum explains that a September 2020 test contract contained a critical issue that had been fixed before public launch but was never patched on the old deployment. The attacker could make a false loan repayment using a victim address and collect the resulting interest, allowing USDC to be taken up to each affected wallet's allowance for the contract. Goldfinch disabled the legacy contract after the incident and proposed using $250,000 from its bug-bounty budget toward victim reimbursement; that proposal is not recorded here as recovered funds.

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.