GoonFi Hack
What happened
A late-March 2026 incident affected GoonFi's v2 WSOL/USDC pool on Solana. Security monitoring records describe an approximately $254,000 loss after a program configuration or logic issue created a pool mispricing. The team reportedly halted the affected program.
Public reporting identifies a configuration or program-logic issue that caused pool mispricing, but no detailed technical postmortem was available at review time. The precise vulnerable instruction and invariant remain unconfirmed.
Case & protocol details
Attack Timeline
The public incident records agree on the affected product and outcome but do not provide a full technical postmortem naming the vulnerable instruction or invariant. Available monitoring states that the WSOL/USDC Prop AMM v2 pool became mispriced because of a program configuration or logic error. Searchers could then exploit that incorrect quote in atomic Solana transactions to trade at a price the pool should not have offered.
This record therefore avoids assigning a more specific root cause than the evidence supports.
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.