
Post-mortem: Legacy Veil Cash Fixed Pools Incident Yesterday, an incident impacted Veil Cash legacy fixed-denomination pools on Base. Live Veil pools (ETH, USDC, cbBTC) and staking were not affected. These pools were sunset from new deposits ~6 months ago and had no withdrawals from remaining funds in the past ~3 months. Timeline: At ~18:09 UTC, an exploiter drained ~2.9 ETH from ~4.5 ETH remaining in the legacy pools via a ZK proof forgery caused by a misconfigured Groth16 verifier. A whitehat (@DefimonAlerts) intervened shortly after, recovering 2.025 ETH and returning funds to veildotcash.eth. Later at ~22:05 UTC, the exploitor returned the remaining funds to veildotcash.eth without prior contact. In summary, 100% of funds from the affected pools have now been recovered and secured. Next steps: - Working with security partners to deploy a return contract enabling funds to be claimed by rightful owners. - Strengthening validation and expanding audit cadence across all current Veil Cash contracts. The affected legacy pools remain deprecated. The Veil Cash protocol continues operating normally.













