Kannagi Finance Vanishes With $1.1M in zkSync Yield Vault Rug Pull
A yield aggregator operating on zkSync, Kannagi Finance, executed an exit scam on Saturday, walking away with an estimated $1.1 million in user funds.
Before the rug pull, DeFiLlama data put the protocol's total value locked at roughly $2.1 million; that figure has since collapsed to about $0.17. The project's website and social media accounts were taken down in the aftermath.

The protocol had passed two audits and had been promoted — via a giveaway tweet that has since been deleted — by SyncSwap, a leading name in the zkSync ecosystem. SyncSwap had also backed EraLend, another zkSync protocol that lost $3.4 million to an exploit just days earlier, on the preceding Tuesday.
The episode adds to a growing pattern in which incomplete audits and casual endorsements end up lending unwarranted credibility to protocols that turn out to be unsafe. Credit for surfacing the incident goes to PeckShield.
How the funds were drained
There isn't much mystery to the mechanism. Kannagi's contract itself was unverified, but the audit report covering the vault stated plainly: "The MainChef address can initiate a withdrawal on behalf of a user by specifying the user's address and an amount to withdraw." That single privileged function gave whoever controlled the MainChef address the ability to pull funds out of any user's position on demand.
The address linked to the theft — 0x95ec03b821f164ce55cbb26f23f591a9bd40d6c1, visible on both zkSync and Ethereum — bridged the stolen assets to Ethereum, where 600 ETH (about $1.1 million at the time) was deposited into Tornado Cash.
Audit fallout

Auditing firm SolidProof subsequently issued a statement clarifying that the vulnerable vault contract had fallen outside the scope of the audit it performed, pointing instead to SourceHat (formerly Solidity Finance), which had audited the vault in question.
SourceHat's own audit report had flagged that "some centralized aspects are present" — a caveat that, in hindsight, understated the risk involved. That line sits alongside an earlier public statement from the firm asserting "No external vulnerabilities identified," where the qualifier "external" turns out to have carried far more weight than it appeared to at the time.
Whether users should bear more responsibility for parsing the fine print of audit findings — rather than treating any completed audit as a blanket guarantee — remains debatable, particularly given how routinely projects lean on audits as a marketing device to attract yield farmers and airdrop hunters. The incident leaves an open question about which L2 will be next to see this pattern repeat, with some pointing to Base.
Get new scam files the moment we publish them — usually 2–3 emails a week.