Exposed Minting Keys and a Broken Withdrawal Function Sink Levyathan Finance
Levyathan.finance collapsed the previous week, taking its roughly $1.5 million in TVL down with it. Since then, the team has published a series of tweets and lengthy Medium posts that appear more focused on deflecting blame than explaining what actually happened.
The root cause was straightforward: Levyathan's developers had left the private keys to a wallet with token-minting authority sitting exposed on GitHub. Around four months later, someone used those keys to mint a large supply of LEV and sell it off until the token's value was effectively wiped out.

Once holders tried to salvage whatever value remained by withdrawing their funds, they ran into a second problem: a bug in the withdrawal mechanism meant that even their now near-worthless tokens couldn't be pulled out. The project's admins responded to the situation on Twitter with a curt remark: "Have a nice day."
The project's official post-mortem reads almost beside the point once you consider how trivially exposed the minting keys were in the first place.
With the token's minting key compromised, affected users turned to the contract's emergencyWithdraw() function to try to recover their staked tokens. That function, however, had its own defect: it calculated the withdrawal amount using rewardDebt — a variable meant for reward accounting — rather than the user's actual staked balance (user.amount).
Some users who withdrew early via this route, including in this transaction, noticed they were receiving more tokens than they should have been owed. Recognizing the opportunity, they kept withdrawing repeatedly, pulling out more and more LEV and draining the contract before other, slower users had a chance to withdraw anything at all.
In its post-mortem, the Levyathan team also published an address where users could anonymously return any funds they'd extracted. That address has since accumulated roughly 3 billion units of assorted dog-themed tokens and a single token called PLUGANAL. A second address was later shared by the team, which has so far collected around 150,000 BUSD — funds that trace back to the first address the team had originally provided.

Taken together, it's a difficult sequence of failures to defend. Leaving clearly identifiable private keys sitting in a public repository is hard to excuse under any circumstances, and especially so when those keys grant unilateral control — with no multisig protection — over a protocol's native token.
In a subsequent update, the Levyathan team argued that because the keys had been publicly visible, this was proof "that it was not an inside job." That framing raised its own questions: had the team simply been careless, or was pointing to the exposed keys itself a convenient way to construct an alibi after the fact? That's left for readers to judge.
Get new scam files the moment we publish them — usually 2–3 emails a week.