From Teenage DeFi Prodigies to SEC Defendants: The Rise and Collapse of Rari Capital
Rari Capital's trajectory ran from breakout success to regulatory censure, passing through two major exploits and a prolonged, disorderly wind-down along the way. Today, user funds remain stranded in abandoned smart contracts while the protocol's founders face SEC sanctions.
Origins

Rari Capital was founded by three young developers — Jai Bhavnani, Jack Lipstone, and David Lucid — who built a robo-advisor for DeFi yield farming. Unlike much of the anonymous DeFi landscape, the three founders operated publicly. Their pitch was an algorithm that automatically routed deposits toward optimal yield, and they charged a 20% performance fee at a time when competitors offered similar services for free. Early on, deposits were capped at $350.
The concept caught on quickly. At its peak, Rari's Fuse lending pools held over $1 billion in user deposits.
First exploit: May 2021
The protocol's first major security failure came in May 2021, when an attacker who had previously targeted Value DeFi's BNB pools turned to Rari. The attack first hit Rari on BSC, draining $11 million, before the same technique was used against the protocol's Ethereum deployment.
The exploit relied on fake tokens and crafted payloads to drain 2.9k ETH from Rari's ETH pool. By the time the team managed to secure the remaining funds, the attacker had extracted a combined $10 million. The attacker subsequently attempted to delete a parting message left on-chain, though the transaction data remained accessible regardless.
In response, Rari's team committed to reimbursing users with $26 million drawn from its developer fund — more than double the amount stolen. The reimbursement quieted the immediate fallout, but it did not resolve the underlying security weaknesses in the protocol.
Second exploit: April 2022
Roughly a year later, on April 30, 2022, Rari was hit again — this time via a re-entrancy vulnerability that allowed an attacker to repeatedly withdraw funds before the protocol's internal accounting could catch up, ultimately draining $80 million.
By this point, Rari had merged with Fei Protocol. Fei offered the attacker a $10 million bounty in exchange for returning the stolen funds, an offer that went unaccepted.
The damage extended well beyond Rari's own users. Babylon Finance, which had allocated six of its investment "gardens" — worth $3.4 million — into Rari's Fuse pools, saw its total value locked fall from $30 million to $4 million in a single day, and its native token BABL collapsed to near zero. Babylon founder Ramon Recuero later described the compounding pressures the bear market, the hack's aftermath, and the loss of roughly three months' worth of operating funds among the factors that pushed the protocol to shut down.
The fallout also reached Tribe DAO, the governance body behind Fei Protocol's stablecoin, which was deeply enmeshed in the Fuse hack's aftermath. Tribe DAO initially voted to fully reimburse affected users, but the process became mired in repeated revotes and vetoes. What began as a commitment to full repayment eroded through debate, failed votes, and eventually the DAO's own dissolution.
Shutdown and frozen funds
By February 2023, Rari Capital's front-end interface had been taken offline entirely as part of the broader Tribe DAO wind-down. Users were given until February 29 to redeem REPT-B tokens and interact with the official Rari Capital applications before that window closed.
After the deadline, user balances remained visible on-chain but effectively inaccessible without direct smart contract interaction — a technical bar most users could not clear. The only realistic path to recovering funds was catching brief liquidity windows that opened during liquidation events, which required both the expertise to spot them and the ability to execute on-chain transactions manually. The loss of the front end also blocked borrowers from repaying outstanding loans, even those who wanted to.
SEC action: September 2024

In September 2024, the SEC brought charges against the protocol. The agency's findings characterized Rari's "autonomous" yield strategies as far less automated than advertised, noted that roughly one in three investors using the platform lost money, and concluded that the protocol's billion-dollar TVL had been built on unregistered securities offerings.
The resulting penalties included permanent injunctions, civil fines, and five-year industry bans for those involved.
Separately, Rari Capital's Twitter account briefly became active again in May 2024, only to be compromised shortly after.
Where things stand
Rari Capital's smart contracts remain deployed and unchanged, holding user balances that are visible on block explorers but largely unreachable. Sporadic liquidation events remain the only mechanism by which some users might recover access to their deposits. The protocol's history — two major exploits followed by a contested wind-down and, ultimately, SEC enforcement — illustrates how a lack of resolution after a hack can compound into a much longer-term loss of user access and institutional accountability.
Get new scam files the moment we publish them — usually 2–3 emails a week.