A Flash Loan, an Inflated Token, and $3.5M Gone From Nirvana Finance
Nirvana Finance, a newly launched protocol on Solana, lost $3.5 million to a flash loan exploit. The project markets itself as a form of "DeFi 3.0," promising to "transform risk into reward" with a "known maximum downside and unlimited upside" — a pitch undercut by a loss amounting to almost 90% of its value.
News of the exploit was first broken by the SolanaFM team, and the Nirvana team confirmed the loss hours later. A detailed post mortem has not yet been released.

As happened previously with Crema Finance, the attacker sourced flash loans from Solend — the same lending protocol that went through a governance crisis the prior month.
Nirvana's team has since appealed directly to the attacker, asking for the funds to be returned.
How the exploit worked: The attacker borrowed a $10 million flash loan from Solend and used it to mint ANA tokens, driving the ANA price up from roughly $8 to approximately $24. With ANA artificially inflated, the attacker then swapped the overpriced tokens for USDT through Nirvana's treasury contract, pocketing about $3.5 million in profit on top of the borrowed capital. The proceeds were bridged out via Wormhole to an Ethereum address controlled by the attacker, where they remained as of publication.
Attacker's Solana address: 76w4SBe2of2wWUsx2FjkkwD29rRznfvEkBa1upSbTAWH
Attack transaction: LyUnvdY9…
Nirvana's treasury contract: CxuuSEv67PzNkMxqCvHeDUr6HKaadoz8NhTfxbQSJnaG

The incident lands at a moment when Solana's momentum appears to be fading. The ecosystem's "Solana summer" run — boosted last year by SBF-linked hype — has cooled considerably since the Wormhole exploit. With venture capital increasingly flowing toward newer layer-1 chains touted for speed and scalability, projects like Nirvana raise the question of whether such launches represent the tail end of a maturing ecosystem's speculative cycle.
Nirvana's own documentation leans heavily on DeFi jargon, with claims such as ANA "protects its holders against catastrophic stablecoin depegging" and that "the ANA token cannot go to zero." The price charts for both its "superstable" NIRV token and "reserve-backed" ANA token tell a very different story following the attack.
The protocol had also touted an "automatic audit" completed just weeks before the exploit. A widely shared comment on the Solana Forums questioning the protocol's actual function proved prescient. The team appears to have accepted the outcome for now, with the future of its tokens left uncertain.
Get new scam files the moment we publish them — usually 2–3 emails a week.