Marinade Finance's Inverted Unstaking Logic Drained $5 Million From mSOL Holders Over Six Months
A single inverted piece of logic in Marinade Finance's validator auction system quietly turned a mechanism designed to reward performance into one that rewarded doing the opposite. For 126 epochs, validators exploited a broken unstaking algorithm, extracting outsized rewards while contributing almost nothing — not through any hack or sudden attack, but simply by understanding that the code punished high bidders and protected low ones.
mSOL holders absorbed the cost: roughly $5 million in losses, accumulated gradually and largely unnoticed until a user going by Shiroi raised the alarm. By that point, some 3.4 million SOL was sitting with validators who were underperforming yet still collecting delegation.

How the mechanism worked
Marinade's pitch to stakers was straightforward: deposit SOL, receive mSOL, and let the protocol handle validator selection through its Stake Auction Marketplace (SAM), where validators competitively bid for delegation rights. The stated rule was simple — the highest bidder wins the stake, and the lowest bidder is first in line to be unstaked. In principle, this should have created a competitive, self-correcting system rewarding the best-performing, highest-bidding validators.
In practice, the code implementing that unstaking priority was built backward. The consequence: validators who bid low were the ones protected from being pulled, not the ones removed first. GitHub records show the auction effectively rewarded the lowest bidders with both stake retention and safety from unstaking — the reverse of the design intent.
The exploit pattern that emerged followed a repeatable sequence: a validator would bid aggressively to win a large stake allocation; once that stake was confirmed, the validator would slash its bid down to the minimum possible unit — one lamport; the inverted priority logic would then treat that low bid as protection, pushing the validator further back in the unstaking queue rather than pulling its delegation; the validator could then continue collecting staking rewards indefinitely while paying almost nothing for the privilege. Wherever the system should have removed these actors, it retained them instead.
This went on for six months. More than 85 validators participated at various points, collectively diverting roughly 37,000 SOL — around $5 million — in rewards away from mSOL holders and toward themselves.
Scale of the exposure
At its high point, the exploit affected 3.4 million SOL in delegated stake — not the work of one bad actor, but a pattern replicated across dozens of validators. Among the worst single epochs by losses: epoch 773 lost 886 SOL, epoch 772 lost 875.8 SOL, and epoch 748 lost 808.8 SOL.
The single largest exploiter drained 1,081 SOL on its own, and seven of the ten worst offenders remained active on the network even after the issue became public. Several of those validators were also backed by the Solana Foundation and by Jito — reputationally established operators taking advantage of the same flaw.
Aggregated over 124 epochs, the data shows that an average of 28% of delegated stake went effectively unpaid for the service it should have provided, and in 24 individual epochs, more than half of the delegated stake earned nothing at all. In effect, validators who played by the rules ended up subsidizing those who didn't.
The response timeline
Despite the scale, Marinade's reaction was slow. On May 9, Shiroi posted a detailed incident report to the project's forum, laying out roughly 37,000 SOL in missing rewards. On May 10, independent community members began digging in, and it became clear this was not an isolated bug but a systemic pattern being actively exploited.
Marinade itself did not respond publicly until May 12, when it acknowledged the issue in general terms, without naming affected validators or accepting direct fault. That same day, the team introduced a new "BidTooLow" penalty, which ultimately penalized only two validators for a combined ~500 SOL.
By May 17, community reviewers checking on-chain data found the exploiting validators still active — their combined stake had actually grown, to 3.41 million SOL. In total, eight days elapsed between the initial disclosure and Marinade's first concrete action, while 126 epochs had passed between the start of the exploit and any partial remedy.
Notably, this was not an unknown risk. A GitHub issue filed weeks earlier by a user identified as Toshiyuki-Tega, titled "unstakePriority Calculation Appears Economically Suboptimal," had already flagged the exact inverted logic responsible. That issue was closed as "not planned," despite correctly describing the mechanism that would go on to cost users an estimated 37,000 SOL in missed rewards. The BidTooLow penalty that followed only caught validators who lowered their bids after already winning delegation — it did nothing for validators who had started with dust-level bids from the outset.
An unresolved problem
Weeks after disclosure, the underlying flaw remained largely intact. As of epoch 785, 92 validators were still bidding below 0.01 SOL while collectively controlling 2.6 million SOL in delegation. The patch's actual enforcement was limited: two validators had bonds slashed, worth 302 SOL and 44 SOL respectively, while the rest continued operating unaffected.
Separately, five validators set their MEV commission to 100%, maximizing their own extracted value while still remaining eligible for delegation under the unchanged rules — those five alone controlled 410,000 SOL. By epoch 788, the number of underbidding validators had edged down slightly to 85, but their combined stake had grown further, to 3.41 million SOL.

At its core, the bug was simple: a sorting algorithm ranked validators for unstaking priority in exactly the opposite order intended.
Community pushback
Forum activity intensified as Marinade struggled to explain months of inaction. Independent investigators continued to document how validators exploited the reversed sorting logic, pointing to cases where minimal bonds secured disproportionately large delegations. Even as some validators denied wrongdoing while continuing to profit, the protocol remained, by the community's own assessment, functionally compromised weeks into the disclosure process.
Why it matters
Judged purely by dollar amount, $5 million is a modest figure by the standards of crypto exploits. What makes this case notable is the mechanism: a quiet, six-month-long transfer of value made possible not by a dramatic attack but by an incentive structure that had simply been coded backward. There was no single attacker and no discrete point of failure — just validators responding rationally to a system that rewarded the wrong behavior.
Marinade's SAM auction was designed to be a transparent, math-driven upgrade to conventional staking delegation. Instead, it demonstrated how quickly an incentive system can be turned against its own users when its implementation doesn't match its design — in this instance, the code executed exactly as written, but what was written inverted the intended logic. The broader lesson is less about any single bad actor and more about complexity itself: intricate systems with non-obvious behavior create fertile ground for exploitation, whether or not anyone deliberately set out to abuse them, and known warnings about the flaw sat unaddressed for weeks before it was fixed even partially.
Get new scam files the moment we publish them — usually 2–3 emails a week.