Migration Function Flaw at Team Finance Drains $15.8M From Four Token Pools
Team Finance, a service that brands itself as an "industry leader in project security and automation," lost $15.8 million worth of assets it had been entrusted to safeguard, after attackers found a hole in the anti-rug mechanism shared by four client projects.
Four liquidity pools were drained in total. FEG, Caw, and Kondux took the brunt of the impact. Tsuka was also affected, but its price held up somewhat better thanks to a secondary liquidity pool it maintained on Uniswap v3.

Team Finance's own marketing claims the platform secures more than $2.5 billion in assets — a figure that looks far less impressive once you consider how illiquid most of the tokens it protects actually are. The incident earned the protocol the #46 spot on the industry loss leaderboard.
Per Team Finance's own announcement, the attacker targeted "the audited v2 to v3 migration function." The flaw sat inside one of the "Liquidity Locks" contracts, which were built to let client projects migrate their locked LP positions from Uniswap v2 over to Uniswap v3.
Security firm Peckshield broke down the mechanics: the protocol's migrate() function could be tricked into transferring real Uniswap v2 liquidity into a new, attacker-controlled Uniswap v3 pair priced at a skewed rate. That mismatch generated a large "leftover" balance that was refunded to the attacker as pure profit. The firm also noted that the contract's supposed authorized-sender check could be sidestepped simply by locking any tokens at all.
The losses split out by each project's Uniswap v2 pool came to:
$11.5M CAW
$1.7M TSUKA
$0.7M KNDX
$1.9M FEG
Exploiter address 1: 0x161cebb807ac181d5303a4ccec2fc580cc5899fd
Exploiter address 2 (holding the stolen funds): 0xba399a2580785a2ded740f5e30ec89fb3e617e6e

Attack transaction: 0xb2e3ea72d353da43a2ac9a8f1670fd16463ab370e563b9b5b26119b2601277ce
Attacker's contract: 0xcff07c4e6aa9e2fec04daaf5f41d1b10f3adadf4
Notably, the vulnerable migrate() function had already passed through Zokyo Security's audit of the Team Finance contracts, conducted that same August, without the issue being flagged.
The reliance on third-party "DAO tooling" was one of the defining trends of the last market cycle. For small, pseudonymous teams building unproven protocols, outsourcing security and legitimacy to a service like Team Finance is an understandable shortcut. But given the roster of thinly-traded tokens the platform was "protecting," the arrangement looks less like genuine security infrastructure and more like a way for projects to borrow an appearance of trustworthiness. Whether Team Finance will step up and reimburse the affected projects, or leave each to fend for itself, is now the open question.
Get new scam files the moment we publish them — usually 2–3 emails a week.