📈 Get daily crypto insights that make you smarter about your money

Texture Finance Attacker Returns 90% of $2.2M Loot After Solana Protocol Bounty Negotiation

In a rare instance of white-hat diplomacy succeeding in the decentralized finance space, the attacker behind the July 9 exploit of Solana-based lending protocol Texture Finance returned approximately 90% of the $2.2 million in stolen USDC on July 10, 2025. The repayment followed a public bounty offer from the Texture team, which convinced the exploiter to retain a percentage of the stolen funds as a bug bounty while returning the majority to affected users. The incident provides a fascinating case study in the emerging practice of on-chain negotiation and its implications for DeFi security.

How the Exploit Unfolded

Texture Finance, a lending platform built on Solana, suffered a smart contract vulnerability in its USDC vault on July 9, 2025. Security analysts from Nominis and Halborn identified the root cause as a missing ownership check in the vault contract, which allowed the attacker to manipulate vault withdrawals and drain approximately $2.2 million in user deposits. The exploit was specific to the USDC vault, leaving other vaults and the broader Texture protocol unaffected.

The vulnerability type, an access control flaw rather than a complex mathematical exploit like a flash loan attack or reentrancy, highlights a persistent challenge in DeFi security. Access control bugs are among the most straightforward vulnerabilities to identify during code audits, yet they continue to appear in production smart contracts. The Texture exploit underscores the importance of thorough peer review and professional auditing before deploying contracts that handle user funds.

The Negotiation Process

Within hours of the exploit, the Texture Finance team publicly communicated with the attacker through on-chain messages and social media channels, offering a bounty in exchange for returning the stolen funds. The negotiated settlement allowed the attacker to keep approximately 10% of the stolen amount, roughly $220,000, as a bug bounty while returning the remaining $1.98 million to the protocol.

This approach, while controversial, has become increasingly common in the DeFi space. Projects face a difficult calculus when negotiating with attackers. Pursuing legal action and law enforcement cooperation often takes months or years with low recovery rates, while direct negotiation can recover user funds within days. The Texture team chose the pragmatic path of maximizing user recovery over ideological purity.

Broader Security Implications

The Texture Finance exploit was one of multiple security incidents during July 2025, a month that saw approximately $139 million stolen across five major crypto hacks according to security researchers. The cumulative impact of these breaches contributed to the $2.17 billion in stolen funds recorded by mid-July 2025, essentially matching the entire 2024 total with half the year still remaining, according to Chainalysis data.

The access control vulnerability pattern in the Texture exploit mirrors weaknesses found in other July incidents. As DeFi protocols grow in complexity and manage increasingly large liquidity pools, the attack surface expands proportionally. The relatively simple nature of the Texture bug, compared to sophisticated attacks like the Bybit hack, demonstrates that even basic security oversights can result in significant losses when protocols manage millions in user deposits.

Lessons for the Ecosystem

The successful fund recovery in the Texture Finance case offers several actionable lessons for the DeFi ecosystem. First, rapid and transparent communication following an exploit creates opportunities for negotiation that might not exist if teams delay response. Second, the willingness to offer bounties, while contentious, provides economic incentives that can align attacker behavior with user interests. Third, the specific vulnerability type suggests that the industry needs to standardize more rigorous access control testing in smart contract development and auditing processes.

The incident also raises questions about the long-term sustainability of bounty-based fund recovery as a security model. While it worked for Texture, reliance on attacker cooperation introduces moral hazard by creating an expectation that exploits can be partially monetized without legal consequences. The DeFi ecosystem continues to debate whether this approach ultimately incentivizes or deters future attacks.

Disclaimer: This article is for informational purposes only and does not constitute financial or security advice.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

25 thoughts on “Texture Finance Attacker Returns 90% of $2.2M Loot After Solana Protocol Bounty Negotiation”

  1. whitehat_skeptic_

    missing ownership check in a vault contract. how does this still happen in 2025. basic access control should be day one audit material

    1. Devika M. any competent auditor would catch it but Solana programs are written in Anchor framework where ownership checks are easy to skip if you dont use the right macros

  2. 220K bounty for a missing ownership check that drained 2.2M. the math works out to a 10% fee for giving back what you stole. thats not justice thats a negotiation

    1. vault_recover_

      Hanno K. 220k for giving back what you stole is technically a negotiation but its also the only realistic outcome. protocols cant recover funds any other way

  3. attacker keeps 10% as bounty and everyone celebrates. $220K for finding a bug that any competent auditor would have caught

  4. 90% returned after negotiation. in 2022 that number would have been 0% and the exploiter would be on a beach somewhere

    1. safety_module

      the attacker keeping 10% as a bounty is becoming standard. its cheaper for the protocol than losing everything but its a terrible precedent long term

      1. bounty_maximalist

        10% bounty on 2.2M is 220k for a missing ownership check. being a whitehat pays better than most dev jobs at this point

        1. bounty_maximalist 220k for a missing ownership check. meanwhile full time security researchers at Halborn probably see half that per bug. the incentive structure is broken

          1. sol_seer_ Halborn audited the contract and missed the ownership check. the incentive structure is broken when the auditor gets paid regardless and the whitehat gets 220k for finding what they missed

          2. sol_vault_skeptic

            Nasrin H. halborn missing the ownership check is bad but the real problem is no multisig or timelock to slow down withdrawals

        2. bounty_maximalist 220k for a missing ownership check is absurd ROI. full time auditors at Halborn probably make less per bug found

  5. solana vaults getting drained because of basic access control flaws while the chain markets itself as high throughput. throughput means nothing without security

    1. Oluwaseun Adeyemi

      an access control bug in a vault handling millions. not a fancy exploit, just a missing ownership check. this keeps happening because audits skip the boring parts

      1. missing ownership check is the new flash loan. boring bug, devastating impact. audits keep skipping access controls because they are not flashy to look for

        1. Aisha B. access control bugs being the new flash loan is spot on. audits skip ownership checks because they are boring to look for but thats where the money lives

  6. the protocol got 90 percent back and still lost trust. TVL will crater anyway because who deposits into a vault with a documented ownership check gap

    1. 90% returned and the protocol is still toast. TVL exodus happens regardless of how much you recover because trust is the actual collateral in DeFi

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$63,998.00-1.8%ETH$1,876.15-2.5%SOL$75.99-1.2%BNB$599.61-0.9%XRP$1.02-2.2%ADA$0.1909-3.3%DOGE$0.0700+0.0%DOT$0.8106+1.1%AVAX$6.51-0.2%LINK$8.43+2.4%UNI$3.97-2.4%ATOM$1.40+1.6%LTC$45.20-1.0%ARB$0.0810+3.1%NEAR$1.61-0.5%FIL$0.7046-0.3%SUI$0.6883-0.9%BTC$63,998.00-1.8%ETH$1,876.15-2.5%SOL$75.99-1.2%BNB$599.61-0.9%XRP$1.02-2.2%ADA$0.1909-3.3%DOGE$0.0700+0.0%DOT$0.8106+1.1%AVAX$6.51-0.2%LINK$8.43+2.4%UNI$3.97-2.4%ATOM$1.40+1.6%LTC$45.20-1.0%ARB$0.0810+3.1%NEAR$1.61-0.5%FIL$0.7046-0.3%SUI$0.6883-0.9%
Scroll to Top