Homora V2 (Alpha Finance)
Rejected venues wait the longest for re-review; a rejection has to earn another look before the scheduled date.
REJECTED — THIS IS A DEAD PROTOCOL, NOT A CANDIDATE FOR ALLOCATION. Homora V2 is a leveraged yield-farming and lending protocol built by Alpha Finance Lab (now Alpha Venture DAO). DefiLlama’s own protocol record carries a `deadFrom` flag dated 2025-10-11, and its last-active chain shows on-chain TVL in the tens of thousands of dollars, not the roughly $110M figure this registry’s worklist initially carried, which reflects a stale or cached snapshot rather than current state. The live front end currently displays a banner stating ”Alpha Homora is currently experiencing issues.” Independent of its current operational status, the protocol suffered a confirmed $37.5M exploit in February 2021 via an accounting-rounding bug in an unreleased lending pool, an incident serious enough that the post-mortem strongly implied insider knowledge was required to execute it.
- DefiLlama’s dead-protocol flag is removed and current, meaningful on-chain TVL is confirmed
- The live application’s operational-issue banner is resolved and the underlying cause disclosed
- A public accounting of the February 2021 exploit’s attribution and any recovered funds is published
- A named multisig with disclosed signers and a timelock governs any surviving admin authority
The research file
Mechanism
Users deposit collateral, borrow additional capital from a shared lending pool, and use the borrowed funds to open leveraged liquidity-provider positions on integrated AMMs, amplifying both yield and liquidation risk. This shared-lending-pool design means borrower risk is pooled across all leveraged positions rather than isolated per strategy, a structurally riskier architecture than the per-vault isolation newer leveraged-LP protocols have generally moved toward since.
Confirmed dead status
DefiLlama’s own protocol record for Homora V2 carries a `deadFrom` field dated 2025-10-11 — an explicit, primary-source signal from this registry’s own trusted TVL data provider that the protocol is no longer considered active. Its last-tracked chain shows on-chain balances in the tens of thousands of dollars as of mid-2025, not a figure supporting any meaningful current allocation. The live application at this review displays a banner reading ”Alpha Homora is currently experiencing issues,” a further, current-dated signal of non-operational status rather than a historical one.
The February 2021 exploit
An attacker exploited a rounding flaw in HomoraBankV2’s unreleased sUSD lending pool: by becoming the sole borrower in an empty pool and repeatedly triggering a permissionless reserve-accrual function, the attacker inflated total debt without inflating debt shares, then borrowed massively against near-zero cost using flash loans to scale the drain across multiple assets. Total losses reached roughly $37.5M. Contemporaneous reporting notes the exploited pool had not yet been exposed in the user interface, meaning the attacker needed knowledge of its existence — Alpha Finance itself stated it had ”a prime suspect,” though no public attribution or prosecution outcome was confirmed in any source this review could access.
Legal structure and control
The operating entity is named as Alpha Finance Lab and affiliates in the product’s Terms of Use, governed by British Virgin Islands law with arbitration through the International Centre for Dispute Resolution seated in the BVI — standard offshore-labs structure with broad liability disclaimers, including a stated liability cap of $100. Governance runs through off-chain Snapshot voting under the project’s ENS-linked address. No specific multisig signer composition, timelock parameters, or documented emergency-pause capability were confirmed from any source this review could access.
Comparison and decision
Leveraged yield farming as a category has substantially consolidated since 2021-2022, with most surviving designs isolating risk per vault rather than pooling it across a shared lending bank the way Homora V2 does. Combined with DefiLlama’s own dead-protocol flag, a live ”experiencing issues” banner, and a serious historical exploit, Homora V2 reads as a first-generation, now-dormant product rather than a live candidate for any allocation this registry could recommend.
Sources
The claims above trace to these. Where a number could not be independently verified, the thesis says so.
- DefiLlama — Homora V2 protocol data · primary · accessed 2026-08-19
Supports: deadFrom 2025-10-11 flag, near-zero last-tracked TVL - Rekt News — Alpha Finance (Homora) exploit post-mortem · secondary · accessed 2026-08-19
Supports: February 2021 exploit mechanism, $37.5M loss figure, insider-knowledge implication - Alpha Homora V2 — application terms of use · primary · accessed 2026-08-19
Supports: Alpha Finance Lab BVI entity, current ”experiencing issues” banner - Alpha Venture DAO — official site · primary · accessed 2026-08-19
Supports: rebrand from Alpha Finance Lab, product suite context - OpenZeppelin — Alpha Homora V2 audit · primary · accessed 2026-08-19
Supports: pre-exploit audit scope and history
Inherited controls
The verdict above grades the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The least safe layer sets the position’s grade, and the position table names which one that is.
| Chain | Verdict | Grade | Control constraint |
|---|---|---|---|
| Ethereum | Approved | sovereign | No sequencer, no upgrade key, no operator who can be compelled — rule changes require social consensus. |
| BNB Smart Chain | Rejected | freezable | the validator set concentrates around one company, and the chain has been halted by decision. |
| Avalanche | Approved · limits | crypto-backed | no party can freeze or seize C-Chain funds, but one vendor writes the only production client and Messari measured over a third of stake hosted on AWS. |
| OP Mainnet | Rejected | hybrid | Ethereum forced inclusion limits sequencer censorship, but the Foundation and Security Council can co-sign an immediate upgrade before a client can exit. |