# Goldfinch proposes a $250,000 reimbursement after a reported test-contract exploit

> The proposal introduced a concrete loss-allocation decision that would cover approximately 75% of the governance record's reported $330,000 USDC loss.

- URL: https://riadefi.com/on-chain/2025-12-14-goldfinch-hack-response-reimbursement-proposal/
- Type: Governance
- Stage: Proposed
- Evidence: mixed
- Materiality: material
- Event date: 2025-12-14
- Version: 1, published 2026-08-22 (first published 2026-08-22)
- Advisor-relevant: no
- Affects: Goldfinch (protocol)

Developing. Some claims here are not yet confirmed; they are listed apart from the confirmed facts. A new version replaces this one when the primary evidence changes.

## What happened

Goldfinch governance opened GIP-85, stating that attackers exploited a five-year-old test contract on 2025-12-02 and proposing to reimburse $250,000 from the remaining bug-bounty budget.

## What changed

The proposal introduced a concrete loss-allocation decision that would cover approximately 75% of the governance record's reported $330,000 USDC loss.

## What did not change

The candidate does not prove that the vote passed, reimbursement was paid, or the underlying exploit affected Goldfinch's active lending pools or client positions.

## Confirmed

- Goldfinch governance published GIP-85 on 2025-12-14.
- The proposal asks voters to authorize $250,000 from the remaining bug-bounty budget for reimbursement.
- The governance record attributes a $330,000 USDC loss to a 2025-12-02 exploit of an old test contract.
- The proposal characterizes the reimbursement as approximately 75% of reported damages.

## Still open

- The candidate does not include the exploited contract address, transactions, technical root cause, or independent loss reconciliation.
- The final vote result and any reimbursement transaction are not established.
- Whether the vulnerable test contract shared code, roles, or dependencies with active Goldfinch contracts is not established.
- The identities and eligibility of proposed reimbursement recipients are not stated.

## What it means for an advisor

- Add the reported exploit and proposed treasury loss allocation to Goldfinch's incident and governance history.
- Require contract-level confirmation before treating the reported amount or scope as fully reconciled.
- Review whether the incident changes conclusions about deprecated-contract management, bug-bounty reserves, or recovery governance.

## Sources

1. [GIP-85: Goldfinch Hack Response](https://snapshot.org/#/goldfinch.eth/proposal/0x3581a51f73aa4b2e691c2ac2cdf82520d8421429f23cc8366a923b85df8315b3) · Goldfinch governance · 2025-12-14


---

Published by Ketju Research on RIADeFi (https://riadefi.com). Educational research for financial professionals; not investment, legal, tax, or compliance advice.
