Homora V2 (Alpha Finance)
This registry rejects Homora V2 because it is a dead protocol, not a candidate for allocation. Homora V2 is a leveraged yield-farming and lending protocol built by Alpha Finance Lab, now Alpha Venture DAO. DefiLlama’s own protocol record has a `deadFrom` flag dated 2025-10-11. Its last-active chain shows on-chain TVL in the tens of thousands of dollars, not the roughly $110M figure that this registry’s worklist first carried. That larger figure is a stale or cached snapshot, not the current state. The live front end now shows a banner stating ”Alpha Homora is currently experiencing issues.” Apart from its current operating status, the protocol suffered a confirmed $37.5M exploit in February 2021 through an accounting-rounding bug in an unreleased lending pool. The incident was serious enough that the post-mortem strongly implied the attacker needed insider knowledge to carry it out.
- DefiLlama’s dead-protocol flag is removed and current, meaningful on-chain TVL is confirmed
- The live application’s operational-issue banner is resolved and the underlying cause disclosed
- A public accounting of the February 2021 exploit’s attribution and any recovered funds is published
- A named multisig with disclosed signers and a timelock governs any surviving admin authority
Confirmed 2026-09-25: 37 days quiet, TVL $110M (-4% in 30 days), no open item. Holds to 2027-09-26 while the watch stays quiet.
The research file
Mechanism
Users deposit collateral, borrow more capital from a shared lending pool, and use the borrowed funds to open leveraged liquidity-provider positions on integrated AMMs. This increases both yield and liquidation risk. Because the protocol uses a shared lending pool, it pools borrower risk across all leveraged positions instead of isolating it by strategy. That design is structurally riskier than the per-vault isolation that newer leveraged-LP protocols have generally adopted since then.
Confirmed dead status
DefiLlama’s own protocol record for Homora V2 has a `deadFrom` field dated 2025-10-11. This is an explicit signal from the registry’s own trusted TVL data provider that it no longer considers the protocol active. Its last-tracked chain shows on-chain balances in the tens of thousands of dollars as of mid-2025, not enough to support any meaningful current allocation. At this review, the live application shows a banner reading ”Alpha Homora is currently experiencing issues.” That is another present-day sign that the protocol does not operate, rather than a sign limited to its history.
The February 2021 exploit
An attacker used a rounding flaw in HomoraBankV2’s unreleased sUSD lending pool. By becoming the only borrower in an empty pool and repeatedly calling a permissionless reserve-accrual function, the attacker raised total debt without raising debt shares. The attacker then used flash loans to scale the drain across several assets and borrowed heavily at near-zero cost. Total losses reached roughly $37.5M. Reports from the time note that the user interface had not yet exposed the pool, so the attacker needed to know it existed. Alpha Finance itself said it had ”a prime suspect,” though this review could not confirm any public attribution or prosecution outcome in the sources it could access.
Legal structure and control
The product’s Terms of Use name the operating entity as Alpha Finance Lab and affiliates. British Virgin Islands law governs, with arbitration through the International Centre for Dispute Resolution seated in the BVI. This is a standard offshore-labs structure with broad liability disclaimers, including a stated liability cap of $100. Governance uses off-chain Snapshot voting under the project’s ENS-linked address. This review could not confirm the specific multisig signer composition, timelock parameters, or a documented emergency-pause function from any source it could access.
Comparison and decision
Leveraged yield farming as a category has shrunk and grouped around fewer protocols since 2021-2022. Most surviving designs isolate risk by vault instead of pooling it across a shared lending bank as Homora V2 does. DefiLlama’s own dead-protocol flag, the live ”experiencing issues” banner, and the serious past exploit together show that Homora V2 is a first-generation product that now lies dormant, not a live candidate for any allocation this registry could recommend.
Sources
The claims above trace to these. Where a number could not be independently verified, the thesis says so.
- DefiLlama — Homora V2 protocol data · primary · accessed 2026-08-19
Supports: deadFrom 2025-10-11 flag, near-zero last-tracked TVL - Rekt News — Alpha Finance (Homora) exploit post-mortem · secondary · accessed 2026-08-19
Supports: February 2021 exploit mechanism, $37.5M loss figure, insider-knowledge implication - Alpha Homora V2 — application terms of use · primary · accessed 2026-08-19
Supports: Alpha Finance Lab BVI entity, current ”experiencing issues” banner - Alpha Venture DAO — official site · primary · accessed 2026-08-19
Supports: rebrand from Alpha Finance Lab, product suite context - OpenZeppelin — Alpha Homora V2 audit · primary · accessed 2026-08-19
Supports: pre-exploit audit scope and history
Inherited controls
The research above describes the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The layer with the most administrative power sets the position’s effective control; that describes control, not quality or suitability.
| Chain | Verdict | Control | Control constraint |
|---|---|---|---|
| Ethereum | Approved | No freeze key | No sequencer, no upgrade key, no operator who can be compelled. Rule changes require social consensus. |
| BNB Smart Chain | Rejected | Issuer can freeze | the validator set concentrates around one company, and the chain has been halted by decision. |
| Avalanche | Approved with limits | Governed, no freeze | no party can freeze or seize C-Chain funds, but one vendor writes the only production client and Messari measured over a third of stake hosted on AWS. |
| OP Mainnet | Rejected | Mixed control | Ethereum forced inclusion limits sequencer censorship, but the Foundation and Security Council can co-sign an immediate upgrade before a client can exit. |