NEWMethodology v3.3 is open for public comment.Read the draft →
About Press Ratings Partners Compare Watchlist Advertise
The Onyx desk · independent · unsponsored

Editorial.

Long-form investigations, methodology essays, and quarterly analysis from the people who run the ratings. Every piece is signed, every source is cited, no piece is sponsored.

Articles published
214
Investigations
41
Sources cited · 2026
1,408
Sponsored issues
0
All 214 Investigations 41 Methodology 28 Analysis 86 Quarterly reports 12 Op-ed 47
⌘ K · search articles Subscribe to the Brief
Investigation
0x4f2a… 0x9d2a… 0xb441… TORNADO $1.4M $2.1M $700k $4.2M 38 min
▼ 5,400 words · 24 sources · 6 cited interviews
Investigation · May 22, 2026 · GameFi

Inside the NovaPlay implosion: how three offshore wallets drained a Certified GameFi token in 42 minutes.

A forensic timeline of the exit, the on-chain breadcrumbs, the KYC records that didn't add up, and what the methodology will change as a result.

Investigations — what we found, and how.

All 41 →
Investigation · Apr 18
The HyperGain exit: anatomy of a $28.4M private-key compromise (or was it?).
38 minutes from upgrade-call to Tornado bridge. The on-chain forensics tell one story; the silence from the team tells another.
Riya Patel·14 min read·11 sources
Investigation · Mar 28
VaultAxis and the 9-minute oracle window: the $4.1M test of a "stale-aware" feed.
A reconstruction of the four-block window that exposed the gap between published oracle protections and deployed ones.
Marisol Chen·12 min read
Investigation · Feb 12
The Quanta Bridge audit, revisited: why two firms missed the same thing.
Looking at the two audit reports that preceded the $14M exploit, side-by-side, against the exploited code path.
Tomás Reyes·22 min read
Advertisement · paid placement · the desk does not see who buys this slot Why this ad? · Media kit →
Liquefy — liquid staking with per-validator transparency.
Stake ETH, receive lqETH, watch the withdrawal queue on-chain.
BannerSponsored Stake with Liquefy ↗

Recent

All Analysis Methodology Quarterly Op-ed DeFi GameFi AI Agents
Analysis · May 18
Restaking's audit problem: why we Verified, not Certified, EigenLayer.
Tomás Reyes·9 min
Methodology · May 14
Q2 methodology release: changes to AI Agent scoring after 18 months of evidence.
Editorial board·6 min
Op-ed · May 09
Why a ratings agency for Web3 cannot be a token economy.
Jakob Kowalski·11 min
Quarterly · Apr 30
Q1 2026 transparency report: 4 removed, 18 reviewed, 2 corrections issued.
Editorial board·14 min
Analysis · Apr 22
Telegram mini-apps, one quarter in: 214 rated, 18 to watchlist.
Amara Okonkwo · 8 min
Methodology · Apr 14
A defense of the +3 bonus rule, and where we've awarded it.
Daniel Bjornsen · 5 min
Analysis · Apr 02
The Base ecosystem in 2026: 214 projects, a methodology view.
Tomás Reyes · 16 min
Op-ed · Mar 24
The case against "vibes" — how I review a DeFi protocol.
Marisol Chen · 12 min

The desk · contributing editors

Full editorial board →
Marisol Chen
Lead reviewer · DeFi
Former senior counsel, SEC Office of the Chief Accountant. Writes long-form on DeFi credit, governance, and the methodology cases that surprised her.
48 articles12 investigations
Tomás Reyes
Lead reviewer · Infra & AI
Former Trail of Bits researcher. Specializes in restaking, agent provenance, and post-mortem reconstructions of audited-but-still-exploited contracts.
62 articles9 investigations
Riya Patel
Investigations · Editorial board
Former investigator, The Block. Six of her exploit reconstructions have been cited in court filings. Specialises in exit-scam forensics.
24 articles14 investigations
15 Screen — Article · long-form investigation onyx.dev/editorial/article/novaplay-implosion
Editorial / Investigations / NovaPlay implosion
Investigation · GameFi

Inside the NovaPlay implosion.

How three offshore wallets drained a Certified GameFi token in 42 minutes — and what our methodology will change as a result.

By Marisol Chen
Lead reviewer · DeFi · 8 yr SEC counsel
PublishedMay 22, 2026
·
18 min read
·
5,400 words
·
24 sources
WALLET A 0x4f2a… $1.4M USDT WALLET B 0x9d2a… $2.1M USDT WALLET C 0xb441… $700k USDT AGGREGATOR 0xc88d… $4.2M 42 MIN SINK TORNADO FIG. 01 · ON-CHAIN FLOW · APRIL 18, 2026 · BLOCKS 19,924,418 — 19,924,624
Fig. 01 · The complete on-chain flow · April 18, 2026, 22:14 – 22:56 UTC · 24 source citations

At 22:14 UTC on April 18, 2026, the NovaPlay master treasury contract on Polygon executed an upgrade transaction. Forty-two minutes later, every USDT NovaPlay had ever held — $4.2 million across three rate-limited withdrawal paths — was passing through a single Tornado Cash deposit.1 NovaPlay had been rated Listed by Onyx eight months earlier, with a score of 68. This piece is a forensic reconstruction of those 42 minutes, an examination of how the rating came to be wrong, and an explanation of what our methodology will change as a result.

The wallets that initiated the withdrawal — 0x4f2a…, 0x9d2a…, and 0xb441… — were not, on April 18, anonymous to NovaPlay's team. All three were listed in the published treasury registry. All three had legitimate operational reasons to hold balances. The exploit, if it can be called that, was not an exploit of the contract logic. The contract logic worked. The exploit was that the same person could move all three.

The 42 minutes

What follows is reconstructed from the on-chain transaction log, a partial set of internal Discord messages obtained from a former NovaPlay engineer2, and direct correspondence with two of the three named treasury signers — both of whom have stated unequivocally that they did not authorize the April 18 transactions and were not consulted on them.

Treasury upgrade — 22:14:08 UTC
NovaPlay master · 0xc88d…d901
UpgradeProposed · 22:14:08 UTC
Self-execute · same block
0xc88d…d901 → 0xc88d…d901
UpgradeExecuted · 22:14:08 UTC
Fig. 02 · Same block self-upgrade · UpgradeProposed + UpgradeExecutedBlock 19,924,418

The first thing to note about the timing: under NovaPlay's own published governance documentation, treasury upgrades were subject to a 72-hour timelock. The April 18 upgrade was both proposed and executed in the same block, twenty-six seconds after the proposal transaction was mined. This was technically possible because the timelock was implemented as a frontend check in the governance dashboard, not as a contract-level constraint. Anyone calling the contract directly could bypass it. This was disclosed nowhere.

The timelock was implemented as a frontend check, not a contract-level constraint. Anyone calling the contract directly could bypass it.

A reader familiar with our methodology will recognize this as a failure mode we score for — specifically, the Multi-sig & key management sub-criterion under Security (worth 4 of 25 points). NovaPlay had been awarded 3 of 4 points there. The 1 point we withheld reflected a noted concern about signer concentration. We did not catch that the published timelock was unenforced. That is on us.

The Halborn audit, revisited

NovaPlay's last audit, by Halborn in October 2025, covered the master treasury contract. The report — public, and good — flagged the timelock-as-frontend-check pattern as a "design observation, low severity." Halborn's recommendation was straightforward: enforce the timelock at the contract layer. NovaPlay marked the finding as "accepted, scheduled for v3.1." V3.1 was scheduled for Q2 2026. April 18 happened in Q2 2026, but before V3.1 shipped.

What does this teach us about the methodology? Two things. First: a "low severity" audit finding that affects governance enforceability should be treated as higher severity than the audit firm rated it.3 Audit firms are not in a position to assess organizational follow-through on findings; we are. Second: an accepted-but-unshipped finding should expire from credit if the proposed remediation date passes. We were giving NovaPlay credit for shipping a fix they had not shipped.

The project page, before and after

NovaPlay
GameFi · Polygon · removed for cause · May 19, 2026
68   Removed
Project page →

The rating was revoked on May 19 — five days before this piece was published, and one month after the events it documents. Removal, in the Onyx methodology, is the most severe action available; under Section 13 of the methodology document, it precludes re-rating under any version, including by a successor entity using shared infrastructure. The reason cited was team-identity falsification, not the exit itself.4 The exit, on its own, would have warranted downgrade and watchlist; the identity falsification is what made the rating itself a misleading signal.

What the methodology will change

The Q3 2026 methodology release will include three changes, drafted in response to this case and one other that will be published later this quarter:

One. All published timelocks must be contract-enforceable and tested under direct-call conditions to receive credit under Security/Multi-sig. Frontend-only timelocks will receive zero credit and a flag in the methodology report.

Two. Accepted audit findings with a project-stated remediation date that has passed will expire from credit on the date of the missed deadline, not on the date of next audit.

Three. Treasury signer identity verification will be lifted from a documentary check to a contemporaneous one: every quarter, we will independently re-contact the named treasury signers via an out-of-band channel and confirm continued affiliation with the project. The two signers who repudiated the NovaPlay transactions, when contacted, had not been employed by NovaPlay for over fourteen months. They had been listed in our public registry the entire time.

None of these changes recover the $4.2M. They are not meant to. They are meant to mean that the NovaPlay rating, which existed for eight months on this site with our name attached to it, is the last rating to be wrong in this particular way.

They are meant to mean that the NovaPlay rating is the last rating to be wrong in this particular way.

The harder question

There is a question this piece has not addressed and should: is independent ratings a sufficient defense against this category of failure, or do credibility platforms like ours create the false-confidence environment that makes failures like this possible? I have a view, and it is too long for this piece. We will publish it as a follow-up.5

What is settled is that NovaPlay was rated by Onyx for eight months, that the rating was wrong in ways the methodology did not catch, and that we are publishing this account so that the next person evaluating a similar project knows what to look for. That is the bargain. We will not always be right. We will always show our working.

Footnotes

  1. All transaction times and block numbers verified against Polygon mainnet at polygonscan.com. Cross-checked against independent indexer Allium and our own RPC node. Full block-by-block log appended to this piece as a CSV at onyx.dev/data/2026-04-18-novaplay.csv.
  2. Source verified as a former engineer at NovaPlay via three independent confirmations including LinkedIn employment history and Onyx prior-contact records. Discord messages reviewed in full; cited excerpts in context. Source granted anonymity due to ongoing employment in the GameFi sector.
  3. Halborn was contacted for response. Their position, which we record without endorsement, is that severity ratings are calibrated to the contract risk surface in isolation; the organizational follow-through dimension falls outside the audit scope. We agree with their characterization of audit scope and disagree that this absolves the rating decision from accounting for it.
  4. See our public Watchlist entry for the full removal decision and evidence trail: onyx.dev/watchlist.
  5. Forthcoming. Working title: "The case against ratings as a credibility substitute." Expected publication late June 2026.
Marisol Chen
Lead reviewer · DeFi · 8 years SEC counsel
Marisol leads DeFi review at Onyx. Before joining in 2024, she was senior counsel at the SEC Office of the Chief Accountant. She writes long-form on credit, governance, and the methodology cases that surprised her. She does not hold any tokens of projects under active Onyx review.

Discussion · 14 wallet-signed

vitalik.eth
Comment will be signed by your wallet
Wallet-signed · public · cannot be edited after posting
samczsun.eth ✓ Cited in piece
Good piece. One quibble — the timelock-as-frontend-check is more common than you imply. Anyone willing to publish a CSV of every "Listed" tier project would be doing the industry a favor. I'll start: I count at least 18 in my own bookmark folder.
May 22, 2026· 38 helpful
0x4F2a…91eC Interacted w/ NovaPlay
Lost about $400 to this. Reading the piece, it's clear the rating shouldn't have been issued in the form it was. But I also notice the rating page never said "timelock confirmed at contract layer" — and as a non-engineer I would have read that subtle distinction as something benign. Suggestion: add an explicit "verified at contract layer / not verified" column to all security sub-criteria, visible on the rating page.
May 22, 2026· 142 helpful
Subscribe

Long-form like this, every Sunday.

The Onyx Brief — investigations, methodology updates, every watchlist action. 14,820 subscribers. 0 sponsored issues.

Or subscribe with wallet · on-chain delivery available