Guru.Fund dev publicly acknowledges exploit and appeals to attacker for asset return in exchange for bounty.
Security & Exploits ·
An individual identifying as Numa, a developer of Guru.Fund, posted an on-chain message acknowledging an exploit and appealing directly to the attacker. The message, sent from a wallet address, proposes a negotiation: the return of some or all stolen assets in exchange for a bounty payment. Numa stated the protocol lacks resources to refund affected users independently and requested the attacker reply on-chain with contact details encoded in transaction data.
The appeal frames the negotiation as a pragmatic effort to minimize harm to vault depositors. Numa emphasized willingness to discuss terms "quickly and in good faith," suggesting the developer views this as an alternative to a total loss scenario for users. The message treats the interaction as a professional exchange between developers rather than a criminal demand.
What remains unclear is whether the attacker responds to the offer, the scale of assets involved in the exploit, or details of how the vulnerability was exploited. No public statement from the attacker or independent confirmation of the breach mechanics has yet emerged.