The Poolin Postmortem: A $173M Lesson in Trust as a Vulnerability Vector

MaxWolf Projects

The numbers tell a story the whitepaper never could. $173 million in liabilities. $52 million in asset sale proceeds. A 30% recovery rate—for secured creditors. Unsecured creditors, holding IOU tokens representing $163.7 million in claims, will recover near zero. This is not a hack. This is not a rug pull. This is a business model failure, codified in bankruptcy court.

Poolin once commanded 14% of the Bitcoin network's hashrate. In 2019, it was a mining pool giant, processing blocks for thousands of miners across the globe. Its wallet service held user funds, promising convenience and quick payouts. Then came the Texas expansion—a bet on cheap power and scale. The bet failed. Expected 600MW of capacity turned into 100MW. The 2022 crypto winter liquidated leveraged positions. By mid-2023, withdrawals were frozen. Users received IOU tokens—pBTC, pETH—as promissory notes. By 2025, Poolin filed for Chapter 11 bankruptcy in New Jersey, and its remaining Texas mining assets (Pyote and Tarbush facilities) were sold via a stalking-horse bid for $52 million to Thor CALAP LLC, with 335 potential buyers contacted, including AI and HPC operators.

This is the skeleton. Now let me dissect the organs.

The IOU Token Illusion

IOU tokens are a form of debt tokenization. They represent a claim on the issuer, not on any underlying collateral. In Poolin's case, $163.7 million of these tokens were issued to 11,700 wallet users who had balances over $100. The total creditor count ranges from 10,001 to 25,000. These tokens were not meant to be traded. They were a stopgap—a way to avoid an immediate bank run. But in crypto, a token that represents a promise without code-enforced backing is a liability, not an asset.

From my years auditing smart contracts, I've seen this pattern before. When a protocol issues a token to mask insolvency, the token becomes a radioactive marker. It signals that the issuer has run out of real assets. The IOU token's value is entirely dependent on the bankruptcy recovery rate, which for unsecured creditors is typically below 10%. In Poolin's case, the $52 million asset sale covers only secured debt and some operational costs. Unsecured creditors will likely see pennies on the dollar.

"Trust is a vulnerability vector." Poolin users trusted the platform with their Bitcoin. That trust was exploited not by a malicious actor, but by management's own overconfidence. The code of the wallet was likely sound; the vulnerability was in the business logic.

The Leverage Trap

Poolin borrowed heavily from two sources: Antalpha (a Bitmain affiliate) and Tether. The Antalpha loan was $213 million, secured against Poolin's mining equipment and customer collateral. When the 2022 crash sent Bitcoin below $20,000, margin calls triggered. Poolin transferred customer collateral to Antalpha as debt repayment. This action effectively prioritized institutional debt over user funds. Tether, having lent against mining equipment, also liquidated its position. The company's debt-to-asset ratio became untenable.

This is not unique to Poolin. Core Scientific, Compute North, and others followed similar paths. But Poolin's case is instructive because it shows how quickly a mining pool can shift from a service provider to a leveraged speculative vehicle. The mining pool business is capital-intensive. The margins are thin. The temptation to use customer deposits as working capital is high. The result is a single point of failure: if the market turns, the pool becomes a black hole.

"Complexity is the enemy of security." Poolin's structure was simple on the surface—pool, wallet, mining farm—but the financial engineering was anything but. Loans, IOU tokens, cross-collateralization. Each layer added a variable that could go negative.

The Governance Vacuum

Poolin was a centralized entity. No DAO, no on-chain governance. The CEO and management made decisions—borrow, expand, freeze withdrawals—without consent from users. When the company entered Chapter 11, control passed to a court-appointed chief restructuring officer, Michael DuFrayne. The original team effectively vanished. This is the endpoint of all centralized crypto services that fail: the loss of user agency.

In my 2017 audit of the Zeek token contract, I saw how groupthink among male developers overlooked an integer overflow. Poolin's management similarly overlooked the obvious: leverage kills. They are not malevolent; they are simply fallible. But in a trust-minimized system, fallibility is catastrophic.

The Contrarian Angle: What the Bulls Got Right

It would be lazy to call this a complete disaster. Let me offer what my structural skepticism demands: the bulls have a point. Poolin's mining technology was never compromised. The PPS+ payout system functioned correctly. The failure was purely financial, not technical. This is a rare instance where the code was not the enemy. The adversary was the human layer—the assumptions embedded in the business plan.

Moreover, the asset sale for $52 million may actually be a bright spot. The stalking-horse bid from Thor CALAP LLC, which also explored AI/HPC use, suggests the Texas power assets have alternative value. The facility's power purchase agreements and infrastructure could be repurposed for AI compute, which is in high demand. This could set a floor for mining farm valuations, a contrarian bullish indicator for the mining sector.

"The code speaks louder than the whitepaper." In this case, the code (the mining pool software) spoke of reliability. The whitepaper (the business plan) spoke of growth. The market reality was a third, darker document: the bankruptcy filing. The industry often conflates technical soundness with business soundness. Poolin's technical team did their job. The business team did not.

Regulatory Implications: A Quiet Warning

The SEC's regulation-by-enforcement approach has not touched Poolin directly—the bankruptcy court handles the fallout. But the IOU token issuance is a textbook case of an unregistered security offer under the Howey test: money invested in a common enterprise with expectation of profits from others' efforts. The SEC could theoretically act, but bankrupt companies are judgment-proof. The lesson for regulators is clear: clarity on custodial wallet liabilities and IOU token classification is overdue.

Poolin's collapse also underscores the risks of cross-chain custody solutions. The IOU tokens were issued on Ethereum and other networks, but their backing was entirely in Bitcoin mining assets held by a Singapore entity with a US subsidiary. Legal recourse is fragmented. The user experience of redeeming an IOU token is orders of magnitude harder than withdrawing from a centralized exchange—a reminder that interoperability without legal hooks is just accounting fiction.

Takeaway: Audit First, Trust Never

Poolin is gone, but its legacy is a warning etched in bankruptcy filings. The next time a mining pool promises 'secure' custody with IOU tokens, remember: in crypto, trust is the most expensive currency. Audit the business logic as rigorously as the smart contract. Verify that the pool does not use customer deposits as collateral for its own leverage. Assume that any centralized service with a wallet is a potential single point of failure.

"Logic does not bleed, but it does break." In Poolin's case, it broke spectacularly. The unsecured creditors are the ones bleeding. For the rest of us, the blood is on the page—a case study in why, in this industry, financial conservatism is a feature, not a bug.

The stalking-horse has left the building. The auction results will determine the final recovery rate. But the real value of this event is not the cents on the dollar—it is the pattern recognition. Next time you see a mining pool with high hashrate and a wallet app, ask one question: who holds the keys? If the answer is not you, assume the worst.

I will continue to follow this case. The asset sale to an AI/HPC buyer may signal a trend. The IOU token holders may organize. But for now, Poolin's story is closed—a cold, hard lesson in the vulnerability of trust.