DeFi protocol Beanstalk loses $180M in exploit, hacker gains $80M

Share This Post

DeFi protocol Beanstalk Farms lost over $180 million to malicious players due to an exploit on April 17 that allowed a hacker to pass a governance proposal.

The Ethereum-based stablecoin protocol’s exploit left several tokens missing and saw its U.S. dollar-pegged stablecoin drop below the $1 mark.

Beans protocol exploited

Blockchain security company PeckShield first reported the hack on Twitter and said a hacker stole more than $80 million by exploiting Beanstalk Farms.

The hacker used flash loans to obtain a large amount of Beanstalk STALK tokens, which gave them enough voting power to pass a governance proposal that drained all the funds on the protocol into the hacker’s wallet.

The hacker then paid back the flash loans from Aave, Uniswap V2, and Sushiswap and converted the funds to Wrapped ETH. The stolen funds were then sent through the Tornado Cash mixer. The hacker also donated some of his stolen crypto to Ukraine.

 

Flash loan exploits are common

Beanstalk Farms’ exploit is not the first time attackers have exploited flash loans. According to the attack summary posted on the Beanstalk Discord server, the exploit happened because Beanstalk failed to:

“use a flash loan resistant measure to determine the % of Stalk that had voted in favor of the BIP.”

The blockchain Security firm responsible for auditing Beanstalk smart contracts, Omnicia, said Beanstalk launched the code with the flash loan vulnerability after its audit. It added in a postmortem analysis of the attack that it had not yet audited the exploited code.

Given the prevalence of flash loans exploits in the DeFi space, it’s surprising that Beanstalk introduced the code without proper auditing.

In addition, there are concerns about whether the protocol will reimburse users. Beanstalk Farms said it will provide more updates at its next town hall meeting.

The hack comes only a few weeks after a Ronin bridge exploit lost over $600 million on Axie Infinity in March.

Meanwhile, Tornado Cash’s use by hackers has given rise to criticism for its lack of effort in preventing fraud. The ETH mixer recently said it is using the Chainanalysis Oracle contract to block addresses sanctioned by the Office of Foreign Assets Control (OFAC) from using its services.

The post DeFi protocol Beanstalk loses $180M in exploit, hacker gains $80M appeared first on CryptoSlate.

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

Dogwifhat Price Prediction: After 39% Pump, Are WIF and STARS Next to Explode Like Dogecoin?

For meme coin investors, this week has been nothing short of euphoric Dogecoin has led the way by doubling in price, but smaller meme coins are taking over Dogwifhat has pumped 44% today – can

Pennsylvania introduces bill to use $7 billion state fund for Bitcoin Strategic Reserve purchases

Pennsylvania’s legislature has introduced landmark legislation for establishing a Bitcoin reserve, positioning the state at the forefront of digital asset policy in the United States The bill,

Dogecoin Eyes Parabolic Rally To Price Discovery, Is The 16,000% Surge From 2020 Possible This Time?

The Dogecoin price is again eyeing a parabolic rally that will put the meme coin in price discovery and send it to new highs in this market cycle Crypto analyst Mikybull Crypto indicated that the

Bitcoin Bull Tim Draper Eyes Trump’s Return as Catalyst for Private Sector Boom: ‘Very Excited’

This week, the bitcoin bull and venture capitalist Tim Draper shared his excitement on X about Donald Trump’s potential next term “Every job they cut in the government will create three

ICP identity protocol DecideID to launch on Solana eliminating any KYC need for DeFi

DecideAI has announced the integration of its biometric identity verification solution, DecideID, into the Solana blockchain, aiming to enhance security and trust within the ecosystem This move

‘PEPE Breakout Starts Now’ Says Analyst As Market Cap Shoots $10B Amidst Listing News

The post ‘PEPE Breakout Starts Now’ Says Analyst As Market Cap Shoots $10B Amidst Listing News appeared first on Coinpedia Fintech News Pepe’s market capitalization has briefly topped $102