Algo Stablecoin Protocol Beanstalk Cut Down by Governance Hijack

  • An attacker drained 24,830 ether and 36 million BEAN tokens worth about $180 million
  • The attacker exploited a loophole in the protocol’s governance process to push through a malicious “improvement proposal”

Beanstalk Farms, billed as “a decentralized credit based stablecoin protocol,” was exploited on Sunday for paper losses of about $180 million — the year’s latest DeFi hack.

That pegs it as the fifth-largest protocol exploit on the tracking site Rekt Leaderboard and the second largest this year after the massive Ronin Bridge hack in March. Security firm PeckShield first reported the news.

Like the Ronin exploit, most of the stolen funds consist of ether, which the attacker quickly began funneling into privacy protocol Tornado Cash in an effort to obscure the tokens’ origin.

The group confirmed the exploit on Twitter Sunday and is now considering a path forward.

Beanstalk had recently celebrated a milestone, reaching $100 million in BEAN tokens minted. One BEAN was meant to be equal to one US dollar, but unlike stablecoins backed by fiat or crypto collateral, Beanstalk used a novel system of financial incentives to maintain its peg using credit rather than overcollateralization, according to its whitepaper.

The protocol had undergone one audit from blockchain security expert Omniscia, but the firm indicated in a post-mortem analysis that the production code which suffered the exploit differed from what the firm had audited.

The developers disputed that account during a live town hall meeting Sunday.

“We’re not in the business of pointing fingers [but] we did take a look at the report they published and didn’t feel that it was a genuine account of what occurred,” the lead developer said.

Omniscia pointed to a “flash-loan susceptible governance flaw” as the culprit, allowing the attacker to propose and then force through a malicious governance proposal that effectively withdrew all the protocol’s assets to the attacker’s wallet.

The trick was to use a massive flash-loan — borrowing vast sums that must be repaid within the same transaction — and circumvent the usual life cycle of a governance proposal. In a bit of DeFi magic using $1.04 billion in borrowed stablecoins, the attacker briefly acquired a supermajority of the protocol’s voting power, which was directed to immediately execute malicious code.

“The Beanstalk Protocol supported protocol upgrades via its Beanstalk-Improvement-Proposal (BIP) governance mechanism and as such, it was possible for an upgrade to perform arbitrary code execution thus allowing the attacker to retrieve their locked funds as part of their malicious update,” Omniscia wrote.

A 24-hour waiting period was in effect, but the offending BIP was disguised as a bid to donate funds to support Ukraine and passed the delay period before a supermajority vote would be effective.

“We thought it was very strange, but we obviously were not aware of what was going on, what attack was in progress,” the developers explained during the town hall.

“We’re going to do everything we can to find out who did this and bring them to justice.”

Following the exploit, the protocol‘s BEAN tokens immediately dropped in value by 90% and effectively all its other assets, including those deployed by the attacker, were liquidated, resulting in a net profit of about $75 million in ether and other tokens.

According to PeckShield, the hacker sent $250,000 of USDC to an address in support of Ukraine.

Seeds of hope

Despite the catastrophe, the protocol’s developers have pledged to continue work on the project.

During the town hall and on the group’s Discord, the pseudonymous team took the extraordinary step of revealing their identities and explained their intention to cooperate with law enforcement in the hope of identifying the attacker and recovering funds.

This is not the first time flash-loans have been deployed in a DeFi exploit. Last year, Cream Finance was robbed of $130 million. That led its governance token CREAM to plummet by 70% — from which it has never recovered.

Unlike other high-value hacks, such as the Solana Wormhole bridge exploit, Beanstalk has no venture capital backing that could potentially provide a bailout to recapitalize the system.

The Beanstalk team did not immediately return a request for comment Monday.

Get the day’s top crypto news and insights delivered to your inbox every evening. Subscribe to Blockworks’ free newsletter now.

The post Algo Stablecoin Protocol Beanstalk Cut Down by Governance Hijack appeared first on Blockworks.

You may also like