UPDATE (Oct. 26, 17:29 UTC): Twelve hours later, here’s what is known about the exploit so far.
According to reports surfacing early Monday, upwards of $25 million in value has been drained from Harvest Finance pools and swapped for renBTC (rBTC) by an unknown attacker. Other funds have been mixed through Tornado Cash, an Ethereum obfuscation software. Following the attack, investors appear to have pulled roughly $350 million from the site.
“We are working actively on the issue of mitigating the economic attack on the Stablecoin and BTC pools, and will update in this thread in realtime (sic) as soon as additional details are available,” the anonymous team behind Harvest Finance said in a tweet.
The team further said the “economic attack” was made possible by manipulating stablecoin prices on Curve Finance, another DeFi protocol that Harvest Finance contracts interact with.
The project’s admins claim to have withdrawn “100% of stablecoin and BTC curve strategy funds” to the vault and “are moving to block deposits to the Stablecoin and BTC vault,” the Harvest Team said in the project’s Discord at 4:45 UTC.
Harvest Finance did not return questions by press time.
The attack comes after DeFi analyst Chris Blec claimed Harvest Finance’s administrators held an “admin key that can drain funds” locked in the protocol’s contracts. It’s unclear at this stage in the exploit what role the admin key or the anonymous team behind the protocol have to do with the sudden drain in assets. Blec did not return a request for comment by press time.
Harvest Finance had over $1 billion in total value locked (TVL) just prior to the possible exploit being unveiled. TVL has dropped to $673 million as of 5:00 UTC, according to DeFi Pulse.
This is a developing story and will be updated when more is known.
The leader in news and information on cryptocurrency, digital assets and the future of money, CoinDesk is a media outlet that strives for the highest journalistic standards and abides by a strict set of editorial policies. CoinDesk is an independent operating subsidiary of Digital Currency Group, which invests in cryptocurrencies and blockchain startups. As part of their compensation, certain CoinDesk employees, including editorial employees, may receive exposure to DCG equity in the form of stock appreciation rights, which vest over a multi-year period. CoinDesk journalists are not allowed to purchase stock outright in DCG.
Learn more about Consensus 2023, CoinDesk’s longest-running and most influential event that brings together all sides of crypto, blockchain and Web3. Head to consensus.coindesk.com to register and buy your pass now.