UPDATE (Oct. 26, 17:29 UTC): Twelve hours later, here’s what is known about the exploit so far.
According to reports surfacing early Monday, upwards of $25 million in value has been drained from Harvest Finance pools and swapped for renBTC (rBTC) by an unknown attacker. Other funds have been mixed through Tornado Cash, an Ethereum obfuscation software. Following the attack, investors appear to have pulled roughly $350 million from the site.
“We are working actively on the issue of mitigating the economic attack on the Stablecoin and BTC pools, and will update in this thread in realtime (sic) as soon as additional details are available,” the anonymous team behind Harvest Finance said in a tweet.
The team further said the “economic attack” was made possible by manipulating stablecoin prices on Curve Finance, another DeFi protocol that Harvest Finance contracts interact with.
The project’s admins claim to have withdrawn “100% of stablecoin and BTC curve strategy funds” to the vault and “are moving to block deposits to the Stablecoin and BTC vault,” the Harvest Team said in the project’s Discord at 4:45 UTC.
Harvest Finance did not return questions by press time.
The attack comes after DeFi analyst Chris Blec claimed Harvest Finance’s administrators held an “admin key that can drain funds” locked in the protocol’s contracts. It’s unclear at this stage in the exploit what role the admin key or the anonymous team behind the protocol have to do with the sudden drain in assets. Blec did not return a request for comment by press time.
Harvest Finance had over $1 billion in total value locked (TVL) just prior to the possible exploit being unveiled. TVL has dropped to $673 million as of 5:00 UTC, according to DeFi Pulse.
This is a developing story and will be updated when more is known.
The leader in news and information on cryptocurrency, digital assets and the future of money, CoinDesk is an award-winning media outlet that strives for the highest journalistic standards and abides by a strict set of editorial policies. In November 2023, CoinDesk was acquired by Bullish group, owner of Bullish, a regulated, institutional digital assets exchange. Bullish group is majority owned by Block.one; both groups have interests in a variety of blockchain and digital asset businesses and significant holdings of digital assets, including bitcoin. CoinDesk operates as an independent subsidiary, and an editorial committee, chaired by a former editor-in-chief of The Wall Street Journal, is being formed to support journalistic integrity.