UPDATE (Oct. 26, 17:29 UTC): Twelve hours later, here’s what is known about the exploit so far.
According to reports surfacing early Monday, upwards of $25 million in value has been drained from Harvest Finance pools and swapped for renBTC (rBTC) by an unknown attacker. Other funds have been mixed through Tornado Cash, an Ethereum obfuscation software. Following the attack, investors appear to have pulled roughly $350 million from the site.
“We are working actively on the issue of mitigating the economic attack on the Stablecoin and BTC pools, and will update in this thread in realtime (sic) as soon as additional details are available,” the anonymous team behind Harvest Finance said in a tweet.
The team further said the “economic attack” was made possible by manipulating stablecoin prices on Curve Finance, another DeFi protocol that Harvest Finance contracts interact with.
The project’s admins claim to have withdrawn “100% of stablecoin and BTC curve strategy funds” to the vault and “are moving to block deposits to the Stablecoin and BTC vault,” the Harvest Team said in the project’s Discord at 4:45 UTC.
Harvest Finance did not return questions by press time.
The attack comes after DeFi analyst Chris Blec claimed Harvest Finance’s administrators held an “admin key that can drain funds” locked in the protocol’s contracts. It’s unclear at this stage in the exploit what role the admin key or the anonymous team behind the protocol have to do with the sudden drain in assets. Blec did not return a request for comment by press time.
Harvest Finance had over $1 billion in total value locked (TVL) just prior to the possible exploit being unveiled. TVL has dropped to $673 million as of 5:00 UTC, according to DeFi Pulse.
This is a developing story and will be updated when more is known.