How a Single Flash-Loaned Vote Emptied Beanstalk's Treasury
Beanstalk, the algorithmic stablecoin protocol, had $181 million pulled out of it in a governance exploit, though the attacker ended up keeping closer to $76 million once flash-loan repayments and swap losses are accounted for. Because rekt.news' leaderboard ranks incidents by total damage rather than net take, this one lands at #5.
The mechanism was a governance attack: the exploiter used a flash loan to temporarily amass enough voting power to force through a malicious proposal, then voted to hand the protocol's assets to themselves. Of the proceeds, about 24,800 ETH was funneled into Tornado Cash, and a separate $250,000 was sent to a Ukraine war-relief donation address. Credit for reconstructing the attack goes to Igor Igamberdiev, Peckshield, and Kelvin Fichter.

Setting up the vote
The exploit combined flash loans with a gap in how Beanstalk's governance handled urgent proposals. Ordinary proposals in the $BEAN contract carry roughly a one-day delay before they can take effect, but an "emergency commit" path let a proposal execute immediately the moment it secured enough votes. Per Kelvin Fichter's breakdown, the attacker laid the groundwork a full day ahead of time by submitting two proposals: #18, which would drain every asset from the contract, and #19, which would send $250,000 worth of BEAN to the Ukraine donation address. Oddly, that Ukraine-related proposal — despite actually being #19 — carried the label "BIP18" rather than "BIP19," muddying what observers could tell about which proposal did what.
Once the roughly one-day delay had passed, the attacker moved. Igor Igamberdiev's analysis traced the exploiter's initial funding back through the Synapse Protocol bridge, and further back to Tornado Cash. Using Aave, they flash-borrowed 350 million DAI, 500 million USDC, and 150 million USDT, adding a further 32 million BEAN borrowed from Uniswap v2 and 11.6 million LUSD from SushiSwap. Those funds were used to add liquidity to Curve pools paired with BEAN, generating enough voting weight to pass the disguised BIP-18, which routed all of the protocol's holdings to the attacker's contract. From there, the attacker unwound the Curve positions, repaid every flash loan, and converted what remained into roughly 24,800 WETH (about $76 million), which moved on to Tornado Cash.
On-chain identifiers
- Attacker's wallet: 0x1c5dcdd006ea78a7e4783f9e6021c32935a10fb4
- Attacker's contract: 0x79224bc0bf70ec34f0ef56ed8251619499a59def
- BIP18 init contract: 0xe5ecf73603d98a0128f05ed30506ac7a663dbb69
- Transaction proposing BIP18: 0x68cdec0ac76454c3b0f7af0b8a3895db00adf6daaf3b50a99716858c4fa54c6f
- Transaction executing the attack: 0xcd314668aaa9bbfebaf1a0bd2b6553d01dd58899c508d4729fa7311dc5d33ad7
Transaction-level breakdown (per Peckshield)
- Flash-borrowed 350,000,000 DAI, 500,000,000 USDC, 150,000,000 USDC, 32,425,202 BEAN, and 11,643,065 LUSD.
- Supplied 350,000,000 DAI, 500,000,000 USDC, and 150,000,000 USDT to the Vyper 3pool contract, receiving 979,691,328 3Crv.
- Exchanged 15,000,000 3Crv for 15,251,318 LUSD through the LUSD3CRV-f pool.
- Added 964,691,328 3Crv into the BEAN3CRV-f pool, receiving 795,425,740 BEAN3CRV-f.
- Added 32,100,950 BEAN and 26,894,383 LUSD to the BEANLUSD-f pool, receiving 58,924,887 BEANLUSD-f.
- Deposited the 795,425,740 BEAN3CRV-f and 58,924,887 BEANLUSD-f into the Diamond (Beanstalk's core) contract.
- Cast a governance vote on the Diamond contract for BIP-18.
- Called emergencyCommit on BIP-18, triggering the attacker's malicious _init contract and releasing 36,084,584 BEAN, 0.54 UNI-V2 WETH-BEAN LP tokens, 874,663,982 BEAN3CRV-f, and 60,562,844 BEANLUSD-f to the attacker's contract.
- Removed 874,663,982 BEAN3CRV-f in liquidity for 1,007,734,729 3Crv.
- Removed 60,562,844 BEANLUSD-f in liquidity for 28,149,504 LUSD.
- Flash-borrowed a second time: 11,795,706 LUSD and 32,197,543 BEAN.
- Exchanged 16,471,404 LUSD for 16,184,690 3Crv.
- Burned the 16,184,690 3Crv for 522,487,380 USDC, 365,758,059 DAI, and 156,732,232 USDT.
- Repaid a flash loan of 150,135,000 USDT, 500,450,000 USDC, and 350,315,000 DAI.
- Burned the 0.54 UNI-V2 WETH-BEAN position for 10,883 WETH and 32,511,085 BEAN.
- Donated 250,000 USDC to the Ukraine crypto-donation address.
- Swapped 15,443,059 DAI for 15,441,256 USDC.
- Swapped 37,228,637 USDC for 11,822 WETH.
- Swapped 6,597,232 USDT for 2,124 WETH.
- Sent the resulting 24,830 WETH profit to the attacker, and onward to Tornado Cash.

Aftermath
To get ahead of suspicion that the exploit had been an inside job, Publius — the pseudonymous team behind Beanstalk — chose to reveal themselves as a group of three developers in a statement posted to Discord.
Beanstalk's auditor, Omniscia, noted that this style of attack fell outside the scope of its original engagement, though its published report does contain commentary on the governance contract that was abused. Flash-loan-driven governance attacks are far from a new concept in DeFi — MakerDAO had warned about the same category of risk previously — which makes it notable that the vulnerability went unaddressed here. Adding an execution delay to on-chain governance proposals remains one of the simpler mitigations available. The incident may push token holders across DeFi to scrutinize governance proposals more closely, even though many assumed a project as widely discussed as Beanstalk — heavily promoted across crypto social media — would already be under close watch.
Get new scam files the moment we publish them — usually 2–3 emails a week.