Vault-Strategy Denomination Mismatch Drains $18M From BearnFi
Binance Smart Chain's habit of hosting forked, copy-pasted protocol code has repeatedly handed anonymous attackers an easy target, and BearnFi (bEarnFi) became the latest casualty, losing roughly $18 million. The details below draw on the technical write-ups published by Peckshield and by bEarn itself.
The vulnerability

At 10:36:20 AM UTC on May 16, 2021, BearnFi's BvaultsBank contract was exploited, with approximately $18 million drained from the pool. The underlying flaw was a mismatch in how a withdrawal amount got interpreted across two contracts: BvaultsBank's withdrawal logic treated a given number as BUSD, while the paired BvaultsStrategy contract treated the identical number as ibBUSD — an interest-bearing token worth more than plain BUSD. Because the same figure was read as two different, unequal assets depending on which contract processed it, the attacker could be credited with more value than they had actually put in.
How the exploit ran
The attacker opened with a flash loan of 7,804,239.111784605253208456 BUSD from CREAM, to be repaid with a fee at the end of the sequence. That BUSD was deposited into BvaultsBank, which passed it to BvaultsStrategy and onward into Alpaca Vault to earn yield; Alpaca minted 7,598,066.589501626344403426 ibBUSD back to BvaultsStrategy in exchange. The attacker then staked that ibBUSD through Alpaca's FairLaunch program.
Next came a withdrawal of 7,804,239.111784605253208533 BUSD from BvaultsBank — a call that BvaultsStrategy misread as a request to withdraw the same numeric amount of ibBUSD, worth a good deal more: 8,016,006.09792806917101481 BUSD. In the round that followed, the attacker deposited that same 7,804,239.111784605253208533 BUSD back into BvaultsBank. Because of the surplus carried over from the previous round, BvaultsStrategy again credited the attacker with 8,016,006.09792806917101481 BUSD, which went back into Alpaca for yield. Repeating this deposit-and-withdraw cycle let the attacker keep compounding the erroneous credit, before finally cashing out and draining the pool entirely. The original flash loan was then repaid with 7,806,580.383518140634784418 BUSD.
The stolen funds were first moved into this wallet.

Pattern and takeaway
This fits a pattern rekt.news had already noticed — exploits landing on weekends, whether because attackers bet on lighter scrutiny then or simply strike once their own workweek ends. The ongoing proliferation of forked BSC code keeps creating fresh openings for anyone looking to exploit a protocol, and the speed at which locked value both surges and collapses across BSC projects underscores a simple point: a track record of running unexploited over time may say more about a protocol's security than any single audit does.
Get new scam files the moment we publish them — usually 2–3 emails a week.