CryptoReal
CASE FILE — Oct 2, 2020

Under Pressure, Andre Cronje's Team Rushes Out an $8M Eminence Refund

Facing threats from members of the community, Andre Cronje and collaborators moved quickly to distribute the $8 million that had been mysteriously sent back after the EMN contract exploit drained $15 million on September 29.

The partial return raised more questions than it answered. Why hand back $8 million from what appeared to be a carefully engineered attack that likely took days to prepare? Why give up half the take only minutes after pulling it off? Some in the community speculated Yearn insiders might actually know who was behind it — and whether the attacker would rather keep $15 million while risking exposure, or walk away with $8 million and anonymity.

A breakdown of the three transactions that made up the exploit is available for review:

Transaction 1 — Sep-29-2020 01:20:41 AM UTC

Transaction 2 — Sep-29-2020 01:22:28 AM UTC

Transaction 3 — Sep-29-2020 01:23:28 AM UTC

Eight minutes after the third transaction, the refund went through:

Return Transaction — Sep-29-2020 01:31:04 AM UTC

Multiple theories circulated about who carried out the attack, with some questioning whether "hack" was even the right word given how unfinished the code appeared to be.

@mierzwik published an article examining the bot behind the attack (0x762bfbd), documenting that the same bot had already stolen 400 UNI a week before targeting EMN.

Separately, @frankresearcher dug into the wallets tied to the exploit, laying out a chain of related addresses in a thread and offering a theory on each one's role:

  • 0x223034e — the address believed to belong to the $ENM attacker
  • 0x762bfbd — the contract the attacker used to withdraw $UNI
  • 0x2d033fe — the address that deployed 0x762bfbd
  • 0x2f14f72 — the address that funded the deployer, likely under common ownership

This remains an active investigation.

To handle the refund, Yearn developer @bantg repurposed Uniswap's LP distribution code together with a merkle tree implementation, a fix he called an "elegant solution". Contributor Milkyklim built a comparable fix for yYFI holders who had claimed between blocks 10923319 and 10954777 and been shorted by a 5% fee bug.

Once refunds went live on youreminence.finance, claims were processed at a pace of $250,000 per minute, and half of the full $8 million had been claimed within 20 minutes. But not everyone paid close attention to the process — some users simply copied banteg's example screenshot instead of entering their own details, which meant they ended up sending their entire claim straight to banteg and the team as an unintended tip. Examples of these accidental full-amount "tips" include:

A 340 DAI tip

A 66.9 DAI tip

Sums referenced in this case file

A 993.3 DAI tip

A 263.1 DAI tip

A complete list of these tip transactions is available on Etherscan.

Some have asked why the claim interface allowed a full 100% tip option at all, rather than a lower cap such as 10–20%. Notably, data compiled by Alphaleakers on DAI claims and donations through youreminence.finance suggested that those who received the largest refunds tended to leave proportionally the smallest tips.

rektHQ operates as a community-driven outlet, and is grateful to the contributors who shared information and analysis around this event. Two anonymous community opinion pieces on the incident follow; rektHQ takes no responsibility for opinions expressed by these anonymous contributors, and its inbox remains open to anyone wishing to share further information.


ANON 1

The $8 million refund is troubling from two angles.

First is the matter of the threats reportedly made against Andre before he approached the Yearn treasury for help. Details of those threats haven't been made public, but proceeding with the refund regardless sets an uncomfortable precedent: it suggests that threatening a project's team can actually produce the desired result.

Second is the moral hazard problem that's already been debated extensively elsewhere. Economists use "moral hazard" to describe situations where the expectation of a bailout encourages riskier behavior — in DeFi terms, users piling into unaudited, high-risk protocols because they anticipate being made whole if things go wrong. That same dynamic exists in traditional finance, where large banks have historically counted on government intervention during a crisis. Whether DeFi should replicate that dynamic is a fair question.

Whoever exploited EMN executed something clever and well thought out, but arguably the more consequential move was returning half the funds — a decision that redirected community anger back toward the very project that got exploited rather than the exploiter. It wouldn't be surprising if this becomes something of a template: attackers tipping back a portion of what they take as an informal courtesy to future targets.

However this specific case plays out, it's worth thinking about what signal it sends to bad actors — and to the ethically ambivalent onlookers — who keep watching these situations resolve without real consequences.

ANON 2

From a technical standpoint, the project felt underbaked, partly because testing had apparently been done on testnet rather than against realistic mainnet conditions.

To be fair, forking mainnet locally to properly simulate Uniswap, Balancer, or bonding-curve behavior is still genuinely difficult, so "test as much as feasible" is understandable — but in practice, real testing often ends up happening in production.

That reasoning, though, also opens the door for careless developers and outright scammers, which is a real concern given how many "Uniswap"-style rug pulls have surfaced recently.

In some ways this both was and wasn't Andre's fault — the amount of hype around him made it entirely plausible that something like this could unfold, and there's only so much any single developer can account for while focused on a broader roadmap rather than every emerging DeFi-specific risk. The same issue likely would have surfaced regardless of who was behind the code.

Communication timing around the event was also messy — understandable given how many new developers have recently joined the $YFI community and how fragmented communication channels have become. Once Andre retweeted the promotional image, a conspiracy theory quickly formed around an intentional surprise. It's easy to fall into that same mindset, given how much crypto culture rewards puzzles and anonymity — even to its own detriment.

The refund itself signals that the project intends to continue in good faith, and that there's still a human element behind large, high-TVL degen bets. People take on risk constantly, regardless of asset class or platform, and it's hard to fault either the team for returning funds to those who got #halfrekt or the exploiter for returning half of what was taken in the first place.

I'm nowhere near Andre's level technically, and even had a passing suspicion something like a rug pull might be coming before going to sleep that night — but really, this whole situation came down to chance as much as anything else. Everyone involved probably just needs more sleep.


CronjeEminencedefi
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.