CryptoReal
CASE FILE — Oct 26, 2020

Flash Loans and Skewed Stablecoin Prices: How Harvest Finance Lost $34 Million

An attacker used a flash loan to extract $33.8 million from Harvest Finance's FARM_USDT and FARM_USDC pools, in one of the more mechanically intricate DeFi exploits of the "DeFi summer" era.

How the arbitrage played out

Over roughly two hours, fUSDT dropped 13.7% and the FARM token fell 67% as the attacker took out a $50 million USDT flash loan and routed it through Curve Finance's Y pool to distort stablecoin prices far beyond their normal range. A full transaction breakdown is available for those wanting the granular detail.

According to analysis credited to @valentinmihov, the entire sequence unfolded inside a single seven-minute window:

  1. Swap 11.4 million USDC to USDT, pushing the USDT price up.
  2. Deposit 60.6 million USDT into the Vault.
  3. Exchange 11.4 million USDT back to USDC, pushing the USDT price back down.
  4. Withdraw 61.1 million USDT from the Vault, netting roughly 0.5 million in profit.
  5. Repeat the cycle 32 times, apparently without any prior dry run.
  6. Convert the proceeds to renBTC and exit into BTC and ETH via Tornado Cash.

The extra profit at step 4 came from the manipulated USDT price: because USDT was artificially cheaper at the moment of withdrawal, the attacker's Vault shares converted into a larger amount of USDT than they had deposited.

Ethereum's 10-million gas limit constrained the operation to roughly four cycles per block, and while each individual cycle only generated under 1% profit, the roughly $500,000 gained per repetition compounded quickly across 32 iterations.

Root cause and how much worse it could have been

The underlying flaw sat in how the protocol calculated LP token prices for deposits and withdrawals. Because the flawed logic wasn't unique to the FARM_USDT and FARM_USDC pools, the same technique could theoretically have been extended to the renBTC pool, the FARM_TUSD pool, and the FARM_DAI pool. The attacker nonetheless stopped after draining $25 million — about 17% of the funds available across the FARM_USDT and FARM_USDC pools — despite having a path to drain the full $400 million sitting across all exposed pools.

Code in the FARM_USDT strategy appeared to calculate an internal price index; the presence of a "tokenIndex" parameter suggests the contract wasn't simply calling get_virtual_price() but performing its own underlying calculation (credit to Andre Cronje for this observation). Separately, PancakeBunnyFin noted that the arbitrage check function's tolerance was too loose — the default 3% slippage tolerance left far too much room for this kind of manipulation.

Funds returned, and a promised reimbursement

The attacker wasn't the only party to come away with a gain. Liquidity providers and the Harvest development team also received a modest payout: the attacker sent back $2,478,549.94 in USDT and USDC to the Harvest Deployer address. Harvest has since said this amount will be redistributed to affected users pro-rata, based on a snapshot.

Developer Julien Bouteloup (@bneiluj) summarized the mechanics in a tweet on October 26, 2020:

No hacker. Just a simple $24M (0x53f) juicy arb on @harvest_finance — $50M USDC flash loan on @UniswapProtocol, swap $11M (USDC/USDT) on @CurveFinance, ~61M on the fUSDT Vault, swap $11M USDT/USDC yUSDT, withdraw $61M with $0.5M profit. Repeat, then clean into @TornadoCash.

Where the money went

Rough figures for how the proceeds were distributed, credited to Jiecut42:

Sums referenced in this case file
  • Hacker: $24,000,000
  • Uniswap LPs: $6,000,000
  • Harvest Developers: $2,500,000
  • Curve LPs: $1,000,000
  • Ethereum Gas: $100,000
  • RenVM fees: $20,000

The chaos generated knock-on gains elsewhere too. Because Curve exposure runs across all of veCRV, holders staking CRV benefited from roughly $500,000 in additional trading fees the attacker generated by swapping over $100 million in USDT and USDC — pushing Curve's daily trading fees up more than 8,000% versus the prior day.

Uniswap liquidity providers saw a similar windfall. Total Uniswap trading volume spiked from $148 million to $1 billion within 24 hours, with 92% of that volume flowing through the USDT/ETH and USDC/ETH pairs alone — generating $5.76 million in fees for LPs (figures credited to Larry Cermak).

An anonymous tip received before the hack

Protecting sources is central to how Rekt operates, and while this story was being written, a contributor reached out with information about contact from the Harvest Finance team in the days leading up to the exploit. It's presented here without additional commentary:

I was contacted by the Harvest Finance team seeking collaboration on incentivising liquidity pools for two asset classes.

The first was trustless BTC, the second was FARM/ETH.

I didn't follow up with them as something was off-putting.

I'm not claiming that it is the Harvest team, but seeing the 3% slippage in the smart contract, and the fact that the exploit was in trustless BTC, which is a "novelty"...

I think that if this isn't Julien, then it has to be Harvest Finance themselves, or the EMN hacker, or someone with deep flashloan knowledge.

Can — or should — this be reversed?

The exploit reignited a familiar argument about whether protocols ought to be able to block or unwind this kind of activity. Some members of the Curve Telegram community argued Curve should intervene, but Curve itself pointed out that the deployed contracts cannot be paused or modified. Separately, some have called on renBTC to voluntarily return the fees it earned from the attacker's activity — a request that runs into the broader tension between decentralization and after-the-fact intervention.

Audits that didn't catch it

Just three weeks before the exploit, on October 6th, Harvest Finance had published a security update touting "rigorous security audits" performed by PeckShield, Haechi Labs, and CertiK. Notably, both PeckShield and CertiK had also audited bZx prior to that protocol's three separate hacks earlier in the same year. Comment from the auditing firms on this incident was still pending at time of writing.

More broadly, the episode underscored that neither developers nor specialized auditors were yet fully accounting for how flash loans could be weaponized against otherwise reasonable-looking contract logic.

Harvest Finance's own public response to the incident was notably terse, posted to Twitter shortly after the exploit was discovered.

What to call it

The episode also reopened debate over labeling: arbitrage, exploit, or hack? The line between the three keeps blurring, even as the "code is law" principle underneath DeFi becomes ever clearer. Harvest Finance itself described the episode as an "arbitrage economic attack." Some observers view the action as outright theft; others frame it simply as a more technically capable trader exploiting the system as designed — whether that amounts to meritocracy or something closer to anarcho-capitalism remains a matter of perspective.

As B.C. Forbes once put it: it is only the farmer who faithfully plants seeds in the spring who reaps a harvest in the autumn.

flash loanhackharvest finance
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.