The Whistleblower Behind the yCredit Warning Speaks on Cronje's "Test in Prod" Habit
On January 1, 2021, Andre Cronje announced the launch of tokenized yield credit through yCredit. Because Cronje no longer uses Twitter, the announcement went out quietly, as a Medium post. That didn't stop his usual following of early depositors: roughly $45,000 flowed into the contracts almost immediately.
Shortly after, Nour Haridy posted a public warning on Twitter urging people to withdraw their funds from the contracts. The warning drew criticism from some corners, with accusations that Haridy was chasing attention rather than following responsible disclosure norms. rekt spoke with Haridy to get his account of what happened.

01The interview
Haridy said he had contacted Cronje directly before going public. According to Haridy, Cronje told him Yearn had no involvement with yCredit, and that the Yearn team itself knew nothing about the project either before or after its release.
Asked why a public statement felt necessary, Haridy said that without one, nothing would have happened — the contract had never been publicly announced in the first place, so there was no established channel through which a private fix could be pushed. He described his tweet as the most responsible option available given that the only alternative was silence. He noted that, as far as he understood, the contract was intended only for Cronje's personal use, meaning Cronje had no particular incentive to flag a bug in it to anyone else.
Haridy said he had told Cronje in advance that he planned to make the vulnerability public, and that Cronje said he was free to do so. He acknowledged he couldn't prove that exchange took place without sharing screenshots of their private conversation — something he said he wouldn't do without Cronje's consent.
Following the public warning, the flaw Haridy had identified was exploited — and so was a second, separate vector he had not disclosed. Haridy noted that hundreds of thousands of dollars were successfully withdrawn in the window after his warning went out. He said that, in hindsight, he would have also looped in the Yearn team directly; he claimed he had actually suggested doing so at the time but was told Yearn had no affiliation with the project. He maintained that his disclosure was responsible regardless, reiterating that the Yearn team was never involved with or aware of yCredit at any point.
Asked whether Cronje could have handled things differently, Haridy suggested a deposit cap would have limited the potential damage. Beyond that, he pointed out that Cronje had acknowledged the contract could be economically exploited, had not shared the contract address publicly, had not invited anyone to use it, and had not built a front-end UI for it. Haridy said his own preference would have been to share source code with other developers for review first, while allowing that this simply reflects differing approaches — Cronje's site, ycredit.finance, connects back to an earlier contract tied to a token called scUSD.
Haridy's tweet attracted significant attention, and some accused him of "clout chasing." He confirmed he saw the moment as a chance for self-promotion, saying he chose visibility over quietly exploiting the bug himself, which he framed as a reasonably good outcome for anyone who managed to withdraw in time. He said that had he used the exploit personally, blame would likely have fallen on the depositors rather than him — though he added he wouldn't have taken that route regardless. He mused that the one scenario where he might have used the exploit was if only Cronje's own funds had been at risk, purely so he could return them as a joke.
Asked whether he views Cronje's approach as effectively a cheap, decentralized substitute for formal audits — testing code live in production — Haridy agreed, saying he takes the same approach himself. He cited a prior instance involving Inverse Finance, where the situation was similar except that a deposit cap had been in place.
Closing the interview, Haridy argued that funds aren't meaningfully safer sitting in any other "audited" contract than they would have been in yCredit, pointing to Aave's near loss of roughly a billion dollars the previous month due to a flawed audited upgrade as evidence that audits offer limited real protection. In his view, the only genuine test of security is sustained on-chain exposure measured against what an attacker could actually profit from over time. He added that because Cronje never invited anyone to use the contract and was testing with his own money, no one who chose to participate anyway was entitled to a vulnerability response or formal disclosure.
02Editor's note
Despite having already gone public with his warning, Haridy initially declined to share exploit details with rekt's OPSEC team, saying he wanted to wait until the contract held zero funds. That delay slowed the investigation and meant no preventive step could be taken before the subsequent exploits occurred.
03Contract addresses
Stable AMM: 0x5cB5e2d7Ab9Fd32021dF8F1D3E5269bD437Ec3Bf
Exchange Router: 0xDD05437d7c7aF576b58262AE5ac6D37515168BE3
Swap Factory: 0x3A4FF19554b0F997A4cEF14A8860DcF813b738a4

Redeployed to: 0x71b6296174c5f07d37cafd6e9b72ab5bb3f14fac
A technical breakdown of the exploit is available in banteg's analysis.
04Community reaction
One anonymous commenter pushed back hard on Haridy's framing, arguing that a unilateral public alert amounted to inviting an attack while discrediting Cronje for the sake of attention — asking why Haridy hadn't simply reached out to the team privately if he had a way to do so, and suggesting the public post effectively signaled the vulnerability to every opportunistic actor still awake. The commenter said further attempts to press Haridy on why this wasn't handled privately were brushed off, leaving them to hope other members of the community would step in. They closed by saying that warnings had, in fact, been given and that no blame attached to Cronje, adding that the "test in prod" model might warrant firmer safeguards against people looking to exploit it, and that anyone who only ever interacted through Etherscan bears responsibility for their own actions and losses.
05Aftermath
The contract has since been redeployed. Whatever reputational and financial fallout resulted has largely been sorted out, and the episode stands as another example of Cronje's habit of shipping experimental code straight to a public audience willing to test it with real money.
Get new scam files the moment we publish them — usually 2–3 emails a week.