Canonical Investigation

Beanstalk Farms Governance Exploit (2022)

EXPLOITED - NO RECOVERY|N/A/100
Ethereum·0xC1E088...5624C5dao
ConcludedScanned 17 April 2022
Run your own scan

See the evidence before you trust the verdict.

Concluded

Historical Investigation

This investigation covers the April 17, 2022 governance exploit. Beanstalk Farms relaunched after the exploit following a community governance vote; the relaunch and subsequent events are noted as outcome but are not assessed here. Evidence is frozen at the acute incident window and public post-mortems.

Executive summary

On April 17, 2022, an attacker used flash loans to acquire a supermajority of Beanstalk governance tokens, passed a malicious proposal, and drained approximately $182M from the protocol - all in a single atomic Ethereum transaction. No funds were recovered. The attacker was never identified. This investigation matters for four reasons. First, the failure class is governance, not code: every function executed correctly, every vote was counted honestly, the proposal passed legitimately by the protocol's own rules. The design assumption that failed was that governing supermajority was sufficiently difficult to acquire and that immediate execution was safe. Flash loans falsified both assumptions simultaneously. Second, the attack completes a conceptual pair with Mango Markets: Mango shows economic assumptions fail when the market executes as designed; Beanstalk shows governance assumptions fail when governance executes as designed. Neither is a software bug. Third, the specific control that was absent - an execution delay between proposal passage and execution - is a simple, well-known protection. Its absence here was not an oversight in a corner case; it was a gap in a nine-figure protocol that had been publicly audited. Fourth, the attribution outcome exercises Attribution Policy V1 in the opposite direction from Ronin and Mango: the attacker contract is on-chain, analyzed, and labeled, but no qualifying primary evidence establishes a real-world identity. Abundant on-chain evidence and UNATTRIBUTED are not contradictions under the policy. They are the correct state when identity evidence is missing regardless of technical evidence.

Evidence Confidence

Confidence per domain, not a single score.

Incident

Verified

Attribution

?Unresolved

Loss

High

Recovery

Verified
Timeline

How the incident unfolded

  1. April 17, 2022

    Single atomic transaction drains $182M

    The attacker executes one Ethereum transaction: flash borrows capital from multiple protocols, acquires a supermajority of Stalk governance tokens, votes for a pre-staged malicious governance proposal (including a $250k USDC Ukraine donation), executes the proposal, transfers approximately $182M in protocol assets to the attacker address, and repays the flash loans. The entire attack completes within one block.

    On-chain Ethereum record; attacker contract 0x79224bc0bf70ec34f0ef56ed8251619499a59def

  2. April 17, 2022

    Beanstalk paused; breach publicly disclosed

    Beanstalk is paused shortly after the exploit. The team publishes a post-mortem identifying the absent execution delay as the enabling condition. Multiple independent security firms publish analyses within hours, all reaching the same conclusion.

    Beanstalk team announcement; post-mortem publication

  3. April-August 2022

    Community governance vote on relaunch plan

    The Beanstalk community votes on a "Barn Raise" relaunch process: a fundraise to recapitalize the protocol, followed by a replant. The investigation is frozen here; the relaunch is noted as outcome, not assessed.

    Beanstalk governance forum; community announcement

Evidence Summary

What the evidence shows

Root cause

VERIFIED

No execution delay between governance vote and execution

Beanstalk's governance allowed proposals to be submitted, voted on, and executed within a single Ethereum block - the same transaction. This meant flash-borrowed capital was sufficient to achieve supermajority and execute an arbitrary proposal before the loan repayment, all atomically. The absent execution delay (timelock) is confirmed as the enabling condition by Beanstalk's post-mortem and multiple independent security analyses. Without it, any governance system where voting power can be temporarily borrowed is vulnerable to single-block supermajority attack.

Attack mechanism

VERIFIED

Flash loan supermajority + instant malicious BIP execution

The attacker deployed an exploit contract that in a single atomic transaction: (1) flash-borrowed large amounts of capital from multiple protocols; (2) used that capital to acquire enough Stalk (Beanstalk's governance token) to constitute a supermajority; (3) voted for a pre-staged malicious governance proposal that would transfer all protocol assets to the attacker; (4) executed the proposal in the same block; (5) drained the assets; (6) repaid the flash loans. The mechanism is publicly confirmed by on-chain analysis of the attacker contract.

Scale

PARTIAL

~$182M across protocol assets

Total corroborated across multiple independent post-mortems. The per-asset breakdown across Bean, LUSD, USDC, WETH and other protocol assets is pending independent reconstruction from Ethereum transaction records.

Attribution

UNATTRIBUTED

Pseudonymous; no qualifying identity evidence

The attacker contract (0x79224bc0bf70ec34f0ef56ed8251619499a59def) is on-chain, confirmed, and labeled in XemaS known addresses. No real-world identity has been established from any qualifying primary source under Attribution Policy V1. This is the correct attribution state regardless of the technical certainty: on-chain evidence does not constitute identity evidence. UNATTRIBUTED is not the same as unknown perpetrator - it means the evidence standard for attribution has not been met.

Recovery

VERIFIED

None - complete loss

No negotiation occurred. No operator backstop existed. No funds were returned. The attacker did send $250k USDC to the Ukraine Relief donation address on-chain - publicly documented and possibly the most unusual feature of the attack. That amount is negligible relative to the loss and does not change the recovery state for the protocol or its depositors.

Findings

What XemaS found

Beanstalk Farms was an algorithmic stablecoin protocol on Ethereum. Its native token, Bean, aimed to maintain a $1 peg through credit and soil mechanisms rather than collateral backing. Governance operated through Stalk tokens: holders of Bean who deposited ("sowed") into the protocol earned Stalk, which conferred voting rights on Beanstalk Improvement Proposals (BIPs). A proposal that achieved a two-thirds supermajority of Stalk could be enacted. Critically, no time elapsed between a proposal passing and its execution - the protocol had no execution delay, no timelock, no grace period. A proposal could be submitted, voted on, passed, and executed in a single Ethereum block.

The attacker recognized what this meant in the context of flash loans. Flash loans allow a borrower to use an arbitrary amount of capital within a single transaction, provided it is fully repaid by transaction end. If governance voting and execution could happen within a transaction, and if flash-borrowed capital could be used to acquire governance tokens and vote with them, then supermajority was not a meaningful barrier. The cost of acquiring a supermajority was merely the flash loan fee, not the actual capital.

On April 17, 2022, the attacker deployed an exploit contract and, in one atomic transaction, borrowed approximately $1B in capital via flash loans from Aave and other protocols. They used that capital to acquire enough Stalk to hold more than two-thirds of the total governance power. They voted for a pre-staged malicious BIP that transferred all Beanstalk's assets - Bean, LUSD, USDC, WETH and others - to the attacker address. The proposal passed with the attacker's own supermajority. The protocol executed the transfer. The attacker repaid the flash loans and exited with approximately $182M in net proceeds.

Included in the malicious proposal was a transfer of $250k USDC to a publicly known Ukraine Relief donation address. Whether this was a distraction, a statement, or a genuine donation is unknown - the attacker was never identified. It did not change the outcome for Beanstalk's depositors: the protocol lost essentially all its assets in one block.

There was no recovery mechanism to invoke. No operator held a backstop fund; the protocol was fully decentralized. No negotiation was possible - the attacker had no reason to engage. Beanstalk eventually relaunched after a community governance vote and a replanting process, but the depositors who held assets at the time of the exploit did not recover them.

Fund Flow

Where the value went

One transaction, one block: flash-borrowed capital in, supermajority vote, proposal executed, $182M out, flash loans repaid. The fund flow is the simplest in the corpus: a single atomic extraction with no laundering window, no negotiation, and no partial return. The attacker's proceeds left the protocol in the same transaction the flash loans were repaid in.

StepMovement
1Flash loans acquired from multiple protocols to fund Stalk acquisition
2Stalk acquired to reach governance supermajority (>2/3)
3Malicious BIP passed and executed: protocol assets transferred to attacker
4$250k USDC transferred to Ukraine Relief donation address (part of the malicious BIP)
5Flash loans repaid; transaction completes atomically
Affected Protocols

Downstream impact

Beanstalk Farms

The protocol lost essentially all its assets in one transaction. Bean stablecoin lost its peg. Depositors received no recovery. The protocol was paused and eventually relaunched after a community governance vote and a recapitalization process; the depositors at the time of the exploit did not recover their assets.

Bean (BEAN stablecoin)

The Bean peg collapsed immediately following the exploit, as the protocol's balance mechanisms depended on the assets that were drained. BEAN holders and farmers lost their positions.

Related Entities

Who was involved

Beanstalk Farms attacker (0x79224bc0bf70ec34f0ef56ed8251619499a59def)

UNATTRIBUTED

Deployed and executed the exploit contract. Pseudonymous; no real-world identity established. On-chain evidence is complete; attribution evidence is absent. The UNATTRIBUTED state under Attribution Policy V1 reflects this distinction: technical certainty and identity certainty are independent evidence claims.

Beanstalk Farms team / DAO

VERIFIED

Protocol developer and governance body. Published the post-mortem identifying the absent execution delay. Led the community governance vote on the Barn Raise relaunch plan. Had no operator-controlled backstop to deploy in response to the exploit.

Interpretation

Why it matters

A governance token that can be borrowed, used to vote, and returned in the same transaction is not governance protection - it is a temporary supermajority vending machine. Any protocol where borrowed capital can acquire voting power in the same block as proposal execution is vulnerable to this attack pattern regardless of the supermajority threshold required. The threshold only sets the size of the flash loan needed, not whether the attack is possible. For depositors: a protocol's decentralization does not eliminate custodial risk - it changes its character. When a centralized protocol is exploited, an operator can sometimes absorb the loss. When a fully decentralized protocol is exploited and there is no governance-controlled treasury outside the attack surface, depositors bear the full loss with no backstop.

Evidence

Evidence table

FactState
Root cause: no execution delay between governance vote and proposal executionVERIFIED
Attack executed in one atomic Ethereum transactionVERIFIED
Attacker contract: 0x79224bc0bf70ec34f0ef56ed8251619499a59defVERIFIED
Total assets drained approximately $182MPARTIAL
$250k USDC sent to Ukraine Relief donation address on-chainVERIFIED
No recovery: no negotiation, no operator backstop, no fund returnVERIFIED
Beanstalk Diamond Proxy: 0xC1E088fC1323b20BCBee9bd1B9fC9546db5624C5PARTIAL
Beanstalk had been publicly audited before the exploitVERIFIED
Honest Limits

What was not visible

Per-asset loss breakdown not independently reconstructed

The ~$182M total is corroborated across multiple post-mortems. The breakdown across Bean, LUSD, USDC, WETH and other protocol assets requires reconstruction from the Ethereum transaction record and is not yet independently verified. Per-asset split carries post-mortem provenance at this stage.

Flash loan source breakdown is PARTIAL

The attacker borrowed capital from multiple flash loan sources. The specific protocols used and amounts per source are documented in on-chain analyses but have not been independently reconstructed by XemaS. The on-chain record is authoritative; XemaS has not yet extracted and verified these values independently.

Beanstalk Diamond Proxy address is PARTIAL

The address 0xC1E088fC1323b20BCBee9bd1B9fC9546db5624C5 is widely referenced in post-mortems. XemaS has not independently verified it on-chain. Verification would confirm this is the protocol's main governance contract and the correct canonical subject for this incident record.

Attacker identity: genuinely unknown, not merely unconfirmed

Unlike Ronin (OFAC-designated) and Mango (public self-identification + conviction), no claim of responsibility or forensic attribution has been publicly established for Beanstalk. The UNATTRIBUTED state reflects the genuine absence of identity evidence, not a gap in investigation effort.

$250k Ukraine donation: motive unknown

The on-chain transfer to the Ukraine Relief address is VERIFIED as a fact. Whether it was a distraction intended to obscure the malicious proposal, a political statement, or a genuine donation from the attacker is not established. This investigation does not speculate on motive.

Lessons Learned

What this incident teaches

Any governance system where voting power can be flash-borrowed must have an execution delay

This is the singular lesson. Flash loans make temporary supermajority essentially free to any attacker with the capital to pay the fee. Without a delay between proposal passage and execution, the protocol cannot distinguish a legitimate supermajority from a flash-borrowed one. A 24-48 hour delay is sufficient; it makes the attack impossible by requiring the borrowed capital to be held for longer than a flash loan allows. This is not a novel insight - execution delays were already a recognized governance security pattern before Beanstalk. Their absence was a known risk class, not an unknown one.

Supermajority thresholds do not protect against flash loans - they only set the loan size

Raising the supermajority threshold from 67% to 75% or 90% changes the capital required for the flash loan, not whether the attack is possible. Flash loan capital is effectively unlimited within a transaction; any threshold is reachable. The threshold is not a meaningful defense. The defense is preventing execution during the window when the borrowed power is active - which requires time, not a higher number.

Audits are bounded by what they evaluate

Beanstalk had been audited before the exploit. The governance flash loan attack vector was not flagged. This is not evidence that audits are useless - it is evidence that audits check what they are asked to check. A security review of a governance system should specifically ask: can voting power be flash-borrowed? Can execution happen in the same block as the vote? These are governance mechanism questions, not smart contract correctness questions, and they require a different evaluation lens than code review.

Decentralization removes the operator backstop as well as operator risk

When a centralized protocol is exploited, the operator may have resources to absorb or partially cover the loss. Beanstalk had no operator with reserves; it was fully decentralized. When the assets were drained, there was no backstop to invoke, no insurance fund to activate, and no counterparty to negotiate with. Depositors in fully decentralized protocols carry the full tail risk directly. That is not an argument against decentralization - it is a risk characteristic that should be priced explicitly.

Related investigations

Structurally related incidents

Relationships derived from shared taxonomy - mechanism, failure pattern, protocol family, and attribution class.

Get started

Scan any address with the same evidence engine

EVM, Solana, Bitcoin, and Tron. Every scan returns verified evidence, not a traffic-light score.

Scan a token or wallet

No account required for a first scan.