Beanstalk Farms Governance Exploit (2022)
See the evidence before you trust the verdict.
Historical Investigation
This investigation covers the April 17, 2022 governance exploit. Beanstalk Farms relaunched after the exploit following a community governance vote; the relaunch and subsequent events are noted as outcome but are not assessed here. Evidence is frozen at the acute incident window and public post-mortems.
On April 17, 2022, an attacker used flash loans to acquire a supermajority of Beanstalk governance tokens, passed a malicious proposal, and drained approximately $182M from the protocol - all in a single atomic Ethereum transaction. No funds were recovered. The attacker was never identified. This investigation matters for four reasons. First, the failure class is governance, not code: every function executed correctly, every vote was counted honestly, the proposal passed legitimately by the protocol's own rules. The design assumption that failed was that governing supermajority was sufficiently difficult to acquire and that immediate execution was safe. Flash loans falsified both assumptions simultaneously. Second, the attack completes a conceptual pair with Mango Markets: Mango shows economic assumptions fail when the market executes as designed; Beanstalk shows governance assumptions fail when governance executes as designed. Neither is a software bug. Third, the specific control that was absent - an execution delay between proposal passage and execution - is a simple, well-known protection. Its absence here was not an oversight in a corner case; it was a gap in a nine-figure protocol that had been publicly audited. Fourth, the attribution outcome exercises Attribution Policy V1 in the opposite direction from Ronin and Mango: the attacker contract is on-chain, analyzed, and labeled, but no qualifying primary evidence establishes a real-world identity. Abundant on-chain evidence and UNATTRIBUTED are not contradictions under the policy. They are the correct state when identity evidence is missing regardless of technical evidence.
Confidence per domain, not a single score.
Incident
Attribution
Loss
Recovery
How the incident unfolded
April 17, 2022
Single atomic transaction drains $182M
The attacker executes one Ethereum transaction: flash borrows capital from multiple protocols, acquires a supermajority of Stalk governance tokens, votes for a pre-staged malicious governance proposal (including a $250k USDC Ukraine donation), executes the proposal, transfers approximately $182M in protocol assets to the attacker address, and repays the flash loans. The entire attack completes within one block.
On-chain Ethereum record; attacker contract 0x79224bc0bf70ec34f0ef56ed8251619499a59def
April 17, 2022
Beanstalk paused; breach publicly disclosed
Beanstalk is paused shortly after the exploit. The team publishes a post-mortem identifying the absent execution delay as the enabling condition. Multiple independent security firms publish analyses within hours, all reaching the same conclusion.
Beanstalk team announcement; post-mortem publication
April-August 2022
Community governance vote on relaunch plan
The Beanstalk community votes on a "Barn Raise" relaunch process: a fundraise to recapitalize the protocol, followed by a replant. The investigation is frozen here; the relaunch is noted as outcome, not assessed.
Beanstalk governance forum; community announcement
What the evidence shows
Root cause
No execution delay between governance vote and execution
Beanstalk's governance allowed proposals to be submitted, voted on, and executed within a single Ethereum block - the same transaction. This meant flash-borrowed capital was sufficient to achieve supermajority and execute an arbitrary proposal before the loan repayment, all atomically. The absent execution delay (timelock) is confirmed as the enabling condition by Beanstalk's post-mortem and multiple independent security analyses. Without it, any governance system where voting power can be temporarily borrowed is vulnerable to single-block supermajority attack.
Attack mechanism
Flash loan supermajority + instant malicious BIP execution
The attacker deployed an exploit contract that in a single atomic transaction: (1) flash-borrowed large amounts of capital from multiple protocols; (2) used that capital to acquire enough Stalk (Beanstalk's governance token) to constitute a supermajority; (3) voted for a pre-staged malicious governance proposal that would transfer all protocol assets to the attacker; (4) executed the proposal in the same block; (5) drained the assets; (6) repaid the flash loans. The mechanism is publicly confirmed by on-chain analysis of the attacker contract.
Scale
~$182M across protocol assets
Total corroborated across multiple independent post-mortems. The per-asset breakdown across Bean, LUSD, USDC, WETH and other protocol assets is pending independent reconstruction from Ethereum transaction records.
Attribution
Pseudonymous; no qualifying identity evidence
The attacker contract (0x79224bc0bf70ec34f0ef56ed8251619499a59def) is on-chain, confirmed, and labeled in XemaS known addresses. No real-world identity has been established from any qualifying primary source under Attribution Policy V1. This is the correct attribution state regardless of the technical certainty: on-chain evidence does not constitute identity evidence. UNATTRIBUTED is not the same as unknown perpetrator - it means the evidence standard for attribution has not been met.
Recovery
None - complete loss
No negotiation occurred. No operator backstop existed. No funds were returned. The attacker did send $250k USDC to the Ukraine Relief donation address on-chain - publicly documented and possibly the most unusual feature of the attack. That amount is negligible relative to the loss and does not change the recovery state for the protocol or its depositors.
What XemaS found
Beanstalk Farms was an algorithmic stablecoin protocol on Ethereum. Its native token, Bean, aimed to maintain a $1 peg through credit and soil mechanisms rather than collateral backing. Governance operated through Stalk tokens: holders of Bean who deposited ("sowed") into the protocol earned Stalk, which conferred voting rights on Beanstalk Improvement Proposals (BIPs). A proposal that achieved a two-thirds supermajority of Stalk could be enacted. Critically, no time elapsed between a proposal passing and its execution - the protocol had no execution delay, no timelock, no grace period. A proposal could be submitted, voted on, passed, and executed in a single Ethereum block.
The attacker recognized what this meant in the context of flash loans. Flash loans allow a borrower to use an arbitrary amount of capital within a single transaction, provided it is fully repaid by transaction end. If governance voting and execution could happen within a transaction, and if flash-borrowed capital could be used to acquire governance tokens and vote with them, then supermajority was not a meaningful barrier. The cost of acquiring a supermajority was merely the flash loan fee, not the actual capital.
On April 17, 2022, the attacker deployed an exploit contract and, in one atomic transaction, borrowed approximately $1B in capital via flash loans from Aave and other protocols. They used that capital to acquire enough Stalk to hold more than two-thirds of the total governance power. They voted for a pre-staged malicious BIP that transferred all Beanstalk's assets - Bean, LUSD, USDC, WETH and others - to the attacker address. The proposal passed with the attacker's own supermajority. The protocol executed the transfer. The attacker repaid the flash loans and exited with approximately $182M in net proceeds.
Included in the malicious proposal was a transfer of $250k USDC to a publicly known Ukraine Relief donation address. Whether this was a distraction, a statement, or a genuine donation is unknown - the attacker was never identified. It did not change the outcome for Beanstalk's depositors: the protocol lost essentially all its assets in one block.
There was no recovery mechanism to invoke. No operator held a backstop fund; the protocol was fully decentralized. No negotiation was possible - the attacker had no reason to engage. Beanstalk eventually relaunched after a community governance vote and a replanting process, but the depositors who held assets at the time of the exploit did not recover them.
Where the value went
One transaction, one block: flash-borrowed capital in, supermajority vote, proposal executed, $182M out, flash loans repaid. The fund flow is the simplest in the corpus: a single atomic extraction with no laundering window, no negotiation, and no partial return. The attacker's proceeds left the protocol in the same transaction the flash loans were repaid in.
| Step | Movement |
|---|---|
| 1 | Flash loans acquired from multiple protocols to fund Stalk acquisition |
| 2 | Stalk acquired to reach governance supermajority (>2/3) |
| 3 | Malicious BIP passed and executed: protocol assets transferred to attacker |
| 4 | $250k USDC transferred to Ukraine Relief donation address (part of the malicious BIP) |
| 5 | Flash loans repaid; transaction completes atomically |
Downstream impact
Beanstalk Farms
The protocol lost essentially all its assets in one transaction. Bean stablecoin lost its peg. Depositors received no recovery. The protocol was paused and eventually relaunched after a community governance vote and a recapitalization process; the depositors at the time of the exploit did not recover their assets.
Bean (BEAN stablecoin)
The Bean peg collapsed immediately following the exploit, as the protocol's balance mechanisms depended on the assets that were drained. BEAN holders and farmers lost their positions.
Who was involved
Beanstalk Farms attacker (0x79224bc0bf70ec34f0ef56ed8251619499a59def)
Deployed and executed the exploit contract. Pseudonymous; no real-world identity established. On-chain evidence is complete; attribution evidence is absent. The UNATTRIBUTED state under Attribution Policy V1 reflects this distinction: technical certainty and identity certainty are independent evidence claims.
Beanstalk Farms team / DAO
Protocol developer and governance body. Published the post-mortem identifying the absent execution delay. Led the community governance vote on the Barn Raise relaunch plan. Had no operator-controlled backstop to deploy in response to the exploit.
Why it matters
A governance token that can be borrowed, used to vote, and returned in the same transaction is not governance protection - it is a temporary supermajority vending machine. Any protocol where borrowed capital can acquire voting power in the same block as proposal execution is vulnerable to this attack pattern regardless of the supermajority threshold required. The threshold only sets the size of the flash loan needed, not whether the attack is possible. For depositors: a protocol's decentralization does not eliminate custodial risk - it changes its character. When a centralized protocol is exploited, an operator can sometimes absorb the loss. When a fully decentralized protocol is exploited and there is no governance-controlled treasury outside the attack surface, depositors bear the full loss with no backstop.
Evidence table
| Fact | State |
|---|---|
| Root cause: no execution delay between governance vote and proposal execution | VERIFIED |
| Attack executed in one atomic Ethereum transaction | VERIFIED |
| Attacker contract: 0x79224bc0bf70ec34f0ef56ed8251619499a59def | VERIFIED |
| Total assets drained approximately $182M | PARTIAL |
| $250k USDC sent to Ukraine Relief donation address on-chain | VERIFIED |
| No recovery: no negotiation, no operator backstop, no fund return | VERIFIED |
| Beanstalk Diamond Proxy: 0xC1E088fC1323b20BCBee9bd1B9fC9546db5624C5 | PARTIAL |
| Beanstalk had been publicly audited before the exploit | VERIFIED |
What was not visible
Per-asset loss breakdown not independently reconstructed
The ~$182M total is corroborated across multiple post-mortems. The breakdown across Bean, LUSD, USDC, WETH and other protocol assets requires reconstruction from the Ethereum transaction record and is not yet independently verified. Per-asset split carries post-mortem provenance at this stage.
Flash loan source breakdown is PARTIAL
The attacker borrowed capital from multiple flash loan sources. The specific protocols used and amounts per source are documented in on-chain analyses but have not been independently reconstructed by XemaS. The on-chain record is authoritative; XemaS has not yet extracted and verified these values independently.
Beanstalk Diamond Proxy address is PARTIAL
The address 0xC1E088fC1323b20BCBee9bd1B9fC9546db5624C5 is widely referenced in post-mortems. XemaS has not independently verified it on-chain. Verification would confirm this is the protocol's main governance contract and the correct canonical subject for this incident record.
Attacker identity: genuinely unknown, not merely unconfirmed
Unlike Ronin (OFAC-designated) and Mango (public self-identification + conviction), no claim of responsibility or forensic attribution has been publicly established for Beanstalk. The UNATTRIBUTED state reflects the genuine absence of identity evidence, not a gap in investigation effort.
$250k Ukraine donation: motive unknown
The on-chain transfer to the Ukraine Relief address is VERIFIED as a fact. Whether it was a distraction intended to obscure the malicious proposal, a political statement, or a genuine donation from the attacker is not established. This investigation does not speculate on motive.
What this incident teaches
Any governance system where voting power can be flash-borrowed must have an execution delay
This is the singular lesson. Flash loans make temporary supermajority essentially free to any attacker with the capital to pay the fee. Without a delay between proposal passage and execution, the protocol cannot distinguish a legitimate supermajority from a flash-borrowed one. A 24-48 hour delay is sufficient; it makes the attack impossible by requiring the borrowed capital to be held for longer than a flash loan allows. This is not a novel insight - execution delays were already a recognized governance security pattern before Beanstalk. Their absence was a known risk class, not an unknown one.
Supermajority thresholds do not protect against flash loans - they only set the loan size
Raising the supermajority threshold from 67% to 75% or 90% changes the capital required for the flash loan, not whether the attack is possible. Flash loan capital is effectively unlimited within a transaction; any threshold is reachable. The threshold is not a meaningful defense. The defense is preventing execution during the window when the borrowed power is active - which requires time, not a higher number.
Audits are bounded by what they evaluate
Beanstalk had been audited before the exploit. The governance flash loan attack vector was not flagged. This is not evidence that audits are useless - it is evidence that audits check what they are asked to check. A security review of a governance system should specifically ask: can voting power be flash-borrowed? Can execution happen in the same block as the vote? These are governance mechanism questions, not smart contract correctness questions, and they require a different evaluation lens than code review.
Decentralization removes the operator backstop as well as operator risk
When a centralized protocol is exploited, the operator may have resources to absorb or partially cover the loss. Beanstalk had no operator with reserves; it was fully decentralized. When the assets were drained, there was no backstop to invoke, no insurance fund to activate, and no counterparty to negotiate with. Depositors in fully decentralized protocols carry the full tail risk directly. That is not an argument against decentralization - it is a risk characteristic that should be priced explicitly.
Structurally related incidents
Relationships derived from shared taxonomy - mechanism, failure pattern, protocol family, and attribution class.
Scan any address with the same evidence engine
EVM, Solana, Bitcoin, and Tron. Every scan returns verified evidence, not a traffic-light score.
Scan a token or walletNo account required for a first scan.