{"investigation":{"slug":"beanstalk","entity_name":"Beanstalk","trust_score":12,"severity_base":null,"score_modifier":0,"confidence":1,"status":"published","content_type":"investigation","summary":"Beanstalk is an Ethereum-based algorithmic stablecoin protocol that on April 17, 2022 suffered one of DeFi's largest governance exploits, losing approximately $182 million after an attacker used flash loans to acquire a supermajority vote and pass a malicious proposal draining the protocol's treasury. The protocol relaunched in August 2022 following a community fundraiser called the Barn Raise, but its BEAN stablecoin has never recovered its peg and total value locked remains a fraction of pre-exploit levels.","sections":[{"content":"Beanstalk is a decentralized, credit-based algorithmic stablecoin protocol deployed on Ethereum. It was designed to maintain a soft peg to the US dollar through a credit mechanism rather than collateral, issuing its native token BEAN. The protocol was founded by three University of Chicago graduates — Benjamin Weintraub, Brendan Sanderson, and Michael Montoya — who operated pseudonymously under the collective alias 'Publius,' a reference to the pseudonymous authors of the Federalist Papers. At its peak before the April 2022 exploit, the protocol held approximately $150–182 million in assets across its liquidity pools. Governance was conducted through a system of on-chain proposals known as Beanstalk Improvement Proposals (BIPs), with voting power derived from deposited Stalk tokens. The protocol's smart contracts were audited by Omniscia; however, the governance functionality that was ultimately exploited was introduced after the original audit was completed and was not itself audited.","heading":"Background","sources":[{"url":"https://www.coindesk.com/tech/2022/04/17/attacker-drains-182m-from-beanstalk-stablecoin-protocol","name":"","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/once-hacked-for-77m-beanstalk-s-algo-stablecoin-protocol-relaunches","name":"","type":"other","credibility":3},{"url":"https://bean.money/beanstalk.pdf","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"On April 17, 2022 at approximately 12:24 PM UTC, an attacker executed a flash loan governance attack against Beanstalk, resulting in a total protocol loss of approximately $182 million, with the attacker retaining approximately $76–80 million in profit after repaying the loans. The attack exploited Beanstalk's governance design, which allowed voting power to be derived directly from deposited assets with no mechanism preventing flash loan-based voting manipulation.\n\nThe attacker had submitted two malicious Beanstalk Improvement Proposals — BIP-18 and BIP-19 — approximately 24 hours before execution, satisfying the protocol's standard governance delay. BIP-18 contained code to transfer all protocol assets to the attacker's address. BIP-19 proposed donating $250,000 worth of BEAN tokens to the official Ukraine war fund, a measure believed to lend BIP-18 an air of legitimacy.\n\nTo acquire sufficient voting power, the attacker took out flash loans totaling over $1 billion from the Aave lending protocol, denominated in approximately 350 million DAI, 500 million USDC, and 150 million USDT, along with 32.4 million BEAN and 11.6 million LUSD sourced from Uniswap v2, SushiSwap, and Curve pools. These funds were deposited into the Beanstalk Diamond contract, granting the attacker approximately 67–79% of the protocol's governance votes — exceeding the two-thirds supermajority required. The attacker then invoked the emergencyCommit function to execute BIP-18 immediately, bypassing the remaining time lock. Protocol assets were drained to the attacker's wallet, the flash loans were repaid in the same transaction block, and the attacker netted approximately 24,930 ETH (roughly $76 million at the time). BEAN collapsed from approximately $1.00 to $0.11 within hours of the exploit.","heading":"The Governance Attack","sources":[{"url":"https://rekt.news/beanstalk-rekt","name":"","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-beanstalk-hack-april-2022","name":"","type":"other","credibility":3},{"url":"https://www.bleepingcomputer.com/news/security/beanstalk-defi-platform-loses-182-million-in-flash-loan-attack/","name":"","type":"other","credibility":3},{"url":"https://medium.com/immunefi/hack-analysis-beanstalk-governance-attack-april-2022-f42788fc821e","name":"","type":"other","credibility":3},{"url":"https://www.bloomberg.com/news/articles/2022-04-18/defi-project-beanstalk-loses-182-million-in-flash-loan-attack","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"The exploit is fully documented on-chain. The primary attack transaction hash is 0xcd314668aaa9bbfebaf1a0bd2b6553d01dd58899c508d4729fa7311dc5d33ad7 on the Ethereum mainnet. The attacker's wallet address is 0x1c5dCdd006EA78a7E4783f9e6021C32935a10fb4.\n\nFollowing the exploit, the attacker transferred approximately 24,930 ETH to Tornado Cash in a series of 270 transactions, most of approximately equal size, executed in rapid succession on April 17, 2022. Tornado Cash is a privacy mixing protocol that obfuscates on-chain fund provenance. No meaningful portion of the stolen funds has been recovered.\n\nBeanstalk Farms sent an on-chain message to the attacker's address offering a whitehat bounty — the right to keep 10% of the stolen funds as a bug bounty if 90% was returned. The attacker did not respond. The remaining BEAN tokens in the exploiter's contract were subsequently burned by the Beanstalk Farms team.\n\nOn-chain analytics confirm that the flash loans were sourced from Aave v2 and routed through Curve, Uniswap v2, and SushiSwap liquidity pools to accumulate the depositable assets necessary to achieve supermajority governance control within a single transaction block.","heading":"On-Chain Evidence","sources":[{"url":"https://rekt.news/beanstalk-rekt","name":"","type":"other","credibility":3},{"url":"https://blog.merklescience.com/hacktrack/hack-track-analysis-of-beanstalk-flash-loan-attack-hack-track-merkle-science","name":"","type":"other","credibility":3},{"url":"https://www.certik.com/resources/blog/revisiting-beanstalk-farms-exploit","name":"","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/beanstalk-farms-offers-plea-deal-to-perpetrators-of-76m-exploit","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"On April 18, 2022, the Beanstalk Farms founders revealed their identities during a Discord town hall, breaking from their 'Publius' pseudonym. Benjamin Weintraub, Brendan Sanderson, and Michael Montoya stated the disclosure was intended to dispel any suspicion that the team was complicit in the attack. The three had previously co-founded the protocol while attending the University of Chicago.\n\nFollowing the exploit, Beanstalk paused the protocol and disabled on-chain governance. Governance was transferred to a community-operated multisig wallet to prevent further flash loan manipulation while a secure on-chain governance mechanism was designed. The team published a recovery roadmap it called 'the Path Forward.'\n\nIn June 2022, Beanstalk Farms launched the 'Barn Raise,' a community recapitalization fundraiser aimed at restoring the approximately $77 million in non-BEAN liquidity stolen from the Silo. The Barn Raise issued Fertilizer tokens to contributors as a debt instrument redeemable against future protocol revenue. By August 4, 2022, when BIP-21 (the Replant proposal) reached supermajority, the Barn Raise had attracted over $17 million USDC in credit via Fertilizer purchases — a small fraction of the total losses.\n\nBeanstalk officially relaunched (called the 'Replant') in August 2022. As of 2024, the protocol has undergone multiple additional security audits through Cyfrin, including audits of 'Beanstalk 2' (April 2024) and 'Beanstalk 3' (May 2024), which included plans for an L2 migration. However, the BEAN stablecoin has not recovered its $1 peg; as of 2025, BEAN trades at approximately $0.23 — roughly 77% below peg. Total value locked in the protocol is approximately $9 million, compared to over $100 million before the exploit.","heading":"Team & Recovery","sources":[{"url":"https://cointelegraph.com/news/once-hacked-for-77m-beanstalk-s-algo-stablecoin-protocol-relaunches","name":"","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2022/06/02/beanstalk-stablecoin-protocol-barn-raise-aims-to-restore-77m-in-lost-funds","name":"","type":"other","credibility":3},{"url":"https://bean.money/blog/path-forward","name":"","type":"other","credibility":3},{"url":"https://www.techtarget.com/searchsecurity/news/252516215/Cryptocurrency-theft-leaves-Beanstalk-Farms-future-in-doubt","name":"","type":"other","credibility":3},{"url":"https://defillama.com/protocol/beanstalk","name":"","type":"other","credibility":3},{"url":"https://github.com/Cyfrin/2024-04-beanstalk-2","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"As of the time of this investigation, no public record exists of formal regulatory action by the U.S. Securities and Exchange Commission (SEC), the Commodity Futures Trading Commission (CFTC), the U.S. Department of Justice (DOJ), or any equivalent body against Beanstalk Farms, its founders, or the attacker in connection with the April 2022 exploit.\n\nThe attacker's use of Tornado Cash to launder the stolen proceeds is relevant in the context of subsequent regulatory actions: in August 2022, the U.S. Treasury's Office of Foreign Assets Control (OFAC) sanctioned Tornado Cash smart contract addresses, making interaction with the mixer a potential violation of U.S. sanctions law for U.S. persons. The attacker's transfers to Tornado Cash predate those sanctions. No indictment or civil complaint identifying the attacker has been made public.\n\nBeanstalk's BEAN token and its Stalk/Seed governance tokens could potentially be subject to securities regulatory scrutiny under the Howey test framework, though no formal proceeding has been initiated. The protocol operates without KYC or AML controls, consistent with most permissionless DeFi protocols.","heading":"Regulatory Status","sources":[{"url":"https://www.bankinfosecurity.com/stablecoin-protocol-beanstalk-loses-millions-in-attack-a-18918","name":"","type":"other","credibility":3},{"url":"https://www.bleepingcomputer.com/news/security/beanstalk-defi-platform-loses-182-million-in-flash-loan-attack/","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Beanstalk presents multiple severe and ongoing risk factors for users and depositors.\n\nFirst, the protocol suffered a documented $182 million loss in a single transaction — one of the largest DeFi exploits in history. The root vulnerability (flash loan-manipulable governance with no snapshot delay) was introduced into production code without an audit, indicating a prior failure of security process.\n\nSecond, the BEAN stablecoin has functionally failed as a dollar peg instrument. Trading at approximately $0.23 as of 2025, it has not held its peg in the more than three years since the exploit. Users treating BEAN as a stablecoin equivalent face significant mark-to-market losses.\n\nThird, the Barn Raise recapitalized only a small fraction (roughly $17 million of $77 million) of the lost liquidity, meaning the protocol relaunched in a structurally undercapitalized state. Holders of Fertilizer (the Barn Raise debt instrument) bear the risk that protocol revenue will be insufficient to redeem their positions.\n\nFourth, development activity as of 2025 is minimal (approximately one commit per month), suggesting limited active maintenance and community engagement.\n\nFifth, the protocol's algorithmic stablecoin design — credit-based, no collateral — is considered a high-risk model category following the collapse of TerraUSD/LUNA in May 2022 and Beanstalk's own exploit. Algorithmic stablecoins that have lost their pegs rarely recover them in practice.\n\nThe attacker's identity remains unknown. All stolen funds were laundered through Tornado Cash and are considered unrecoverable.","heading":"Risk Assessment","sources":[{"url":"https://rekt.news/beanstalk-rekt","name":"","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-beanstalk-hack-april-2022","name":"","type":"other","credibility":3},{"url":"https://defillama.com/protocol/beanstalk","name":"","type":"other","credibility":3},{"url":"https://www.coingecko.com/en/coins/bean","name":"","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2021-08-06","event":"Beanstalk protocol launched on Ethereum mainnet by pseudonymous founders 'Publius' (Benjamin Weintraub, Brendan Sanderson, Michael Montoya).","source":""},{"date":"2022-04-16","event":"Attacker submits malicious BIP-18 and BIP-19 governance proposals to Beanstalk, initiating the required 24-hour governance delay.","source":""},{"date":"2022-04-17","event":"At approximately 12:24 PM UTC, attacker executes flash loan attack using over $1 billion borrowed from Aave, acquires ~79% of governance votes, passes BIP-18 via emergencyCommit, and drains approximately $182 million from the protocol. Approximately 24,930 ETH ($76M net profit) is transferred to Tornado Cash in 270 transactions.","source":""},{"date":"2022-04-18","event":"Beanstalk Farms team pauses the protocol, disables on-chain governance, and transfers control to a community multisig. Founders reveal their identities on Discord to dispel complicity concerns.","source":""},{"date":"2022-04-18","event":"Beanstalk Farms sends on-chain message offering attacker a 10% whitehat bounty in exchange for returning 90% of funds. Attacker does not respond.","source":""},{"date":"2022-06-06","event":"Barn Raise fundraiser launches, targeting $77 million in recapitalization via Fertilizer token sales.","source":""},{"date":"2022-08-04","event":"BIP-21 (the Replant proposal) reaches supermajority. Barn Raise has attracted over $17 million USDC — approximately 22% of the target.","source":""},{"date":"2022-08-06","event":"Beanstalk protocol officially relaunches ('Replant') with governance under community multisig and restructured tokenomics.","source":""},{"date":"2024-04","event":"Cyfrin conducts security audit of Beanstalk 2 upgrade, including BEAN:wstETH liquidity whitelisting.","source":"","date_original":"2024-04-01"},{"date":"2024-05","event":"Cyfrin conducts security audit of Beanstalk 3, which includes plans for Ethereum L2 migration.","source":"","date_original":"2024-05-01"},{"date":"2025-05","event":"BEAN trades at approximately $0.23 (77% below peg). Protocol TVL approximately $9 million. Attacker identity remains unknown; stolen funds unrecovered.","source":"","date_original":"2025-05-01"}],"sources_used":[{"url":"https://www.coindesk.com/tech/2022/04/17/attacker-drains-182m-from-beanstalk-stablecoin-protocol","name":"","type":"other","archive_url":"http://web.archive.org/web/20251111081130/https://www.coindesk.com/tech/2022/04/17/attacker-drains-182m-from-beanstalk-stablecoin-protocol","credibility":3,"archive_timestamp":"2025-11-11T08:11:30+00:00"},{"url":"https://cointelegraph.com/news/once-hacked-for-77m-beanstalk-s-algo-stablecoin-protocol-relaunches","name":"","type":"other","archive_url":"https://web.archive.org/web/20260829234325/https://cointelegraph.com/news/once-hacked-for-77m-beanstalk-s-algo-stablecoin-protocol-relaunches","credibility":3,"archive_timestamp":"2026-08-29T23:43:25+00:00"},{"url":"https://bean.money/beanstalk.pdf","name":"","type":"other","archive_url":"http://web.archive.org/web/20260413205903/https://bean.money/beanstalk.pdf","credibility":3,"archive_timestamp":"2026-04-13T20:59:03+00:00"},{"url":"https://rekt.news/beanstalk-rekt","name":"","type":"other","archive_url":"http://web.archive.org/web/20260714093834/https://rekt.news/beanstalk-rekt","credibility":3,"archive_timestamp":"2026-07-14T09:38:34+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-beanstalk-hack-april-2022","name":"","type":"other","archive_url":"http://web.archive.org/web/20260210153714/https://www.halborn.com/blog/post/explained-the-beanstalk-hack-april-2022","credibility":3,"archive_timestamp":"2026-02-10T15:37:14+00:00"},{"url":"https://www.bleepingcomputer.com/news/security/beanstalk-defi-platform-loses-182-million-in-flash-loan-attack/","name":"","type":"other","archive_url":"http://web.archive.org/web/20250908123435/https://www.bleepingcomputer.com/news/security/beanstalk-defi-platform-loses-182-million-in-flash-loan-attack/","credibility":3,"archive_timestamp":"2025-09-08T12:34:35+00:00"},{"url":"https://medium.com/immunefi/hack-analysis-beanstalk-governance-attack-april-2022-f42788fc821e","name":"","type":"other","archive_url":"http://web.archive.org/web/20251117052409/https://medium.com/immunefi/hack-analysis-beanstalk-governance-attack-april-2022-f42788fc821e","credibility":3,"archive_timestamp":"2025-11-17T05:24:09+00:00"},{"url":"https://www.bloomberg.com/news/articles/2022-04-18/defi-project-beanstalk-loses-182-million-in-flash-loan-attack","name":"","type":"other","archive_url":"http://web.archive.org/web/20240812234049/https://www.bloomberg.com/news/articles/2022-04-18/defi-project-beanstalk-loses-182-million-in-flash-loan-attack","credibility":3,"archive_timestamp":"2024-08-12T23:40:49+00:00"},{"url":"https://blog.merklescience.com/hacktrack/hack-track-analysis-of-beanstalk-flash-loan-attack-hack-track-merkle-science","name":"","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://www.certik.com/resources/blog/revisiting-beanstalk-farms-exploit","name":"","type":"other","archive_url":"https://web.archive.org/web/20260829145303/https://www.certik.com/blog/revisiting-beanstalk-farms-exploit","credibility":3,"archive_timestamp":"2026-08-29T14:53:03+00:00"},{"url":"https://cointelegraph.com/news/beanstalk-farms-offers-plea-deal-to-perpetrators-of-76m-exploit","name":"","type":"other","archive_url":"http://web.archive.org/web/20250920172902/https://cointelegraph.com/news/beanstalk-farms-offers-plea-deal-to-perpetrators-of-76m-exploit","credibility":3,"archive_timestamp":"2025-09-20T17:29:02+00:00"},{"url":"https://www.coindesk.com/business/2022/06/02/beanstalk-stablecoin-protocol-barn-raise-aims-to-restore-77m-in-lost-funds","name":"","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://bean.money/blog/path-forward","name":"","type":"other","archive_url":"http://web.archive.org/web/20260515140616/https://www.bean.money/blog/path-forward","credibility":3,"archive_timestamp":"2026-05-15T14:06:16+00:00"},{"url":"https://www.techtarget.com/searchsecurity/news/252516215/Cryptocurrency-theft-leaves-Beanstalk-Farms-future-in-doubt","name":"","type":"other","archive_url":"http://web.archive.org/web/20260415111703/https://www.techtarget.com/searchsecurity/news/252516215/Cryptocurrency-theft-leaves-Beanstalk-Farms-future-in-doubt","credibility":3,"archive_timestamp":"2026-04-15T11:17:03+00:00"},{"url":"https://defillama.com/protocol/beanstalk","name":"","type":"other","archive_url":"http://web.archive.org/web/20251013181320/https://defillama.com/protocol/beanstalk","credibility":3,"archive_timestamp":"2025-10-13T18:13:20+00:00"},{"url":"https://github.com/Cyfrin/2024-04-beanstalk-2","name":"","type":"other","archive_url":"https://web.archive.org/web/20260829133918/https://github.com/Cyfrin/2024-04-beanstalk-2","credibility":3,"archive_timestamp":"2026-08-29T13:39:18+00:00"},{"url":"https://www.bankinfosecurity.com/stablecoin-protocol-beanstalk-loses-millions-in-attack-a-18918","name":"","type":"other","archive_url":"https://web.archive.org/web/20260830003244/https://www.bankinfosecurity.com/stablecoin-protocol-beanstalk-loses-millions-in-attack-a-18918","credibility":3,"archive_timestamp":"2026-08-30T00:32:44+00:00"},{"url":"https://www.coingecko.com/en/coins/bean","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:49.814395+00:00","updated_at":"2026-08-30T01:16:33.999938+00:00"}}