{"investigation":{"slug":"beanstalk-farms","entity_name":"Beanstalk Farms","trust_score":28,"severity_base":null,"score_modifier":0,"confidence":0.88,"status":"published","content_type":"investigation","summary":"Beanstalk Farms is an Ethereum-based algorithmic stablecoin protocol that issues the BEAN token using a credit-based, uncollateralized peg mechanism. On April 17, 2022, the protocol suffered one of the largest governance exploits in DeFi history when an attacker used a flash loan to seize supermajority voting power and drain approximately $182 million from the protocol's liquidity pools. The protocol relaunched in August 2022 following a community fundraise, subsequent security audits, and governance restructuring, and later migrated to Arbitrum via BIP-50.","sections":[{"content":"Beanstalk Farms is a decentralized development organization that maintains the Beanstalk stablecoin protocol, originally deployed on Ethereum mainnet. The protocol issues a USD-pegged stablecoin called BEAN using a credit-based mechanism rather than collateral, relying on algorithmic supply adjustments and on-chain lending incentives to maintain its peg. The protocol uses a timekeeping mechanism called Seasons (approximately one hour each), during which it evaluates the oracle price and debt level to dynamically adjust Bean supply, Soil supply, and lending rates. The Beanstalk protocol grew organically to approximately $100 million in market capitalization and attracted $144 million in incentivized liquidity within roughly eight months of launch. The founding team operated under the collective pseudonym 'Publius,' a reference to the anonymous authors of the Federalist Papers, and consists of Benjamin Weintraub, Brendan Sanderson, and Michael Montoya, who attended the University of Chicago together. The founders publicly revealed their identities following the April 2022 exploit to demonstrate they were not involved in the attack.","heading":"Protocol Overview","sources":[{"url":"https://medium.com/beanstalkfarms/introducing-beanstalk-557c45cb8d80","name":"medium.com","type":"other","credibility":3},{"url":"https://bean.money/blog/how-beanstalk-tackles-the-stablecoin-trilemma","name":"bean.money","type":"other","credibility":3},{"url":"https://www.techtarget.com/searchsecurity/news/252516215/cryptocurrency-theft-leaves-beanstalk-farms-future-in-doubt","name":"techtarget.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On April 17, 2022, Beanstalk suffered a governance flash loan attack that resulted in approximately $182 million in protocol losses. The attacker exploited a critical design flaw: Beanstalk's emergency governance mechanism did not use flash-loan-resistant voting tallies, allowing an attacker to acquire supermajority voting power within a single transaction. The attack sequence began with the attacker depositing BEAN tokens into Beanstalk's Silo roughly 24 hours prior, creating a malicious governance proposal called 'InitBip18' that would transfer all deposited assets to an attacker-controlled address. On the day of the attack, the exploiter flashloaned over $1 billion in assets — primarily from Aave — then deposited approximately 350 million DAI and converted assets into BEAN3CRV-f and BEANLUSD-f Curve LP tokens, which translated directly into Stalk governance tokens. This gave the attacker more than 67 percent of all Stalk votes, satisfying the two-thirds supermajority threshold required to invoke the emergency commit function. The entire sequence — borrow, vote, drain, repay — occurred within a single Ethereum transaction block. The attacker extracted approximately 24,830 ETH and 36 million BEAN tokens, realizing a net profit of roughly $76 to $80 million after repaying the flashloan. BEAN's price collapsed approximately 86 percent from its $1 peg immediately following the exploit. According to blockchain analytics firm PeckShield, the attacker subsequently laundered all stolen funds through Tornado Cash. The attacker also donated $250,000 of the stolen funds to a Ukraine relief cryptocurrency address. The attacker's identity remains unknown.","heading":"April 2022 Governance Exploit","sources":[{"url":"https://www.coindesk.com/tech/2022/04/17/attacker-drains-182m-from-beanstalk-stablecoin-protocol","name":"coindesk.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/beanstalk-farms-loses-182m-in-defi-governance-exploit","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://medium.com/immunefi/hack-analysis-beanstalk-governance-attack-april-2022-f42788fc821e","name":"medium.com","type":"other","credibility":3},{"url":"https://www.certik.com/resources/blog/6HaLMGIL5sI2fpfEZc0nzS-revisiting-beanstalk-farms-exploit","name":"certik.com","type":"other","credibility":3},{"url":"https://www.bleepingcomputer.com/news/security/beanstalk-defi-platform-loses-182-million-in-flash-loan-attack/","name":"bleepingcomputer.com","type":"other","credibility":3},{"url":"https://www.bloomberg.com/news/articles/2022-04-18/defi-project-beanstalk-loses-182-million-in-flash-loan-attack","name":"bloomberg.com","type":"other","credibility":3},{"url":"https://www.elliptic.co/blog/76-million-stolen-from-beanstalk-farms-defi-stablecoin-protocol","name":"elliptic.co","type":"other","credibility":3}],"severity":"medium"},{"content":"Beanstalk engaged Omniscia to conduct a formal audit of its core smart contracts, approved via BIP-5 by the Beanstalk DAO on December 3, 2021. Omniscia completed the audit on April 2, 2022 — just 15 days before the exploit — identifying 76 findings (8 via statistical analysis, 68 via manual review), all of which were addressed prior to report release. Omniscia concluded the codebase was 'of a very high standard.' However, Omniscia later clarified in a post-mortem that the specific governance code exploited had been introduced after their initial audits and was therefore outside the scope of their review. Following the exploit, Beanstalk commissioned two additional audits: Halborn completed its audit on July 13, 2022, identifying 17 findings that were resolved or acknowledged; Trail of Bits completed its audit on July 22, 2022, identifying 13 findings. Halborn was subsequently retained on a continuous basis to audit new Beanstalk code, and an Immunefi bug bounty program was launched. The pre-exploit audit gap — new governance code that was unaudited at the time of launch — represents a material process failure that directly enabled the attack.","heading":"Audit History and Pre-Exploit Security Posture","sources":[{"url":"https://bean.money/blog/omniscia-audit-of-beanstalk-completed","name":"bean.money","type":"other","credibility":3},{"url":"https://bean.money/blog/halborn-audit-of-beanstalk-completed","name":"bean.money","type":"other","credibility":3},{"url":"https://bean.money/blog/trail-of-bits-audit-of-beanstalk-completed","name":"bean.money","type":"other","credibility":3},{"url":"https://omniscia.io/reports/beanstalk-core-protocol/","name":"omniscia.io","type":"other","credibility":3},{"url":"https://github.com/BeanstalkFarms/Beanstalk-Audits","name":"github.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Immediately following the exploit, the Beanstalk team disabled protocol governance, paused operations, and burned the remaining BEAN tokens in the exploiter contract. The team made a public offer to the attacker to return 90 percent of stolen funds in exchange for a 10 percent whitehat bounty; this offer was not accepted. On June 6, 2022, Beanstalk launched the 'Barn Raise,' a community recapitalization fundraiser structured around Fertilizer debt tokens, targeting approximately $77 million in non-Bean assets lost from the Silo. Over $5.5 million in Fertilizer sold in the first hour of the campaign. By August 4, 2022, when a governance supermajority approved BIP-21 (the Replant proposal), the Barn Raise had attracted over $17 million USDC in committed credit. The Replant event occurred on August 6, 2022 — the protocol's one-year anniversary — with users holding more than 99 percent of outstanding Stalk supporting the relaunch vote. Governance was restructured from fully on-chain to a community-run multi-signature wallet, pending the future implementation of a flash-loan-resistant on-chain governance mechanism.","heading":"Post-Exploit Response and Barn Raise","sources":[{"url":"https://bean.money/blog/beanstalk-governance-exploit","name":"bean.money","type":"other","credibility":3},{"url":"https://bean.money/blog/path-forward","name":"bean.money","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2022/06/02/beanstalk-stablecoin-protocol-barn-raise-aims-to-restore-77m-in-lost-funds","name":"coindesk.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/once-hacked-for-77m-beanstalk-s-algo-stablecoin-protocol-relaunches","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://decrypt.co/106882/beanstalk-celebrates-anniversary-with-safe-replant-and-unpause-months-after-182m-exploit","name":"decrypt.co","type":"other","credibility":3},{"url":"https://www.theblock.co/post/161915/beanstalk-stablecoin-relaunches-four-months-after-182-million-exploit","name":"theblock.co","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the Replant in August 2022, the BEAN stablecoin continued to face peg maintenance challenges. By May 2023, BEAN was trading approximately at $0.91, exhibiting a persistent depeg despite high lending rate incentives intended to encourage Bean buybacks and burns. The protocol subsequently implemented BIP-50, which migrated Beanstalk from Ethereum mainnet to Arbitrum One in order to reduce transaction costs and improve throughput. The migration required users with circulating BEAN tokens or smart-contract-held positions to manually initiate migration, as Beanstalk could not automatically migrate assets held outside its own contracts. The protocol continues to operate on Arbitrum as of 2025. However, BEAN's market capitalization has remained a fraction of its pre-exploit peak, and the uncollateralized algorithmic stablecoin model underpinning BEAN carries inherent structural risks highlighted by the broader collapse of similar models (e.g., TerraUST) in May 2022, just weeks after the Beanstalk exploit.","heading":"Ongoing Peg Stability and Protocol Migration","sources":[{"url":"https://blockworks.co/news/algo-stablecoin-protocol-beanstalk-relaunches-following-180m-hack","name":"blockworks.co","type":"other","credibility":3},{"url":"https://blec.report/is-bean-a-stablecoin-contender/","name":"blec.report","type":"other","credibility":3},{"url":"https://docs.bean.money/almanac/guides/balances/migrate-to-arbitrum","name":"docs.bean.money","type":"other","credibility":3},{"url":"https://github.com/BeanstalkFarms/Farmers-Almanac/blob/master/guides/balances/migrate-to-arbitrum.md","name":"github.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The April 2022 exploit exposed a fundamental class of vulnerability in on-chain governance systems that permit instantaneous voting power acquisition via flash loans. The Beanstalk protocol's emergency commit mechanism — requiring only a two-thirds supermajority with no time-lock between vote acquisition and execution — allowed an attacker to pass a fully malicious proposal in a single atomic transaction. This design choice prioritized governance speed over security. Post-exploit, Beanstalk replaced on-chain governance with a community multi-sig, which trades decentralization for security. The uncollateralized, credit-based stablecoin model also introduces structural fragility: the protocol's ability to maintain BEAN's peg depends on continuous market confidence and active participation in its lending mechanism, without any hard collateral backstop. The persistent post-relaunch depeg through 2023 illustrates the fragility of purely algorithmic peg mechanisms. Independent analysis by Immunefi and CertiK both identified the lack of flash-loan-resistant vote tallying as the single root cause of the attack.","heading":"Governance Risk and Structural Vulnerabilities","sources":[{"url":"https://medium.com/immunefi/hack-analysis-beanstalk-governance-attack-april-2022-f42788fc821e","name":"medium.com","type":"other","credibility":3},{"url":"https://www.certik.com/resources/blog/6HaLMGIL5sI2fpfEZc0nzS-revisiting-beanstalk-farms-exploit","name":"certik.com","type":"other","credibility":3},{"url":"https://www.merklescience.com/blog/hack-track-analysis-of-beanstalk-flash-loan-attack","name":"merklescience.com","type":"other","credibility":3},{"url":"https://bean.money/blog/path-forward-faq","name":"bean.money","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2021-08-06","event":"Beanstalk protocol launched on Ethereum mainnet, issuing the BEAN algorithmic stablecoin.","source":""},{"date":"2021-12-03","event":"Beanstalk DAO approves BIP-5, committing to hire Omniscia for a formal smart contract audit.","source":""},{"date":"2022-04-02","event":"Omniscia completes its audit of Beanstalk's core smart contracts, finding no outstanding issues. The governance code later exploited was outside the audit scope.","source":""},{"date":"2022-04-17","event":"Beanstalk suffers a governance flash loan attack. The attacker flashloans over $1 billion from Aave and other sources, acquires supermajority Stalk governance power, passes a malicious proposal, and drains approximately $182 million from the protocol. Net attacker profit is approximately $76-80 million. BEAN collapses ~86% from peg. Stolen funds laundered through Tornado Cash.","source":""},{"date":"2022-04-17","event":"Beanstalk Farms founders (operating as 'Publius') reveal their identities as Benjamin Weintraub, Brendan Sanderson, and Michael Montoya at an emergency Discord town hall to demonstrate non-involvement.","source":""},{"date":"2022-04-23","event":"Beanstalk DAO approves hiring Halborn for a post-exploit security audit.","source":""},{"date":"2022-06-06","event":"The Barn Raise recapitalization fundraiser launches. Over $5.5 million in Fertilizer tokens sold in the first hour.","source":""},{"date":"2022-07-13","event":"Halborn completes its audit of Beanstalk, identifying 17 findings all resolved or acknowledged.","source":""},{"date":"2022-07-22","event":"Trail of Bits completes its audit of Beanstalk, identifying 13 findings all resolved or acknowledged.","source":""},{"date":"2022-08-04","event":"BIP-21 (Replant proposal) achieves supermajority approval. Barn Raise has attracted over $17 million USDC in credit commitments.","source":""},{"date":"2022-08-06","event":"Beanstalk relaunches via the Replant event on the protocol's one-year anniversary. On-chain governance is replaced with a community multi-sig wallet. Over 99% of Stalk holders backed the relaunch.","source":""},{"date":"2023-05","event":"BEAN stablecoin reported trading at approximately $0.91, exhibiting a persistent depeg despite algorithmic incentives designed to restore the peg.","source":"","date_original":"2023-05-01"},{"date":"2024","event":"Beanstalk implements BIP-50, migrating the protocol from Ethereum mainnet to Arbitrum One to reduce transaction costs and improve throughput.","source":"","date_original":"2024-01-01"}],"sources_used":[{"url":"https://medium.com/beanstalkfarms/introducing-beanstalk-557c45cb8d80","name":"medium.com","type":"other","credibility":3},{"url":"https://bean.money/blog/how-beanstalk-tackles-the-stablecoin-trilemma","name":"bean.money","type":"other","credibility":3},{"url":"https://www.techtarget.com/searchsecurity/news/252516215/cryptocurrency-theft-leaves-beanstalk-farms-future-in-doubt","name":"techtarget.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/tech/2022/04/17/attacker-drains-182m-from-beanstalk-stablecoin-protocol","name":"coindesk.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/beanstalk-farms-loses-182m-in-defi-governance-exploit","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://medium.com/immunefi/hack-analysis-beanstalk-governance-attack-april-2022-f42788fc821e","name":"medium.com","type":"other","credibility":3},{"url":"https://www.certik.com/resources/blog/6HaLMGIL5sI2fpfEZc0nzS-revisiting-beanstalk-farms-exploit","name":"certik.com","type":"other","credibility":3},{"url":"https://www.bleepingcomputer.com/news/security/beanstalk-defi-platform-loses-182-million-in-flash-loan-attack/","name":"bleepingcomputer.com","type":"other","credibility":3},{"url":"https://www.bloomberg.com/news/articles/2022-04-18/defi-project-beanstalk-loses-182-million-in-flash-loan-attack","name":"bloomberg.com","type":"other","credibility":3},{"url":"https://www.elliptic.co/blog/76-million-stolen-from-beanstalk-farms-defi-stablecoin-protocol","name":"elliptic.co","type":"other","credibility":3},{"url":"https://bean.money/blog/omniscia-audit-of-beanstalk-completed","name":"bean.money","type":"other","credibility":3},{"url":"https://bean.money/blog/halborn-audit-of-beanstalk-completed","name":"bean.money","type":"other","credibility":3},{"url":"https://bean.money/blog/trail-of-bits-audit-of-beanstalk-completed","name":"bean.money","type":"other","credibility":3},{"url":"https://omniscia.io/reports/beanstalk-core-protocol/","name":"omniscia.io","type":"other","credibility":3},{"url":"https://github.com/BeanstalkFarms/Beanstalk-Audits","name":"github.com","type":"other","credibility":3},{"url":"https://bean.money/blog/beanstalk-governance-exploit","name":"bean.money","type":"other","credibility":3},{"url":"https://bean.money/blog/path-forward","name":"bean.money","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2022/06/02/beanstalk-stablecoin-protocol-barn-raise-aims-to-restore-77m-in-lost-funds","name":"coindesk.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/once-hacked-for-77m-beanstalk-s-algo-stablecoin-protocol-relaunches","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://decrypt.co/106882/beanstalk-celebrates-anniversary-with-safe-replant-and-unpause-months-after-182m-exploit","name":"decrypt.co","type":"other","credibility":3},{"url":"https://www.theblock.co/post/161915/beanstalk-stablecoin-relaunches-four-months-after-182-million-exploit","name":"theblock.co","type":"other","credibility":3},{"url":"https://blockworks.co/news/algo-stablecoin-protocol-beanstalk-relaunches-following-180m-hack","name":"blockworks.co","type":"other","credibility":3},{"url":"https://blec.report/is-bean-a-stablecoin-contender/","name":"blec.report","type":"other","credibility":3},{"url":"https://docs.bean.money/almanac/guides/balances/migrate-to-arbitrum","name":"docs.bean.money","type":"other","credibility":3},{"url":"https://github.com/BeanstalkFarms/Farmers-Almanac/blob/master/guides/balances/migrate-to-arbitrum.md","name":"github.com","type":"other","credibility":3},{"url":"https://www.merklescience.com/blog/hack-track-analysis-of-beanstalk-flash-loan-attack","name":"merklescience.com","type":"other","credibility":3},{"url":"https://bean.money/blog/path-forward-faq","name":"bean.money","type":"other","credibility":3}],"source_tags":[],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-30T18:24:39.82177+00:00","updated_at":"2026-08-29T01:33:30.533+00:00"}}