{"investigation":{"slug":"bearnfi","entity_name":"BearnFi","trust_score":12,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"bEarn.fi (BearnFi) is a Binance Smart Chain-based cross-chain yield farming and algorithmic stablecoin protocol that launched in late 2020. On May 16, 2021, an attacker exploited a smart contract denomination mismatch to drain approximately $10.85 million in BUSD from the protocol's bVaults via a flash loan attack. The project subsequently became inactive, with its native BFI token recording no price data after mid-2023 and a market capitalization of effectively zero. The entity has been flagged by ZachXBT.","sections":[{"content":"On May 16, 2021, at 10:36:20 AM UTC, the bEarn.fi BvaultsBank contract was exploited through a flash loan attack, resulting in the loss of approximately $10.85 million in BUSD stablecoins. The attacker borrowed 7,804,239 BUSD from Cream Finance via a flash loan and executed a series of 26 to 30 deposit and withdrawal transactions against bEarn's BUSD Alpaca strategy vault. The exploit drained the pool before the attacker repaid the flash loan with fees and exited.\n\nThe attacker's wallet was identified as 0x47f341d896b08daacb344d9021f955247e50d089, and the primary exploit transaction hash is 0x603b2bbe2a7d0877b22531735ff686a7caad866f6c0435c37b7b49e4bfd9a36c. Following the attack, bEarn's algorithmic stablecoin BDO dropped approximately 11%, trading down to $0.24.\n\nBlockchain security firm PeckShield published a post-mortem identifying the root cause as an inconsistent asset denomination between the BvaultsBank contract and its associated BvaultsStrategy contract. Specifically, the BvaultsBank's withdraw logic assumed the withdrawn amount was denominated in BUSD, while BvaultsStrategy assumed the same value was denominated in ibBUSD, an interest-bearing token worth more than BUSD. This mismatch meant that a withdrawal request of 7,804,239 BUSD was effectively processed as 7,804,239 ibBUSD, which was equivalent to approximately 8,016,006 BUSD in market value. By iterating this cycle repeatedly, the attacker extracted funds in excess of what they deposited in each loop.","heading":"May 2021 Flash Loan Exploit","sources":[{"url":"https://peckshield.medium.com/bearn-fi-incident-inconsistent-asset-denomination-between-vault-strategy-9b24b68ab1c0","name":"peckshield.medium.com","type":"other","credibility":3},{"url":"https://beincrypto.com/defi-protocol-bearn-suffers-11m-flash-loan-attack/","name":"beincrypto.com","type":"other","credibility":3},{"url":"https://bearndao.medium.com/bvaults-busd-alpaca-strategy-exploit-post-mortem-and-bearn-s-compensation-plan-b0b38c3b5540","name":"bearndao.medium.com","type":"other","credibility":3},{"url":"https://rekt.news/bearn-rekt/","name":"rekt.news","type":"other","credibility":3},{"url":"https://github.com/OriginProtocol/security/blob/master/incidents/2021-05-16-BearnFi.md","name":"github.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The vulnerability that enabled the May 2021 exploit was present in the bVaults smart contract from its initial deployment, according to bEarn's own post-mortem. The team acknowledged: 'we passed the method withdraw from FairLaunch contract with BUSD amount while we should have used ibBUSD amount instead.' This implies the error was not introduced through an upgrade but was a fundamental flaw present at launch.\n\nbEarn had engaged CertiK to audit its bDollar smart contract, and PeckShield was subsequently engaged for analysis following the exploit. However, reporting from January 2021 indicated the CertiK audit was still in progress at the time, raising questions about the audit coverage of the bVaults strategy contracts that were ultimately exploited.\n\nThe rekt.news analysis of the incident criticized the broader BSC ecosystem for a pattern of hastily-copied and inadequately reviewed smart contract code, noting that 'time is the most valuable audit of all.' The bEarn exploit occurred during a period when BSC DeFi protocols were suffering repeated flash loan attacks — including PancakeBunny, Cream Finance, Bogged Finance, Uranium Finance, Meerkat Finance, Spartan Protocol, and BurgerSwap — all within weeks of each other in May 2021.","heading":"Smart Contract Vulnerability and Security Posture","sources":[{"url":"https://rekt.news/bearn-rekt/","name":"rekt.news","type":"other","credibility":3},{"url":"https://peckshield.medium.com/bearn-fi-incident-inconsistent-asset-denomination-between-vault-strategy-9b24b68ab1c0","name":"peckshield.medium.com","type":"other","credibility":3},{"url":"https://www.bsc.news/post/bearn-jan-2021-review","name":"bsc.news","type":"other","credibility":3},{"url":"https://www.vidma.io/blog/the-bearn-exploit-a-18-million-lesson-in-defi-smart-contract-vulnerabilities","name":"vidma.io","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the exploit, the bEarn team published a post-mortem on Medium via the BEARNDAO account. The team stated they 'deeply regret this incident' and announced immediate steps including contacting Binance to flag the attacker's address, freezing all bVaults, engaging auditors CertiK and PeckShield, and taking balance snapshots.\n\nThe compensation plan promised affected users a total of 105% of their stolen funds: 87.5% of initial deposits reimbursed in BUSD immediately, 7.5% in BDOv2 (bDollar) tokens immediately, and 10% in BDEX tokens vested over 80 weeks. The compensation fund was to be sourced from remaining vault savings, the Dev Fund, the DAO Fund, and a portion of ongoing protocol fees.\n\nYearn Finance core developer Banteg publicly criticized the practice of immediate full compensation, stating: 'Promising a full compensation just a few hours after a hack seems to become a common theme. It creates a distorted perception of risk for the users and hurts the adoption of insurance protocols.' Banteg's criticism was that rapid compensation pledges mislead DeFi users about the actual financial risk of participating in unaudited or inadequately audited protocols.\n\nThe team also committed to requiring deposit caps and full audits on all new strategies before deployment going forward.","heading":"Team Response and Compensation Plan","sources":[{"url":"https://bearndao.medium.com/bvaults-busd-alpaca-strategy-exploit-post-mortem-and-bearn-s-compensation-plan-b0b38c3b5540","name":"bearndao.medium.com","type":"other","credibility":3},{"url":"https://cryptoslate.com/defi-platform-bearn-fi-promises-105-compensation-after-10-million-hack-but-is-it-the-right-thing/","name":"cryptoslate.com","type":"other","credibility":3},{"url":"https://www.bsc.news/post/victims-of-latest-defi-bearn-fi-exploit-receives-assurance-of-complete-compensation","name":"bsc.news","type":"other","credibility":3}],"severity":"medium"},{"content":"bEarn.fi operated under the BEARNDAO governance structure, with the protocol managed by holders of its BFI and BFIE tokens across Binance Smart Chain and Ethereum respectively. The project's communications were published through the 'BEARNDAO' Medium account, with no individual founders or team members publicly identified by name in available sources.\n\nThe anonymity of the team is a commonly noted risk factor in DeFi protocols, particularly during the 2020-2021 BSC yield farming boom where many projects launched without disclosing developer identities. The AMA records published on the BEARNDAO Medium account do not identify specific individuals by name. This anonymity limits accountability in the event of future incidents or abandonment.","heading":"Anonymous Team and Governance","sources":[{"url":"https://bearndao.medium.com/official-ama-with-the-bearn-fi-team-8d814d09d60d","name":"bearndao.medium.com","type":"other","credibility":3},{"url":"https://bearndao.medium.com/bearn-fi-introduction-9e65f6395dfc","name":"bearndao.medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the May 2021 exploit, bEarn.fi continued to operate but saw declining activity and user interest. The BFI token became effectively inactive; market data sources report that the last recorded price data for BFI was in August 2023, after which trading activity ceased and the market capitalization fell to zero.\n\nOn-chain developer activity tracking and market data aggregators such as CoinLore and CoinPaprika confirm that the BFI token is no longer actively traded and the project has not produced verifiable public updates through major channels in years. The protocol's website (bearn.fi) remained accessible as of the investigation date but showed no evidence of ongoing development activity.","heading":"Protocol Inactivity and Token Decline","sources":[{"url":"https://www.coinlore.com/coin/bearn-fi","name":"coinlore.com","type":"other","credibility":3},{"url":"https://coinpaprika.com/coin/bfi-bearnfi/","name":"coinpaprika.com","type":"other","credibility":3},{"url":"https://stack.money/asset/bearn-fi","name":"stack.money","type":"other","credibility":3}],"severity":"medium"},{"content":"bEarn.fi's exploit occurred during a concentrated period of flash loan and smart contract attacks against Binance Smart Chain DeFi protocols in May 2021. BSC hackers made approximately $167 million through flash loans and exploits across the month. The pattern of attacks was attributed by analysts to the rapid proliferation of forked or copied smart contract code deployed without adequate security review, as well as BSC's low transaction fees enabling high-frequency attack patterns that would be prohibitively expensive on Ethereum mainnet.\n\nbEarn.fi's exploit is documented in the OriginProtocol security incident registry and appears in multiple DeFi hack tracking databases including ChainSec and Halborn's 2021 DeFi hack recap. The protocol is consistently listed among the notable BSC smart contract failures of 2021.","heading":"Broader BSC Risk Context","sources":[{"url":"https://github.com/OriginProtocol/security/blob/master/incidents/2021-05-16-BearnFi.md","name":"github.com","type":"other","credibility":3},{"url":"https://protos.com/bsc-binance-smart-chainflash-loan-attacks-crypto-may/","name":"protos.com","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/the-10-biggest-defi-hacks-of-2021-a-recap","name":"halborn.com","type":"other","credibility":3},{"url":"https://www.chainsec.io/defi-hacks","name":"chainsec.io","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2020-11","event":"bEarn.fi protocol launches on Binance Smart Chain, offering cross-chain yield farming, algorithmic stablecoin, and related DeFi products.","source":"","date_original":"2020-11-01"},{"date":"2021","event":"bEarn.fi January review published; CertiK audit of the bDollar smart contract reported as in progress but not yet completed.","source":"","date_original":"2021-01-01"},{"date":"2021-05-16","event":"Flash loan exploit occurs at 10:36:20 AM UTC. Attacker borrows 7.8M BUSD from Cream Finance and executes 26-30 deposit/withdrawal cycles against the bVaults BUSD Alpaca strategy, draining approximately $10.85 million in BUSD.","source":""},{"date":"2021-05-16","event":"bEarn team freezes all bVaults, contacts Binance to flag attacker address 0x47f341d896b08daacb344d9021f955247e50d089, and engages CertiK and PeckShield.","source":""},{"date":"2021-05-17","event":"bEarn team publishes post-mortem and announces 105% compensation plan for affected users: 87.5% BUSD + 7.5% BDOv2 immediately, 10% BDEX vested over 80 weeks.","source":""},{"date":"2021-05-17","event":"PeckShield publishes technical analysis confirming root cause as inconsistent asset denomination (BUSD vs ibBUSD) between BvaultsBank and BvaultsStrategy contracts.","source":""},{"date":"2021-05-17","event":"Yearn Finance developer Banteg criticizes bEarn's immediate compensation promise, warning it creates a distorted perception of risk for DeFi users.","source":""},{"date":"2023-08-10","event":"Last recorded price data for BFI token per market data aggregators. Protocol activity effectively ceases with market capitalization falling to zero.","source":""}],"sources_used":[{"url":"https://peckshield.medium.com/bearn-fi-incident-inconsistent-asset-denomination-between-vault-strategy-9b24b68ab1c0","name":"peckshield.medium.com","type":"other","archive_url":"http://web.archive.org/web/20260322055924/https://peckshield.medium.com/bearn-fi-incident-inconsistent-asset-denomination-between-vault-strategy-9b24b68ab1c0","credibility":3,"archive_timestamp":"2026-03-22T05:59:24+00:00"},{"url":"https://beincrypto.com/defi-protocol-bearn-suffers-11m-flash-loan-attack/","name":"beincrypto.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://bearndao.medium.com/bvaults-busd-alpaca-strategy-exploit-post-mortem-and-bearn-s-compensation-plan-b0b38c3b5540","name":"bearndao.medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://rekt.news/bearn-rekt/","name":"rekt.news","type":"other","archive_url":"http://web.archive.org/web/20260513154119/https://rekt.news/bearn-rekt","credibility":3,"archive_timestamp":"2026-05-13T15:41:19+00:00"},{"url":"https://github.com/OriginProtocol/security/blob/master/incidents/2021-05-16-BearnFi.md","name":"github.com","type":"other","archive_url":"https://web.archive.org/web/20260830203816/https://github.com/OriginProtocol/security/blob/master/incidents/2021-05-16-BearnFi.md","credibility":3,"archive_timestamp":"2026-08-30T20:38:16+00:00"},{"url":"https://www.bsc.news/post/bearn-jan-2021-review","name":"bsc.news","type":"other","archive_url":null,"credibility":3,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.vidma.io/blog/the-bearn-exploit-a-18-million-lesson-in-defi-smart-contract-vulnerabilities","name":"vidma.io","type":"other","archive_url":"http://web.archive.org/web/20260513073439/https://www.vidma.io/blog/the-bearn-exploit-a-18-million-lesson-in-defi-smart-contract-vulnerabilities","credibility":3,"archive_timestamp":"2026-05-13T07:34:39+00:00"},{"url":"https://cryptoslate.com/defi-platform-bearn-fi-promises-105-compensation-after-10-million-hack-but-is-it-the-right-thing/","name":"cryptoslate.com","type":"other","archive_url":"http://web.archive.org/web/20260309181702/https://cryptoslate.com/defi-platform-bearn-fi-promises-105-compensation-after-10-million-hack-but-is-it-the-right-thing/","credibility":3,"archive_timestamp":"2026-03-09T18:17:02+00:00"},{"url":"https://www.bsc.news/post/victims-of-latest-defi-bearn-fi-exploit-receives-assurance-of-complete-compensation","name":"bsc.news","type":"other","archive_url":null,"credibility":3,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://bearndao.medium.com/official-ama-with-the-bearn-fi-team-8d814d09d60d","name":"bearndao.medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://bearndao.medium.com/bearn-fi-introduction-9e65f6395dfc","name":"bearndao.medium.com","type":"other","archive_url":"http://web.archive.org/web/20250919014158/https://bearndao.medium.com/bearn-fi-introduction-9e65f6395dfc","credibility":3,"archive_timestamp":"2025-09-19T01:41:58+00:00"},{"url":"https://www.coinlore.com/coin/bearn-fi","name":"coinlore.com","type":"other","archive_url":"http://web.archive.org/web/20260830093035/https://www.coinlore.com/coin/bearn-fi","credibility":3,"archive_timestamp":"2026-08-30T09:30:35+00:00"},{"url":"https://coinpaprika.com/coin/bfi-bearnfi/","name":"coinpaprika.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:gone","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://stack.money/asset/bearn-fi","name":"stack.money","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-job","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://protos.com/bsc-binance-smart-chainflash-loan-attacks-crypto-may/","name":"protos.com","type":"other","archive_url":"http://web.archive.org/web/20260511084742/https://protos.com/bsc-binance-smart-chainflash-loan-attacks-crypto-may/","credibility":3,"archive_timestamp":"2026-05-11T08:47:42+00:00"},{"url":"https://www.halborn.com/blog/post/the-10-biggest-defi-hacks-of-2021-a-recap","name":"halborn.com","type":"other","archive_url":"http://web.archive.org/web/20260806015737/https://www.halborn.com/blog/post/the-10-biggest-defi-hacks-of-2021-a-recap","credibility":3,"archive_timestamp":"2026-08-06T01:57:37+00:00"},{"url":"https://www.chainsec.io/defi-hacks","name":"chainsec.io","type":"other","archive_url":"http://web.archive.org/web/20260519074402/https://www.chainsec.io/defi-hacks","credibility":3,"archive_timestamp":"2026-05-19T07:44:02+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:57.402374+00:00","updated_at":"2026-08-30T20:47:34.558293+00:00"}}