{"investigation":{"slug":"bent-finance","entity_name":"Bent Finance","trust_score":28,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"Bent Finance is an Ethereum-based DeFi yield aggregator built on top of Curve Finance and Convex Finance, offering staking and liquidity pool boosting for the BENT token. In December 2021, the protocol suffered an insider exploit in which a rogue developer with access to the contract deployer private key inserted a backdoor into the cvxCRV and MIM pool contracts, resulting in the theft of approximately 440 ETH (~$1.75M). Stolen funds were ultimately returned by the attacker and reimbursed to users by late December 2021, but the incident caused a 73% BENT token price collapse and left the protocol with negligible TVL.","sections":[{"content":"On December 20, 2021, Bent Finance disclosed a security incident traced to its own contract deployer address. On-chain security firm PeckShield identified that the Bent Finance cvxCRV pool contract had been silently updated on November 30, 2021 — approximately 20 days before discovery — to hardcode a balance of 100000001000001 * 10^12 tokens for attacker address 0xd23cfffa066f81c7640e3f0dc8bb2958f7686d1f. This manipulation allowed the address to withdraw pool liquidity far exceeding any legitimate stake. A secondary attacker address, 0x9e966a54082427d7ac56aeaee4baae7d11a6e468, was also identified as connected to the operation. The exploit targeted both the cvxCRV and MIM pools. According to the Halborn post-mortem, the attacker then swapped stolen cvxCRV tokens into CRV and converted them to ETH. Funds were routed through Tornado Cash: the attacker's primary wallet received two deposits from Tornado Cash on December 9, 2021, and approximately 440 ETH was laundered through Tornado Cash in two batches between December 12 and December 21, 2021. Total losses were confirmed at approximately $1.75 million. The Bent Finance team initially stated 'no funds had been lost' before reversing course after PeckShield's public identification of the deployer-originating transaction.","heading":"Insider Exploit — December 2021","sources":[{"url":"https://halborn.com/explained-the-bent-finance-hack-december-2021/","name":"halborn.com","type":"other","credibility":3},{"url":"https://rekt.news/bent-finance","name":"rekt.news","type":"other","credibility":3},{"url":"https://cryptopotato.com/bent-finance-exploit-originated-from-deployer-address-confirms-protocol/","name":"cryptopotato.com","type":"other","credibility":3},{"url":"https://www.quadrigainitiative.com/casestudy/bentfinancemaliciousbalanceinjection.php","name":"quadrigainitiative.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The core technical failure enabling the exploit was the deployment of Bent Finance smart contracts without multisig wallet ownership. Ownership was held by a single externally owned account (EOA), meaning any party possessing the deployer private key could push unilateral contract updates. The Bent Finance team had planned to migrate to multisig but had not yet completed the transition. During this window, an individual described as a rogue developer — employed by or contracted through the protocol's CTO — was shared the deployer private key in order to perform routine updates. This developer allegedly used the access to insert the backdoor balance-injection code, then followed up with a clean contract update to conceal the change. The backdoor was live and undetected for approximately 20 days. The incident is categorized as an insider threat rather than an external smart contract vulnerability. No audit had flagged the access control gap prior to the exploit.","heading":"Access Control Failure and Root Cause","sources":[{"url":"https://halborn.com/explained-the-bent-finance-hack-december-2021/","name":"halborn.com","type":"other","credibility":3},{"url":"https://www.vidma.io/blog/the-bent-finance-betrayal-unraveling-the-1-75m-exploit","name":"vidma.io","type":"other","credibility":3},{"url":"https://www.quadrigainitiative.com/casestudy/bentfinancemaliciousbalanceinjection.php","name":"quadrigainitiative.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the exploit disclosure, the Bent Finance team engaged in negotiations with the alleged attacker. The hacker agreed to return the stolen tokens. According to CoinCodeCap's reporting, a full reimbursement of 512,696.06482288612 cvxcrv-f tokens was made to a team-controlled multisig at address 0xaBb8B277F49de499b902A1E09A2aCA727595b544. The community additionally contributed an estimated 200,000 cvxCRV (approximately $1 million at the time) to cover any remaining deficit. By approximately December 24-25, 2021, the team reported that affected users had been made whole. Two independent white hat developers were employed by the team to assist with patching the access control vulnerabilities. The BENT token, which had reached an all-time high of $15.90 on December 19, 2021 — one day before the exploit was discovered — dropped approximately 73-74% upon disclosure.","heading":"Fund Recovery and User Reimbursement","sources":[{"url":"https://coincodecap.com/bent-finances-makes-a-stronger-comeback","name":"coincodecap.com","type":"other","credibility":3},{"url":"https://www.quadrigainitiative.com/casestudy/bentfinancemaliciousbalanceinjection.php","name":"quadrigainitiative.com","type":"other","credibility":3},{"url":"https://cryptopotato.com/bent-finance-exploit-originated-from-deployer-address-confirms-protocol/","name":"cryptopotato.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The BENT governance and utility token has experienced near-total value destruction since the December 2021 exploit. As of available 2026 data, the token trades at approximately $0.012, representing a decline of more than 99.9% from its all-time high of $15.90. Current 24-hour trading volume is reported below $15 USD. The protocol's total value locked (TVL) as tracked by DeFiLlama stands at approximately $15,553 as of 2026, with $97,186 in staked BENT tokens. The protocol's website (bent.finance) and application (app.bentfinance.com) remain accessible but the protocol is effectively dormant with negligible activity. No public roadmap updates or substantive governance activity have been publicly reported since 2022. The identity of the rogue developer responsible for the exploit has not been publicly confirmed.","heading":"Token and Protocol Status","sources":[{"url":"https://www.coingecko.com/en/coins/bent-finance","name":"coingecko.com","type":"other","credibility":3},{"url":"https://defillama.com/protocol/bent-finance","name":"defillama.com","type":"other","credibility":3},{"url":"https://coinmarketcap.com/currencies/bent-finance/","name":"coinmarketcap.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The Bent Finance team operated under pseudonymous identities. Core team members were publicly known only by their handles: swisshed, ape, santonicle, and conrad. No legal names, corporate registration details, or jurisdiction of incorporation have been publicly disclosed. The CTO role was referenced in post-exploit reporting as the individual who granted the rogue developer access to deployer keys, but this individual was not identified by name. The protocol's initial denial of losses — stating 'no funds had been lost' before PeckShield's public disclosure forced an acknowledgment — drew criticism regarding transparency. The protocol's anonymous structure also complicated accountability: because the attacker laundered funds via Tornado Cash, no legal recovery mechanism was publicly pursued. The incident was widely cited in post-mortems as illustrating the systemic risk of anonymous team structures in DeFi protocols lacking multisig controls.","heading":"Team Transparency and Accountability","sources":[{"url":"https://www.quadrigainitiative.com/casestudy/bentfinancemaliciousbalanceinjection.php","name":"quadrigainitiative.com","type":"other","credibility":3},{"url":"https://rekt.news/bent-finance","name":"rekt.news","type":"other","credibility":3},{"url":"https://bentfi.medium.com/getting-bent-w-vesting-roadmaps-and-the-hundredth-ape-409b6c228bd","name":"bentfi.medium.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2021-11-30","event":"Rogue developer silently updates Bent Finance cvxCRV pool contract to hardcode a malicious token balance for attacker address 0xd23cfffa066f81c7640e3f0dc8bb2958f7686d1f. A subsequent clean update is deployed to conceal the modification.","source":""},{"date":"2021-12-09","event":"Attacker's primary wallet receives two deposits from Tornado Cash, pre-funding the operation.","source":""},{"date":"2021-12-12","event":"Attacker begins executing withdrawals. First batch: 263,000 cvxCRV-f extracted from Bent Finance pools, converted to ETH, and sent to Tornado Cash.","source":""},{"date":"2021-12-19","event":"BENT token reaches all-time high of $15.90 per token.","source":""},{"date":"2021-12-20","event":"Exploit discovered at approximately 8:55 PM EST. Bent Finance disables reward claims and alerts users. Second batch of approximately 240 ETH laundered via Tornado Cash. Total: ~440 ETH (~$1.75M) laundered.","source":""},{"date":"2021-12-21","event":"PeckShield publicly confirms exploit originated from Bent Finance's own deployer address. Protocol issues official confirmation and advises all pool investors to withdraw funds. BENT token drops 73-74%. Team employs two independent white hat developers.","source":""},{"date":"2021-12-24","event":"Hacker agrees to return stolen funds to team multisig at 0xaBb8B277F49de499b902A1E09A2aCA727595b544. Full reimbursement of 512,696 cvxcrv-f tokens completed. Community contributed ~200,000 additional cvxCRV to cover deficit.","source":""}],"sources_used":[{"url":"https://halborn.com/explained-the-bent-finance-hack-december-2021/","name":"halborn.com","type":"other","archive_url":"https://web.archive.org/web/20260830085709/https://www.halborn.com/blog/post/explained-the-bent-finance-hack-december-2021","credibility":3,"archive_timestamp":"2026-08-30T08:57:09+00:00"},{"url":"https://rekt.news/bent-finance","name":"rekt.news","type":"other","archive_url":"http://web.archive.org/web/20260513170511/https://rekt.news/bent-finance","credibility":3,"archive_timestamp":"2026-05-13T17:05:11+00:00"},{"url":"https://cryptopotato.com/bent-finance-exploit-originated-from-deployer-address-confirms-protocol/","name":"cryptopotato.com","type":"other","archive_url":"http://web.archive.org/web/20260724222957/https://cryptopotato.com/bent-finance-exploit-originated-from-deployer-address-confirms-protocol/","credibility":3,"archive_timestamp":"2026-07-24T22:29:57+00:00"},{"url":"https://www.quadrigainitiative.com/casestudy/bentfinancemaliciousbalanceinjection.php","name":"quadrigainitiative.com","type":"other","archive_url":"http://web.archive.org/web/20251207221445/https://quadrigainitiative.com/casestudy/bentfinancemaliciousbalanceinjection.php","credibility":3,"archive_timestamp":"2025-12-07T22:14:45+00:00"},{"url":"https://www.vidma.io/blog/the-bent-finance-betrayal-unraveling-the-1-75m-exploit","name":"vidma.io","type":"other","archive_url":"http://web.archive.org/web/20260418193015/https://www.vidma.io/blog/the-bent-finance-betrayal-unraveling-the-1-75m-exploit","credibility":3,"archive_timestamp":"2026-04-18T19:30:15+00:00"},{"url":"https://coincodecap.com/bent-finances-makes-a-stronger-comeback","name":"coincodecap.com","type":"other","archive_url":"http://web.archive.org/web/20260420062654/https://coincodecap.com/bent-finances-makes-a-stronger-comeback","credibility":3,"archive_timestamp":"2026-04-20T06:26:54+00:00"},{"url":"https://www.coingecko.com/en/coins/bent-finance","name":"coingecko.com","type":"other","archive_url":"http://web.archive.org/web/20251007051456/https://www.coingecko.com/en/coins/bent-finance","credibility":3,"archive_timestamp":"2025-10-07T05:14:56+00:00"},{"url":"https://defillama.com/protocol/bent-finance","name":"defillama.com","type":"other","archive_url":"http://web.archive.org/web/20250914215745/https://defillama.com/protocol/bent-finance","credibility":3,"archive_timestamp":"2025-09-14T21:57:45+00:00"},{"url":"https://coinmarketcap.com/currencies/bent-finance/","name":"coinmarketcap.com","type":"other","archive_url":"https://web.archive.org/web/20260830125113/https://coinmarketcap.com/currencies/bent-finance/","credibility":3,"archive_timestamp":"2026-08-30T12:51:13+00:00"},{"url":"https://bentfi.medium.com/getting-bent-w-vesting-roadmaps-and-the-hundredth-ape-409b6c228bd","name":"bentfi.medium.com","type":"other","archive_url":"http://web.archive.org/web/20251010091857/https://bentfi.medium.com/getting-bent-w-vesting-roadmaps-and-the-hundredth-ape-409b6c228bd","credibility":3,"archive_timestamp":"2025-10-10T09:18:57+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:52.249961+00:00","updated_at":"2026-08-30T13:44:38.859068+00:00"}}