{"investigation":{"slug":"eminence","entity_name":"Eminence Finance","trust_score":10,"severity_base":null,"score_modifier":0,"confidence":0.92,"status":"published","content_type":"investigation","summary":"Eminence Finance (EMN) was an unfinished, unaudited NFT gaming protocol being developed by Yearn Finance founder Andre Cronje that was exploited on September 29, 2020, resulting in the theft of approximately $15 million in DAI from its bonding curve contracts. The contracts had never been officially announced or released to the public, but community members discovered and deposited into them after Cronje's cryptic tweets; the attacker returned $8 million to Cronje's deployer address but $7 million was never recovered. The incident became a defining case study in DeFi's 'degen' culture and the risks of deploying unaudited smart contracts to Ethereum mainnet.","sections":[{"content":"Eminence Finance (ticker: EMN) was a planned NFT gaming ecosystem described as an 'economy for a gaming multiverse,' developed by Andre Cronje, the founder of Yearn Finance (YFI). Cronje has stated he began the project in late September 2020, intending it as a staging/testing environment deployed on Ethereum mainnet for internal development purposes. The project had no public front-end interface, no whitepaper, no audit, and had not been formally announced to the public at the time of the exploit. According to Cronje's own statement: 'Yesterday we finished the concept behind our new economy for a gaming multiverse. Eminence. As per my usual methodology, I deployed our staging contracts on ETH so we can continue developing on it.' He estimated the project was at minimum three weeks away from any public launch.","heading":"Project Overview","sources":[{"url":"https://decrypt.co/43203/hackers-drain-15-million-from-unreleased-yearn-finance-project","name":"decrypt.co","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/hacker-steals-15m-after-degens-pile-into-unreleased-yearn-finance-project","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://cryptopotato.com/yearn-finance-foray-into-gaming-multiverse-results-in-15-million-contract-hack/","name":"cryptopotato.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On September 29, 2020, at approximately 04:00 UTC, an attacker exploited the EMN bonding curve contracts and drained approximately $15,015,533 DAI. The attack was executed using a flash loan and proceeded as follows: the attacker borrowed roughly 15 million DAI via Uniswap; used the borrowed DAI to mint EMN tokens; traded and burned approximately half of the EMN for eAAVE tokens (a wrapped representation of Aave), which increased EMN's price on the bonding curve; swapped the remaining EMN back for DAI at the inflated price; then used the eAAVE to mint additional EMN and again exchanged it for DAI. This cycle was executed three times, allowing the attacker to net approximately 15 million DAI while repaying the flash loan. The vulnerability stemmed from the bonding curve mechanics in the unaudited contracts, which allowed recursive minting and burning to manipulate the effective price and extract funds deposited by other users. The EMN contract address is 0x5ade7ae8660293f2ebfcefaba91d141d72d221e8 on Ethereum mainnet. The entire exploit transpired within a single transaction, consistent with the flash loan attack model.","heading":"The September 2020 Flash Loan Exploit","sources":[{"url":"https://rekt.news/eminence-rekt-in-prod","name":"rekt.news","type":"other","credibility":3},{"url":"https://www.theblock.co/post/79061/yfi-eminence-defi-protocol-exploited","name":"theblock.co","type":"other","credibility":3},{"url":"https://coinrivet.com/defi-investors-lose-15-million-in-eminence-flash-loan-exploit/","name":"coinrivet.com","type":"other","credibility":3},{"url":"https://cryptobriefing.com/unaudited-crypto-gaming-platform-eminence-hacked-15-million/","name":"cryptobriefing.com","type":"other","credibility":3},{"url":"https://etherscan.io/token/0x5ade7ae8660293f2ebfcefaba91d141d72d221e8","name":"etherscan.io","type":"other","credibility":3}],"severity":"medium"},{"content":"In an unusual development, approximately 11 minutes after draining the contracts, the attacker returned $8,000,000 DAI to Cronje's Yearn deployer contract address. The identity of the attacker and the motive for the partial return were never publicly established. Cronje forwarded the $8 million to the Yearn multisig treasury for distribution to affected users. Yearn developers banteg and Klim K built distribution scripts and a snapshot of EMN and eToken holders at the block immediately preceding the exploit. The refund site youreminence.finance distributed funds at approximately $250,000 per minute; half of the $8 million was claimed within 20 minutes of opening. A separate community issue arose when some users, copying banteg's screenshot of the refund claim interface without reading it carefully, accidentally donated their full entitlement back to banteg's address rather than claiming it. In total, affected users recovered roughly 53 cents on the dollar (8/15). The remaining approximately $7 million was never recovered.","heading":"Partial Fund Return and Refund Distribution","sources":[{"url":"https://rekt.news/eminence-refund-do-or-dai/","name":"rekt.news","type":"other","credibility":3},{"url":"https://www.coindesk.com/tech/2020/10/01/defi-degens-hit-hard-by-eminence-exploit-will-be-partially-compensated","name":"coindesk.com","type":"other","credibility":3},{"url":"https://github.com/banteg/your-eminence","name":"github.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The EMN contracts had received no independent security audit at the time of deployment or exploit. This fact was confirmed by multiple outlets and was central to community and industry criticism. The contracts were deployed to Ethereum mainnet — not a testnet — but Cronje framed this as an internal staging practice rather than a public launch. Notably, there was no official front-end, no documentation, and no public announcement beyond cryptic tweets. The bonding curve mechanism that was exploited had not been reviewed by any third-party security firm. The incident is frequently cited in DeFi security literature as a canonical example of the dangers of deploying unaudited smart contracts to mainnet, regardless of the developer's intent.","heading":"Absence of Audit and Security Controls","sources":[{"url":"https://cryptobriefing.com/unaudited-crypto-gaming-platform-eminence-hacked-15-million/","name":"cryptobriefing.com","type":"other","credibility":3},{"url":"https://www.vidma.io/blog/the-eminence-hack-lessons-in-defi-security-and-smart-contract-vulnerabilities","name":"vidma.io","type":"other","credibility":3},{"url":"https://thedefiant.io/news/defi/andre-cronje-diehards-take-test-in-prod-over-the-edge-with-15m-hack","name":"thedefiant.io","type":"other","credibility":3}],"severity":"medium"},{"content":"After the exploit, Cronje stated: 'The contracts I deployed yesterday were purely for myself to engage with, both GIL and EMN are staging and will not be used,' and 'do not use random contracts I deploy unless I reference it in a medium article.' These statements reflected Cronje's long-standing 'test in prod' philosophy — a phrase he later said he regretted, explaining it was meant as a warning to deter casual use, not as a permission to deploy insecure code. Community reaction was divided. Some argued Cronje bore no responsibility because the contracts were never intended for public use. Others countered that Cronje's cryptic promotional-style tweet about 'a gaming multiverse' created foreseeable FOMO, and that deploying on mainnet — rather than a public testnet such as Ropsten or Kovan — exposed real user funds to risk. A group calling itself 'EMN Investigation' alleged that certain Yearn team members may have been posting tutorials for how to accrue and sell EMN tokens during the brief window before the exploit, and alleged possible insider awareness of the price rise. These allegations were never substantiated by independent evidence and no legal proceedings resulted from them.","heading":"Developer Responsibility and Community Debate","sources":[{"url":"https://decrypt.co/43292/eminence-finance-exploit-leads-to-degen-soul-searching","name":"decrypt.co","type":"other","credibility":3},{"url":"https://thedefiant.io/news/defi/andre-cronje-diehards-take-test-in-prod-over-the-edge-with-15m-hack","name":"thedefiant.io","type":"other","credibility":3},{"url":"https://www.theblock.co/post/81174/yfi-andre-cronje-clarifies-test-in-prod","name":"theblock.co","type":"other","credibility":3},{"url":"https://fullycrypto.com/emn-investigation-lawsuit-raises-responsibility-issue","name":"fullycrypto.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the exploit, a group of affected investors organized under the name 'EMN Investigation' and crowdfunded an attempt to finance a lawsuit against Andre Cronje and named Yearn team members, including Kirby and banteg. The group alleged Cronje was liable because he deployed the contracts on mainnet and that certain team members may have known of the price appreciation and profited. The crowdfunding campaign failed to raise sufficient capital to retain legal counsel, and no lawsuit was ever formally filed. According to Cointelegraph's reporting, the speculative lawsuit attempt attracted little sustained support. No regulatory body — including the SEC or CFTC — has taken any enforcement action related to the Eminence Finance incident as of the date of this investigation.","heading":"Attempted Lawsuit and Legal Outcome","sources":[{"url":"https://cointelegraph.com/news/group-raising-funds-to-sue-andre-cronje-over-emn-hack","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://cryptonews.net/news/legal/396498/","name":"cryptonews.net","type":"other","credibility":3},{"url":"https://blockchain.news/news/yearn.finance-andre-cronje-sued-eminence-project-hack-death-threats","name":"blockchain.news","type":"other","credibility":3}],"severity":"medium"},{"content":"Cronje received death threats following the exploit. Yearn developer banteg confirmed on October 9, 2020 that 'Andre has gone quiet because he has been receiving death threats.' Cronje briefly withdrew from Twitter, posting on October 10: 'Still here. Still building. Nothing has changed. I'm just done tweeting and being on social media.' This was consistent with a broader pattern; Cronje has withdrawn from and returned to public DeFi development multiple times. He formally announced retirement from DeFi in March 2022, citing the personal costs of public development. He subsequently returned to activity via the Fantom Foundation and, in 2025, launched Flying Tulip, a new DeFi venture that raised $200 million in seed funding.","heading":"Developer Response and Social Media Exit","sources":[{"url":"https://cointelegraph.com/news/yfi-s-andre-cronje-disappeared-after-death-threats-will-love-bring-him-back","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://blockchain.news/news/yearn.finance-andre-cronje-sued-eminence-project-hack-death-threats","name":"blockchain.news","type":"other","credibility":3},{"url":"https://www.dlnews.com/articles/web3/andre-cronje-the-rise-and-fall-of-a-defi-god/","name":"dlnews.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The Eminence Finance incident is not isolated within Cronje's development history. Cream Finance, a DeFi protocol with which Cronje was publicly associated as an adviser, suffered three separate exploits: approximately $38 million stolen in February 2021, $19 million in August 2021, and $130 million in October 2021. While Cronje was not the lead developer of Cream Finance, his public endorsement and advisory role contributed to user confidence in the protocol. Critics have noted a recurring pattern in which Cronje's public association with a project — whether as developer, adviser, or mere tweeter — has precipitated large inflows of user capital into contracts before adequate security review, with consequent losses when vulnerabilities were exploited. Supporters counter that Yearn Finance itself, Cronje's primary completed project, was never successfully exploited and that the risks were inherent in early DeFi's experimental culture rather than in Cronje's conduct specifically.","heading":"Broader Pattern: Cronje-Adjacent Protocol Risks","sources":[{"url":"https://www.dlnews.com/articles/web3/andre-cronje-the-rise-and-fall-of-a-defi-god/","name":"dlnews.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/markets/2020/12/08/andre-cronje-defi-expressionist","name":"coindesk.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Eminence Finance (EMN) was never completed or relaunched following the September 2020 exploit. The project has no active development, no live front-end, and no known active team. The EMN token contract (0x5ade7ae8660293f2ebfcefaba91d141d72d221e8) remains on-chain but represents a defunct, fully exploited protocol. ZachXBT, the pseudonymous blockchain investigator, has flagged the entity in connection with the exploit. Users who lost funds in the 2020 attack received partial compensation (approximately 53 cents on the dollar) from the $8 million returned by the attacker; no further compensation mechanism has been established. The project is considered permanently defunct.","heading":"Current Status","sources":[{"url":"https://etherscan.io/token/0x5ade7ae8660293f2ebfcefaba91d141d72d221e8","name":"etherscan.io","type":"other","credibility":3},{"url":"https://rekt.news/eminence-rekt-in-prod","name":"rekt.news","type":"other","credibility":3},{"url":"https://cryptotaxcalculator.io/blog/eminence-finance/","name":"cryptotaxcalculator.io","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2020-09-28","event":"Andre Cronje deploys Eminence Finance staging contracts to Ethereum mainnet for internal development. Cryptic tweet about 'a gaming multiverse' goes public, triggering community discovery of the contracts.","source":""},{"date":"2020-09-29","event":"Community members deposit approximately $15 million DAI into the unaudited EMN bonding curve contracts by interacting directly with the smart contracts (no front-end exists).","source":""},{"date":"2020-09-29","event":"At approximately 04:00 UTC, an unknown attacker uses a flash loan to exploit the EMN bonding curve mechanics, draining the full $15,015,533 DAI from the contracts.","source":""},{"date":"2020-09-29","event":"Approximately 11 minutes after the exploit, the attacker returns $8,000,000 DAI to Cronje's Yearn deployer contract address. Motive and attacker identity remain unknown.","source":""},{"date":"2020-09-29","event":"Cronje acknowledges the exploit and states the contracts were staging-only and not intended for public use. He announces the $8 million will be redistributed to affected users.","source":""},{"date":"2020-09-29","event":"Cronje goes silent on social media, later confirmed to be in response to death threats received following the exploit.","source":""},{"date":"2020-10","event":"Yearn developers banteg and Klim K publish distribution scripts and a snapshot for the refund. Refund site youreminence.finance goes live; $4 million claimed within 20 minutes.","source":"","date_original":"2020-10-01"},{"date":"2020-10-09","event":"Banteg confirms Cronje has stopped tweeting due to death threats. The EMN Investigation group announces a crowdfund to finance a lawsuit against Cronje.","source":""},{"date":"2020-10-10","event":"Cronje resurfaces on Twitter: 'Still here. Still building. Nothing has changed.'","source":""},{"date":"2020-10-12","event":"Crowdfunding attempt for the EMN lawsuit fails to raise sufficient capital. No legal action proceeds.","source":""},{"date":"2020-10","event":"Cronje publishes clarification on the 'test in prod' statement, expressing regret over the phrase and stating it was intended as a caution, not a development methodology endorsement.","source":"","date_original":"2020-10-01"},{"date":"2022-03-06","event":"Cronje announces retirement from DeFi, citing personal toll of public development. Eminence Finance is never relaunched.","source":""}],"sources_used":[{"url":"https://decrypt.co/43203/hackers-drain-15-million-from-unreleased-yearn-finance-project","name":"decrypt.co","type":"other","archive_url":"http://web.archive.org/web/20260521103504/https://decrypt.co/43203/hackers-drain-15-million-from-unreleased-yearn-finance-project","credibility":3,"archive_timestamp":"2026-05-21T10:35:04+00:00"},{"url":"https://cointelegraph.com/news/hacker-steals-15m-after-degens-pile-into-unreleased-yearn-finance-project","name":"cointelegraph.com","type":"other","archive_url":"http://web.archive.org/web/20260729050205/https://cointelegraph.com/news/hacker-steals-15m-after-degens-pile-into-unreleased-yearn-finance-project","credibility":3,"archive_timestamp":"2026-07-29T05:02:05+00:00"},{"url":"https://cryptopotato.com/yearn-finance-foray-into-gaming-multiverse-results-in-15-million-contract-hack/","name":"cryptopotato.com","type":"other","archive_url":"http://web.archive.org/web/20260416231706/https://cryptopotato.com/yearn-finance-foray-into-gaming-multiverse-results-in-15-million-contract-hack/","credibility":3,"archive_timestamp":"2026-04-16T23:17:06+00:00"},{"url":"https://rekt.news/eminence-rekt-in-prod","name":"rekt.news","type":"other","archive_url":"http://web.archive.org/web/20260513160457/https://rekt.news/eminence-rekt-in-prod","credibility":3,"archive_timestamp":"2026-05-13T16:04:57+00:00"},{"url":"https://www.theblock.co/post/79061/yfi-eminence-defi-protocol-exploited","name":"theblock.co","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://coinrivet.com/defi-investors-lose-15-million-in-eminence-flash-loan-exploit/","name":"coinrivet.com","type":"other","archive_url":"https://web.archive.org/web/20260830083437/https://coinrivet.com/defi-investors-lose-15-million-in-eminence-flash-loan-exploit/","credibility":3,"archive_timestamp":"2026-08-30T08:34:37+00:00"},{"url":"https://cryptobriefing.com/unaudited-crypto-gaming-platform-eminence-hacked-15-million/","name":"cryptobriefing.com","type":"other","archive_url":"http://web.archive.org/web/20260114161111/https://cryptobriefing.com/unaudited-crypto-gaming-platform-eminence-hacked-15-million/","credibility":3,"archive_timestamp":"2026-01-14T16:11:11+00:00"},{"url":"https://etherscan.io/token/0x5ade7ae8660293f2ebfcefaba91d141d72d221e8","name":"etherscan.io","type":"other","archive_url":"https://web.archive.org/web/20260829192634/https://etherscan.io/token/0x5ade7ae8660293f2ebfcefaba91d141d72d221e8","credibility":3,"archive_timestamp":"2026-08-29T19:26:34+00:00"},{"url":"https://rekt.news/eminence-refund-do-or-dai/","name":"rekt.news","type":"other","archive_url":"http://web.archive.org/web/20260518010141/https://rekt.news/eminence-refund-do-or-dai","credibility":3,"archive_timestamp":"2026-05-18T01:01:41+00:00"},{"url":"https://www.coindesk.com/tech/2020/10/01/defi-degens-hit-hard-by-eminence-exploit-will-be-partially-compensated","name":"coindesk.com","type":"other","archive_url":"http://web.archive.org/web/20251026133728/https://www.coindesk.com/tech/2020/10/01/defi-degens-hit-hard-by-eminence-exploit-will-be-partially-compensated","credibility":3,"archive_timestamp":"2025-10-26T13:37:28+00:00"},{"url":"https://github.com/banteg/your-eminence","name":"github.com","type":"other","archive_url":"https://web.archive.org/web/20260901035952/https://github.com/banteg/your-eminence","credibility":3,"archive_timestamp":"2026-09-01T03:59:52+00:00"},{"url":"https://www.vidma.io/blog/the-eminence-hack-lessons-in-defi-security-and-smart-contract-vulnerabilities","name":"vidma.io","type":"other","archive_url":"http://web.archive.org/web/20260418200906/https://www.vidma.io/blog/the-eminence-hack-lessons-in-defi-security-and-smart-contract-vulnerabilities","credibility":3,"archive_timestamp":"2026-04-18T20:09:06+00:00"},{"url":"https://thedefiant.io/news/defi/andre-cronje-diehards-take-test-in-prod-over-the-edge-with-15m-hack","name":"thedefiant.io","type":"other","archive_url":"http://web.archive.org/web/20251230003219/https://thedefiant.io/news/defi/andre-cronje-diehards-take-test-in-prod-over-the-edge-with-15m-hack","credibility":3,"archive_timestamp":"2025-12-30T00:32:19+00:00"},{"url":"https://decrypt.co/43292/eminence-finance-exploit-leads-to-degen-soul-searching","name":"decrypt.co","type":"other","archive_url":"https://web.archive.org/web/20260830084910/https://decrypt.co/43292/eminence-finance-exploit-leads-to-degen-soul-searching","credibility":3,"archive_timestamp":"2026-08-30T08:49:10+00:00"},{"url":"https://www.theblock.co/post/81174/yfi-andre-cronje-clarifies-test-in-prod","name":"theblock.co","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://fullycrypto.com/emn-investigation-lawsuit-raises-responsibility-issue","name":"fullycrypto.com","type":"other","archive_url":"http://web.archive.org/web/20260305150417/https://fullycrypto.com/emn-investigation-lawsuit-raises-responsibility-issue","credibility":3,"archive_timestamp":"2026-03-05T15:04:17+00:00"},{"url":"https://cointelegraph.com/news/group-raising-funds-to-sue-andre-cronje-over-emn-hack","name":"cointelegraph.com","type":"other","archive_url":"http://web.archive.org/web/20260211101033/https://cointelegraph.com/news/group-raising-funds-to-sue-andre-cronje-over-emn-hack","credibility":3,"archive_timestamp":"2026-02-11T10:10:33+00:00"},{"url":"https://cryptonews.net/news/legal/396498/","name":"cryptonews.net","type":"other","archive_url":"https://web.archive.org/web/20260829192154/https://cryptonews.net/news/legal/396498/","credibility":3,"archive_timestamp":"2026-08-29T19:21:54+00:00"},{"url":"https://blockchain.news/news/yearn.finance-andre-cronje-sued-eminence-project-hack-death-threats","name":"blockchain.news","type":"other","archive_url":"http://web.archive.org/web/20260901071710/https://blockchain.news/news/yearn.finance-andre-cronje-sued-eminence-project-hack-death-threats","credibility":3,"archive_timestamp":"2026-09-01T07:17:10+00:00"},{"url":"https://cointelegraph.com/news/yfi-s-andre-cronje-disappeared-after-death-threats-will-love-bring-him-back","name":"cointelegraph.com","type":"other","archive_url":"http://web.archive.org/web/20260414031305/https://cointelegraph.com/news/yfi-s-andre-cronje-disappeared-after-death-threats-will-love-bring-him-back","credibility":3,"archive_timestamp":"2026-04-14T03:13:05+00:00"},{"url":"https://www.dlnews.com/articles/web3/andre-cronje-the-rise-and-fall-of-a-defi-god/","name":"dlnews.com","type":"other","archive_url":"http://web.archive.org/web/20260309093714/https://www.dlnews.com/articles/web3/andre-cronje-the-rise-and-fall-of-a-defi-god/","credibility":3,"archive_timestamp":"2026-03-09T09:37:14+00:00"},{"url":"https://www.coindesk.com/markets/2020/12/08/andre-cronje-defi-expressionist","name":"coindesk.com","type":"other","archive_url":"http://web.archive.org/web/20251025074557/https://www.coindesk.com/markets/2020/12/08/andre-cronje-defi-expressionist","credibility":3,"archive_timestamp":"2025-10-25T07:45:57+00:00"},{"url":"https://cryptotaxcalculator.io/blog/eminence-finance/","name":"cryptotaxcalculator.io","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:55:00.845331+00:00","updated_at":"2026-09-01T10:06:41.991246+00:00"}}