{"investigation":{"slug":"harvest-finance","entity_name":"Harvest Finance","trust_score":22,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"Harvest Finance is a decentralized yield-aggregation protocol (token: FARM) that suffered a landmark $33.8 million flash loan-based price manipulation attack on October 26, 2020, one of the largest DeFi exploits of that year. Pre-attack, the protocol held over $1 billion in TVL while being governed by a single anonymous admin key—a concentration of power flagged by multiple security auditors and researchers. The protocol continues to operate with substantially reduced TVL (~$12 million as of 2025), though the stolen funds were never recovered and the attacker was never publicly identified or charged.","sections":[{"content":"On October 26, 2020, an unidentified attacker executed a sophisticated arbitrage attack against Harvest Finance's USDC and USDT vaults, draining approximately $33.8 million in stablecoins. The attacker obtained a $50 million USDC flash loan from Uniswap and repeatedly swapped between USDC and USDT on Curve Finance's Y pool to manipulate the relative prices of the two assets. Because Harvest Finance's fToken (vault share token) pricing mechanism relied on Curve pool spot prices rather than time-weighted averages, the attacker was able to deposit into Harvest vaults at artificially favorable exchange rates, withdraw at the corrected rate, and pocket the difference. The cycle was repeated 17 times against the USDC vault and 13 times against the USDT vault, with the entire operation completing in under seven minutes. The Harvest team publicly attributed the incident to an 'engineering error' and acknowledged fault. Approximately $2.5 million was voluntarily returned by the attacker to the Harvest deployer address for reasons that were never explained; the remainder was converted to renBTC and moved across multiple exchanges including Binance, Kraken, Huobi, and BitMEX before being partially routed through the Wasabi wallet mixing service. The FARM token dropped approximately 65% within one hour of the attack becoming public.","heading":"October 2020 Flash Loan Price Manipulation Attack","sources":[{"url":"https://www.coindesk.com/tech/2020/10/26/harvest-finance-24m-attack-triggers-570m-bank-run-in-latest-defi-exploit","name":"coindesk.com","type":"other","credibility":3},{"url":"https://decrypt.co/46445/engineering-error-34-million-defi-hack-harvest-finance","name":"decrypt.co","type":"other","credibility":3},{"url":"https://www.theblock.co/post/82292/defi-protocol-harvest-finance-exploited","name":"theblock.co","type":"other","credibility":3},{"url":"https://slowmist.medium.com/slow-mist-analysis-of-harvest-finances-hacked-event-63450b49e6a5","name":"slowmist.medium.com","type":"other","credibility":3},{"url":"https://www.scorechain.com/blog/5-days-after-the-harvest-finance-hack-what-we-know-so-far","name":"scorechain.com","type":"other","credibility":3},{"url":"https://immunebytes.com/blog/harvest-finance-fund-theft-incident-oct-26-2020-detailed-analysis/","name":"immunebytes.com","type":"other","credibility":3}],"severity":"medium"},{"content":"In the twelve hours following the exploit, Harvest Finance's total value locked fell from over $1 billion to approximately $430 million—a decline of more than $570 million—as depositors withdrew funds in a cascading bank run. The platform's native FARM governance token fell from approximately $242 to near $100 within hours. The scale of the bank run was notable: the direct loss to the attacker was $33.8 million, but the broader market impact was measured in the hundreds of millions. This episode was frequently cited in subsequent DeFi security literature as an example of how user confidence can collapse independently of the technical scope of an exploit.","heading":"Bank Run and TVL Collapse","sources":[{"url":"https://www.coindesk.com/tech/2020/10/26/harvest-finance-24m-attack-triggers-570m-bank-run-in-latest-defi-exploit","name":"coindesk.com","type":"other","credibility":3},{"url":"https://thedefiant.io/news/defi/harvest-finance-grapples-to-make-users-whole-after-34m-hack","name":"thedefiant.io","type":"other","credibility":3}],"severity":"medium"},{"content":"Prior to the October 2020 attack, Harvest Finance was publicly criticized for operating a protocol holding over $1 billion in user funds under the control of a single externally owned Ethereum account (EOA) operated by an entirely anonymous development team. Security auditors PeckShield and Haechi Labs, who completed audits in September 2020, both flagged that governance functions were assigned to a single EOA—the deployer address 0xf00d—rather than a multisig or DAO structure. PeckShield's report explicitly noted this 'raises necessary concerns,' and identified that the admin key holder could arbitrarily mint new FARM tokens and modify vault strategies to redirect user funds to an attacker-controlled address. Independent researcher Chris Blec documented the centralization risk in detail, reporting that when he raised these concerns publicly, he was allegedly harassed, banned from the project's Discord, and blocked on Twitter. In response to community pressure, the team implemented a 12-hour timelock dashboard to give users advance notice of contract changes—a measure critics regarded as insufficient. Unlike comparable protocols such as Yearn Finance and SushiSwap, which distributed multisig signing authority among named community members, Harvest Finance's developers declined to adopt multisig governance and refused to reveal their identities.","heading":"Anonymous Team and Governance Centralization","sources":[{"url":"https://cointelegraph.com/news/anonymous-devs-behind-a-defi-yield-farm-could-steal-1b-in-12-hours","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://cryptobriefing.com/harvest-finance-developers-adamant-keeping-1-billion-project-centralized/","name":"cryptobriefing.com","type":"other","credibility":3},{"url":"https://survivingdefi.substack.com/p/hunting-harvests-admin-key","name":"survivingdefi.substack.com","type":"other","credibility":3},{"url":"https://finxflo.medium.com/what-did-we-learn-about-anonymity-from-the-harvest-finance-24-million-hack-eb608d070e2f","name":"finxflo.medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The Harvest Finance team stated publicly that the attacker was 'well-known in the crypto community' and that they had collected 'a significant amount of personally identifiable information' on the individual. The team explicitly declined to publicly identify the attacker, stating 'we are not interested in doxxing the attacker.' In coordination with Ren Protocol, the team identified ten Bitcoin wallet addresses holding the stolen funds and requested that Binance, Coinbase, Kraken, and other exchanges freeze them. Despite these efforts, the bulk of the stolen funds were moved through mixer services and across multiple exchanges and were not recovered. No public criminal charges or civil proceedings related to the attacker have been reported. The team raised the bounty for information leading to fund recovery from $100,000 to $400,000 and ultimately to $1 million, but no recovery of the remaining approximately $31 million has been publicly confirmed.","heading":"Attacker Identity and Fund Recovery","sources":[{"url":"https://www.coindesk.com/tech/2020/10/29/harvest-finance-boosts-bounty-to-1m-for-information-leading-to-return-of-exploited-funds","name":"coindesk.com","type":"other","credibility":3},{"url":"https://securityaffairs.com/110043/cyber-crime/harvest-finance-cyber-heist.html","name":"securityaffairs.com","type":"other","credibility":3},{"url":"https://decrypt.co/46303/harvest-finance-issue-100000-bounty-on-hacker","name":"decrypt.co","type":"other","credibility":3},{"url":"https://www.scorechain.com/blog/5-days-after-the-harvest-finance-hack-what-we-know-so-far","name":"scorechain.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the exploit, the Harvest Finance community voted to issue a reparations token called GRAIN (an IOU instrument) to affected USDC and USDT vault depositors. GRAIN was structured so that 1 GRAIN represented $1 of protocol debt to the affected user. Affected users received GRAIN in proportion to their share of the approximately 13.5% drawdown suffered during the attack, along with a proportional share of the $2.5 million returned by the attacker. The protocol committed to directing 0.5% of total weekly FARM token emissions to a buyback pool that would redeem GRAIN at $1 until the full loss was recovered. A claims portal launched on December 7, 2020. Whether the GRAIN buyback program has fully compensated affected users—given the substantial decline in FARM token price and protocol revenue since 2020—is not confirmed in available sources.","heading":"GRAIN Token Compensation Mechanism","sources":[{"url":"https://medium.com/harvest-finance/announcing-the-grain-claims-portal-20dd12c4f631","name":"medium.com","type":"other","credibility":3},{"url":"https://docs.harvest.finance/general-info/security/grain-token","name":"docs.harvest.finance","type":"other","credibility":3},{"url":"https://x.com/harvest_finance/status/1325676438721351681","name":"x.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Harvest Finance underwent multiple third-party security audits. PeckShield and Haechi Labs completed audits in September 2020, shortly before the exploit. CertiK conducted an audit from September 16 to October 2, 2020, and Least Authority audited smart contracts from November 2020 through February 2021. The PeckShield audit found no critical bugs in the smart contract business logic but prominently flagged the centralized admin key as a governance concern. Haechi Labs identified one major issue (described as already fixed at the time of publication) and five minor issues, several of which the team classified as intentional design choices. Notably, none of the pre-attack audits identified the specific price-oracle vulnerability that was ultimately exploited in October 2020, which involved the use of manipulable spot prices from Curve pools rather than time-weighted average prices.","heading":"Security Audit Findings","sources":[{"url":"https://docs.harvest.finance/other/security/audites","name":"docs.harvest.finance","type":"other","credibility":3},{"url":"https://leastauthority.com/blog/audit-of-harvest-smart-contracts-for-harvest-finance/","name":"leastauthority.com","type":"other","credibility":3},{"url":"https://farm.chainwiki.dev/en/security","name":"farm.chainwiki.dev","type":"other","credibility":3}],"severity":"medium"},{"content":"As of mid-2025, Harvest Finance continues to operate as a yield aggregation protocol across five blockchain networks: Ethereum, Base, Arbitrum, Polygon, and ZKsync Era. According to DeFiLlama data, total value locked stands at approximately $12.1 million—a fraction of its pre-hack $1 billion peak. The FARM token trades near its all-time low of approximately $6–$9, with a market capitalization of approximately $4–5 million. The protocol's largest deployment is on the Base network ($7.5 million TVL), where it operates a cbBTC vault in partnership with Moonwell DeFi. The anonymous founding team has not publicly identified themselves. No further security incidents of comparable scale to the 2020 exploit have been publicly reported, though the protocol remains relatively low-traffic compared to leading yield aggregators.","heading":"Current Protocol Status","sources":[{"url":"https://defillama.com/protocol/harvest-finance","name":"defillama.com","type":"other","credibility":3},{"url":"https://coinmarketcap.com/currencies/harvest-finance/","name":"coinmarketcap.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2020-09","event":"Harvest Finance launches FARM token and begins yield aggregation operations; quickly accumulates over $1 billion in TVL.","source":"","date_original":"2020-09-01"},{"date":"2020-09-16","event":"CertiK security audit begins; PeckShield and Haechi Labs audits also completed around this period, flagging single admin key governance risk.","source":""},{"date":"2020-10-20","event":"Researcher Chris Blec publicly documents Harvest Finance admin key centralization risks and reports being banned from the project's Discord after raising concerns.","source":""},{"date":"2020-10-26","event":"Flash loan price manipulation attack drains approximately $33.8 million from USDC and USDT vaults in under seven minutes. FARM token drops 65% within an hour. $570 million in TVL exits the platform within 12 hours.","source":""},{"date":"2020-10-26","event":"Attacker voluntarily returns approximately $2.5 million in USDC/USDT to the Harvest deployer address; motive is not explained.","source":""},{"date":"2020-10-26","event":"Harvest Finance offers a $100,000 bounty (raised to $400,000 within 36 hours) for information leading to return of stolen funds.","source":""},{"date":"2020-10-27","event":"Stolen funds begin moving through major exchanges including Binance, Kraken, Huobi, and BitMEX after being converted to Bitcoin via renBTC.","source":""},{"date":"2020-10-29","event":"Harvest Finance raises bounty to $1 million for information leading to recovery of exploited funds.","source":""},{"date":"2020-11","event":"Stolen Bitcoin traced through the Wasabi wallet mixing service; approximately 169 BTC remains unspent in tracked addresses at this date.","source":"","date_original":"2020-11-01"},{"date":"2020-11-30","event":"Least Authority begins smart contract audit of Harvest Finance; audit concludes February 2021.","source":""},{"date":"2020-12-07","event":"GRAIN token claims portal launches, allowing affected USDC/USDT vault users to claim reparation tokens proportional to their loss.","source":""},{"date":"2021","event":"Harvest Finance continues operations; GRAIN buyback program is ongoing but full restitution of the approximately $31 million remaining loss is unconfirmed.","source":"","date_original":"2021-01-01"},{"date":"2025","event":"Protocol operates with approximately $12.1 million TVL across five chains, primarily on Base network. FARM token trades near all-time lows. Anonymous team has not disclosed identities.","source":"","date_original":"2025-01-01"}],"sources_used":[{"url":"https://www.coindesk.com/tech/2020/10/26/harvest-finance-24m-attack-triggers-570m-bank-run-in-latest-defi-exploit","name":"coindesk.com","type":"other","archive_url":"https://web.archive.org/web/20260915185751/https://www.coindesk.com/tech/2020/10/26/harvest-finance-24m-attack-triggers-570m-bank-run-in-latest-defi-exploit","credibility":3,"archive_timestamp":"2026-09-15T18:57:51+00:00"},{"url":"https://decrypt.co/46445/engineering-error-34-million-defi-hack-harvest-finance","name":"decrypt.co","type":"other","archive_url":"http://web.archive.org/web/20260611095240/https://decrypt.co/46445/engineering-error-34-million-defi-hack-harvest-finance","credibility":3,"archive_timestamp":"2026-06-11T09:52:40+00:00"},{"url":"https://www.theblock.co/post/82292/defi-protocol-harvest-finance-exploited","name":"theblock.co","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://slowmist.medium.com/slow-mist-analysis-of-harvest-finances-hacked-event-63450b49e6a5","name":"slowmist.medium.com","type":"other","archive_url":"http://web.archive.org/web/20250909132028/https://slowmist.medium.com/slow-mist-analysis-of-harvest-finances-hacked-event-63450b49e6a5","credibility":3,"archive_timestamp":"2025-09-09T13:20:28+00:00"},{"url":"https://www.scorechain.com/blog/5-days-after-the-harvest-finance-hack-what-we-know-so-far","name":"scorechain.com","type":"other","archive_url":"http://web.archive.org/web/20260511024330/https://www.scorechain.com/blog/5-days-after-the-harvest-finance-hack-what-we-know-so-far","credibility":3,"archive_timestamp":"2026-05-11T02:43:30+00:00"},{"url":"https://immunebytes.com/blog/harvest-finance-fund-theft-incident-oct-26-2020-detailed-analysis/","name":"immunebytes.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://thedefiant.io/news/defi/harvest-finance-grapples-to-make-users-whole-after-34m-hack","name":"thedefiant.io","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://cointelegraph.com/news/anonymous-devs-behind-a-defi-yield-farm-could-steal-1b-in-12-hours","name":"cointelegraph.com","type":"other","archive_url":"http://web.archive.org/web/20260308131736/https://cointelegraph.com/news/anonymous-devs-behind-a-defi-yield-farm-could-steal-1b-in-12-hours","credibility":3,"archive_timestamp":"2026-03-08T13:17:36+00:00"},{"url":"https://cryptobriefing.com/harvest-finance-developers-adamant-keeping-1-billion-project-centralized/","name":"cryptobriefing.com","type":"other","archive_url":"http://web.archive.org/web/20251206114539/https://cryptobriefing.com/harvest-finance-developers-adamant-keeping-1-billion-project-centralized/","credibility":3,"archive_timestamp":"2025-12-06T11:45:39+00:00"},{"url":"https://survivingdefi.substack.com/p/hunting-harvests-admin-key","name":"survivingdefi.substack.com","type":"other","archive_url":"https://web.archive.org/web/20260829195331/https://survivingdefi.substack.com/p/hunting-harvests-admin-key","credibility":3,"archive_timestamp":"2026-08-29T19:53:31+00:00"},{"url":"https://finxflo.medium.com/what-did-we-learn-about-anonymity-from-the-harvest-finance-24-million-hack-eb608d070e2f","name":"finxflo.medium.com","type":"other","archive_url":"http://web.archive.org/web/20250831004637/https://finxflo.medium.com/what-did-we-learn-about-anonymity-from-the-harvest-finance-24-million-hack-eb608d070e2f","credibility":3,"archive_timestamp":"2025-08-31T00:46:37+00:00"},{"url":"https://www.coindesk.com/tech/2020/10/29/harvest-finance-boosts-bounty-to-1m-for-information-leading-to-return-of-exploited-funds","name":"coindesk.com","type":"other","archive_url":"https://web.archive.org/web/20260915185839/https://www.coindesk.com/tech/2020/10/29/harvest-finance-boosts-bounty-to-1m-for-information-leading-to-return-of-exploited-funds","credibility":3,"archive_timestamp":"2026-09-15T18:58:39+00:00"},{"url":"https://securityaffairs.com/110043/cyber-crime/harvest-finance-cyber-heist.html","name":"securityaffairs.com","type":"other","archive_url":"http://web.archive.org/web/20260314052213/https://securityaffairs.com/110043/cyber-crime/harvest-finance-cyber-heist.html","credibility":3,"archive_timestamp":"2026-03-14T05:22:13+00:00"},{"url":"https://decrypt.co/46303/harvest-finance-issue-100000-bounty-on-hacker","name":"decrypt.co","type":"other","archive_url":"http://web.archive.org/web/20260420192359/https://decrypt.co/46303/harvest-finance-issue-100000-bounty-on-hacker","credibility":3,"archive_timestamp":"2026-04-20T19:23:59+00:00"},{"url":"https://medium.com/harvest-finance/announcing-the-grain-claims-portal-20dd12c4f631","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://docs.harvest.finance/general-info/security/grain-token","name":"docs.harvest.finance","type":"other","archive_url":null,"credibility":3,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://x.com/harvest_finance/status/1325676438721351681","name":"x.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://docs.harvest.finance/other/security/audites","name":"docs.harvest.finance","type":"other","archive_url":"http://web.archive.org/web/20260609153732/https://docs.harvest.finance/other/security/audites","credibility":3,"archive_timestamp":"2026-06-09T15:37:32+00:00"},{"url":"https://leastauthority.com/blog/audit-of-harvest-smart-contracts-for-harvest-finance/","name":"leastauthority.com","type":"other","archive_url":"https://web.archive.org/web/20260829193658/https://leastauthority.com/blog/audit-of-harvest-smart-contracts-for-harvest-finance/","credibility":3,"archive_timestamp":"2026-08-29T19:36:58+00:00"},{"url":"https://farm.chainwiki.dev/en/security","name":"farm.chainwiki.dev","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://defillama.com/protocol/harvest-finance","name":"defillama.com","type":"other","archive_url":"http://web.archive.org/web/20250917030052/https://defillama.com/protocol/harvest-finance","credibility":3,"archive_timestamp":"2025-09-17T03:00:52+00:00"},{"url":"https://coinmarketcap.com/currencies/harvest-finance/","name":"coinmarketcap.com","type":"other","archive_url":"http://web.archive.org/web/20260113052240/https://coinmarketcap.com/currencies/harvest-finance/","credibility":3,"archive_timestamp":"2026-01-13T05:22:40+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:55:00.635903+00:00","updated_at":"2026-09-15T19:04:32.268345+00:00"}}