Summary
Beanstalk is an Ethereum-based algorithmic stablecoin protocol that on April 17, 2022 suffered one of DeFi's largest governance exploits, losing approximately $182 million after an attacker used flash loans to acquire a supermajority vote and pass a malicious proposal draining the protocol's treasury. The protocol relaunched in August 2022 following a community fundraiser called the Barn Raise, but its BEAN stablecoin has never recovered its peg and total value locked remains a fraction of pre-exploit levels.
Connected Entities
1 entitiesTimeline(11 events)
2021-08-06
Beanstalk protocol launched on Ethereum mainnet by pseudonymous founders 'Publius' (Benjamin Weintraub, Brendan Sanderson, Michael Montoya).
2022-04-16
Attacker submits malicious BIP-18 and BIP-19 governance proposals to Beanstalk, initiating the required 24-hour governance delay.
2022-04-17
At approximately 12:24 PM UTC, attacker executes flash loan attack using over $1 billion borrowed from Aave, acquires ~79% of governance votes, passes BIP-18 via emergencyCommit, and drains approximately $182 million from the protocol. Approximately 24,930 ETH ($76M net profit) is transferred to Tornado Cash in 270 transactions.
2022-04-18
Beanstalk Farms team pauses the protocol, disables on-chain governance, and transfers control to a community multisig. Founders reveal their identities on Discord to dispel complicity concerns.
2022-04-18
Beanstalk Farms sends on-chain message offering attacker a 10% whitehat bounty in exchange for returning 90% of funds. Attacker does not respond.
2022-06-06
Barn Raise fundraiser launches, targeting $77 million in recapitalization via Fertilizer token sales.
2022-08-04
BIP-21 (the Replant proposal) reaches supermajority. Barn Raise has attracted over $17 million USDC — approximately 22% of the target.
2022-08-06
Beanstalk protocol officially relaunches ('Replant') with governance under community multisig and restructured tokenomics.
2024-04-01
Cyfrin conducts security audit of Beanstalk 2 upgrade, including BEAN:wstETH liquidity whitelisting.
2024-05-01
Cyfrin conducts security audit of Beanstalk 3, which includes plans for Ethereum L2 migration.
2025-05-01
BEAN trades at approximately $0.23 (77% below peg). Protocol TVL approximately $9 million. Attacker identity remains unknown; stolen funds unrecovered.
Decision Log
- hash: 67VAbsxWX3fVrMu3VWJhZs47MNgtaDUeoVVzc2ZSDh8N
This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.
model: claude-sonnet-4-6
generated: 5/4/2026, 2:54:49 AM
last updated: 5/19/2026, 9:12:20 PM
avoid.net — verified advice for a post-truth world