EasyFi Hack

REPORTED LOSS $59.0M
High Private Key Compromised (Unknown Method) ethereum polygon

What happened

EasyFi reported a 19 April 2021 attack in which an attacker remotely accessed the founder’s machine and obtained mnemonic and admin keys. Protocol pools on Ethereum and Polygon were drained; BSC pools were reported unaffected.

Technical Root Cause

The operator’s post-mortem attributes the incident to remote compromise of a founder device and exposed mnemonic/admin keys. It does not establish the malware or remote-access technique used.

Case & protocol details

Classification Infrastructure / Borrowing and Lending / Social Engineering
Protocol Type Exploit/Access control
Affected asset / contract EASY
Official Website easyfi.network/
Protocol Twitter/X @EasyfiNetwork

How it happened

  1. The attacker compromised the founder’s machine and accessed wallet and admin key material.
  2. Funds were removed from USDT, USDC, MATIC, ETH and DAI pools, and EASY token contracts were affected.
  3. EasyFi investigated, worked with forensics partners and proposed a token migration and recovery process.

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.