Harvest Finance Hack
What happened
Harvest Finance's USDC and USDT vaults lost about $33.8 million on October 26, 2020 when an attacker used flash-loaned stablecoins to move the Curve Y pool conditions used in Harvest's vault accounting. The attacker deposited while the manipulated valuation yielded excess fUSDC or fUSDT shares, reversed the Curve trade, and redeemed those shares at the restored valuation. The incident affected the USDC and USDT vaults, not Harvest's DAI, TUSD, WBTC, or renBTC vaults.
Harvest withdrew funds from the affected shared-pool strategies and later made funds returned by the attacker available to affected users alongside GRAIN claims.
Harvest's vault accounting used a real-time valuation derived from a Curve shared pool when minting and redeeming vault shares. That external pool state could be moved by a large same-transaction trade. The attacker exploited the resulting mismatch: shares were minted while the Curve-derived value was manipulated, then redeemed after the trade was reversed. The existing 3% arbitrage threshold allowed the approximately 1% USDC share-price movement used in the documented cycle.
Case & protocol details
Attack Timeline
Audit assessment
Review priorities based on the documented failure pattern in Harvest Finance (October 2020).
Critical checks
- Verify every sensitive logic path is guarded by appropriate access controls and input validation - see the Flash Loan Attacks attack class for patterns
- Audit oracle price feeds for manipulation risks - ensure time-weighted average prices (TWAPs) or multi-source aggregators are used, not spot prices
Funds Recovery
Recovered
$2.5M
Net Loss
$31,298,800
Evidence & learning
Proof of concept
1 availableSources and on-chain records
- report Post-mortem rekt.news
- report Post-mortem medium.com
- report Post-mortem medium.com
- transaction Transaction etherscan.io
- analysis Harvest GRAIN and recovery documentation docs.harvest.finance
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.