Harvest Finance Hack

TOTAL LOST $33.8M
High Flash-loan-funded Curve Y pool price manipulation and vault-share accounting arbitrage Ethereum
Chain Ethereum Primary network
Recovered $2.5M 7.4% returned
Loss Rank #173 All-time
Audit Firms 2 Before incident

What happened

Harvest Finance's USDC and USDT vaults lost about $33.8 million on October 26, 2020 when an attacker used flash-loaned stablecoins to move the Curve Y pool conditions used in Harvest's vault accounting. The attacker deposited while the manipulated valuation yielded excess fUSDC or fUSDT shares, reversed the Curve trade, and redeemed those shares at the restored valuation. The incident affected the USDC and USDT vaults, not Harvest's DAI, TUSD, WBTC, or renBTC vaults.

Harvest withdrew funds from the affected shared-pool strategies and later made funds returned by the attacker available to affected users alongside GRAIN claims.

Technical Root Cause

Harvest's vault accounting used a real-time valuation derived from a Curve shared pool when minting and redeeming vault shares. That external pool state could be moved by a large same-transaction trade. The attacker exploited the resulting mismatch: shares were minted while the Curve-derived value was manipulated, then redeemed after the trade was reversed. The existing 3% arbitrage threshold allowed the approximately 1% USDC share-price movement used in the documented cycle.

Case & protocol details

Classification Oracle manipulation / manipulable market-price dependency
Protocol Type Yield Aggregator
Affected asset / contract FARM
Smart Contract Language Solidity
Official Website harvest.finance/
Protocol Twitter/X @harvest_finance
Team Anonymous
Source Code Unverified

Market Context at Time of Hack

Token Categories
DeFi DAO Ethereum Ecosystem Yield Farming Yield Aggregator Governance Polygon Ecosystem BNB Chain Ecosystem

Attack Timeline

The attacker borrowed large USDC and USDT balances within the attack flow, then made a large Curve Y pool swap that temporarily changed the value Harvest used for an individual stablecoin position. With that value distorted, the attacker deposited into a Harvest vault and received more vault shares than the deposit should have produced at an unmanipulated valuation. The attacker then reversed the Curve swap and withdrew the Harvest shares at the restored valuation. The pattern was repeated across USDC and USDT vault transactions over roughly seven minutes.

Audit assessment

Review priorities based on the documented failure pattern in Harvest Finance (October 2020).

Critical checks

  • Verify every sensitive logic path is guarded by appropriate access controls and input validation - see the Flash Loan Attacks attack class for patterns
  • Audit oracle price feeds for manipulation risks - ensure time-weighted average prices (TWAPs) or multi-source aggregators are used, not spot prices

Review history

A prior review is not a guarantee of safety, particularly when code changes after the reviewed version.

Funds Recovery

7.4%

Recovered

$2.5M

Net Loss

$31,298,800

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.