Harvest Keeper Hack

TOTAL LOST $933K
Low Rugpull ethereum

What happened

Harvest Keeper was rugpulled via privileged function. 929,595 $USD were stolen in total across three chains.

Harvest Keeper claimed to be an AI-powered trading platform running on Binance, Ethereum, and Polygon chains. The platform was rugpulled by the contract owner via the privileged function getAmount(). The function allowed the contract owner to drain all remaining $USDT from the project's contract.

710,595 $USDT was siphoned out in a single transaction this way. 219,000 $USD worth of assets were stolen via ice phishing and then exploiting user approvals across Binance, Ethereum, and Polygon chains in addition. All the stolen funds were transferred through multiple EOA addresses.

Attacker addresses:

https://bscscan.com/address/0x027c83d2…95ade8

https://bscscan.com/address/0x250ce5a8…710c14

Malicious transaction:

https://bscscan.com/tx/0x3c9e53a9…a8809b

Approval exploits transaction example:

https://bscscan.com/tx/0x12f1def8…896f7a

Case & protocol details

Classification Yield Aggregator / Rugpull
Protocol Type Exit Scam/Rugpull
Smart Contract Language Solidity
Official Website harvest-keeper.app/
Protocol Twitter/X @harvest_keeper

Evidence & learning

Sources and on-chain records

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.