Reaper Farm Hack

TOTAL LOST $1.7M
Medium Access Control Attacks fantom

What happened

The Reaper Farm protocol was hacked due to the lack of validation checks, as a result of which user funds were withdrawn to the attacker's account.

Reaper is an auto-compounding yield farm that maximizes users' yields by leveraging the power of compound interest.

The Reaper Farm protocol had a lack of validation check, which the attacker took advantage of, stealing $1.7M.

The attacker created a smart contract (https://ftmscan.com/tx/0xe7635f32…bdc607 ) which was used to withdraw funds from the protocol to the attacker address (B).

Example transactions:

  1. Tx
  2. Tx
  3. Tx

Full list of transactions: https://ftmscan.com/token/0x04068da6…5d5b75?a=0x2c177d20…9ca954

Then all stolen tokens were bridged from FTM to ETH.

Example transactions:

  1. Tx
  2. Tx
  3. Tx

Then all funds were laundered via Tornado.Cash.

Attacker addresses:

(FTM) scammer address(A): https://ftmscan.com/address/0x5636e55e…bb527a

(FTM) scammer address(B): https://ftmscan.com/address/0x2c177d20…9ca954

(ETH) scammer address(B): https://etherscan.io/address/0x2c177d20…9ca954

Attacker's contract address: https://ftmscan.com/address/0x8162a5e1…4d0145

Case & protocol details

Classification Yield Aggregator / Access Control
Protocol Type Yield Aggregator
Smart Contract Language Solidity
Official Website www.reaper.farm/
Protocol Twitter/X @Reaper_Farm

Security review history

Evidence & learning

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.