T
iTokenly

Beanstalk hack — April 2022

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Target typeStablecoin or yield protocol
Loss$77,000,000Published estimates range $76,000,000 to $77,000,000Price at time of incident
MethodGovernance attackflash-loan-funded supermajority used to vote and execute a malicious proposal in one transaction via emergencyCommit
ChainsEthereum
OutcomeProject relaunched

What happened

Beanstalk, a credit-based algorithmic stablecoin protocol on Ethereum, was drained at roughly 12:24 UTC on 17 April 2022 through its own governance process.

The day before, the attacker had submitted two proposals: BIP-18, which transferred the protocol's assets to an address they controlled, and BIP-19, a $250,000 donation to Ukraine's official crypto donation address. Beanstalk imposed a one-day delay before a proposal could execute, but its emergencyCommit function allowed a proposal holding a two-thirds supermajority to be voted on and executed inside a single transaction. When the delay elapsed the attacker took flash loans of 350 million DAI, 500 million USDC and 150 million USDT from Aave, roughly $32 million in BEAN from Uniswap V2 and nearly $12 million in LUSD from SushiSwap, over $1 billion in total, converted them into Curve LP positions deposited in the Silo, cleared the two-thirds voting threshold, called emergencyCommit on BIP-18, drained the liquidity pools, repaid the loans and exited in one block.

Two different quantities circulate and are not interchangeable. The figure of roughly $181-182 million is the protocol's total value destroyed, including BEAN that became worthless; Immunefi puts it at $181 million and Elliptic at $182 million. What the attacker actually removed was smaller: Beanstalk's own statement describes about $77 million in non-Beanstalk user assets, Elliptic traced just under 25,000 ETH worth about $76 million, and Immunefi puts the retained non-BEAN assets at around $77 million, the rest having been burned by the team. The amount fields in this record track the attacker's take.

The proceeds went through Tornado Cash. The Ukraine donation executed, though sources differ on the asset: Immunefi describes BIP-19 as sending $250,000 in BEAN, while Elliptic reports $250,000 in USDC arriving at the Crypto Fund of Ukraine. No suspect has been publicly identified. Beanstalk recapitalised through the Barn Raise, completed audits with Halborn and Trail of Bits, and unpaused under BIP-21, which was proposed on 29 July 2022, concluded voting on 5 August and scheduled the unpause for 6 August 2022.

Sources

  1. Beanstalk FarmsPrimary · retrieved 2026-08-01
  2. Beanstalk FarmsPrimary · retrieved 2026-08-01
  3. EllipticSecondary · retrieved 2026-08-01
  4. ImmunefiSecondary · retrieved 2026-08-01

Official post-mortem: https://bean.money/blog/beanstalk-governance-exploit

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Beanstalk hack — April 2022", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/beanstalk
https://itokenly.com/hacks/beanstalk

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.