T
iTokenly

bEarn Fi hack — May 2021

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedMay 16, 2021
Target typeOther
Loss$10,850,000Published estimates range $10,850,000 to $18,000,000Price at time of incident
MethodContract logic errorInconsistent asset denomination between the BvaultsBank vault contract and the BvaultsStrategy it delegated to. BvaultsBank's withdraw(address, uint256 wantAmount) treated the amount as denominated in BUSD while the strategy treated the same number as denominated in ibBUSD, Alpaca Finance's interest-bearing receipt token, which was worth more. A flash loan from Cream Finance supplied the capital to cycle deposits and withdrawals through the mismatch 26 times.
ChainsBNB Chain
OutcomeUnresolved

What happened

On 16 May 2021, beginning at 10:36 UTC, an attacker drained the BvaultsBank contract of bEarn Fi, a yield aggregator on BNB Chain. Reported losses range from about $10.85 million to $18 million: CryptoSlate put the drain at $10.85 million in BUSD from the BUSD Alpaca strategy vault, PeckShield, which analysed the incident, at roughly $11 million, and rekt.news at $18 million without explaining how that larger figure is reached. This entry records $10.85 million as the best-documented number and $18 million as the upper bound.

The flaw was a mismatch in units between two contracts. BvaultsBank's withdraw function treated the requested amount as denominated in BUSD, while the BvaultsStrategy it called through treated the same number as denominated in ibBUSD, the interest-bearing receipt token issued by Alpaca Finance. Because one ibBUSD was worth more than one BUSD, a request to withdraw 100 BUSD caused 100 ibBUSD to be pulled out instead. The attacker borrowed 7,804,239 BUSD from Cream Finance in a flash loan and cycled deposits and withdrawals through the vault 26 times, taking out more than was put in on each pass, before repaying the loan. bEarn attributed the cause to the improper implementation of the withdraw function, saying it had passed the withdraw method from the FairLaunch contract with a BUSD amount where an ibBUSD amount should have been used.

Within hours bEarn announced compensation worth 105 per cent of losses: 87.5 per cent in BUSD and 7.5 per cent in BDOv2 immediately, plus 10 per cent in BDEX vested over 80 weeks, funded from remaining protocol assets, the developer and DAO funds, and a share of future protocol fees. The speed of the pledge drew criticism from Yearn Finance developer banteg, who argued that promising full compensation hours after a hack creates a distorted perception of risk for users and hurts the adoption of insurance protocols. The stolen funds were not recovered and the attacker was not identified.

Sources

  1. PeckShieldSecondary · retrieved 2026-08-01
  2. CoinDeskSecondary · retrieved 2026-08-01
  3. CryptoSlateSecondary · retrieved 2026-08-01
  4. rekt.newsSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "bEarn Fi hack — May 2021", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/bearn-fi
https://itokenly.com/hacks/bearn-fi

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.