Bent Finance hack — December 2021
Incident facts
| Date of incident | (approximate) |
|---|---|
| Publicly disclosed | December 21, 2021 |
| Target type | Other |
| Loss | $1,750,000Published estimates range $1,600,000 to $2,100,000Price at time of incident |
| Method | Insider actionAn unverified contract update pushed from the project's own deployer address hardcoded an enormous cvxCRV/MIM balance for a controlled address; verified code was redeployed afterwards to conceal the change, and the fabricated balance was later used to claim rewards far exceeding any deposit. Contracts had not yet been moved behind a multisig. |
| Chains | Ethereum |
| Outcome | Users reimbursed |
What happened
Bent Finance, a yield optimiser built on top of Curve and Convex, disclosed on 21 December 2021 that funds had been drained from its cvxCRV and MIM reward pools. The protocol said the transactions originated from its own deployer address, which roughly three weeks earlier had pushed an unverified contract update assigning a very large token balance to an address the updater controlled. That hardcoded balance allowed the holder to claim rewards far in excess of anything deposited. Verified code was redeployed afterwards, hiding the change until anomalies in reward distribution were noticed.
Withdrawals ran from around 12 December until roughly 04:50 UTC on 21 December 2021. Published losses vary. Fraud investigator Joe McGill counted about 440 ETH, worth over $1.6 million at the time. Token-denominated accounts put it at roughly 512,700 cvxCRV, valued in different reports at between $1.75 million and $2.1 million.
Bent Finance disabled reward claims, told users to withdraw, and said it consulted outside researchers, including samczsun, before concluding the update had been inserted by someone with internal access. The project's contracts were mid-migration to multisig ownership at the time. No individual has been named, charged, or has admitted responsibility, so the insider account rests on the project's own conclusion and on PeckShield's observation that the activity came from the deployer address.
Within days the party holding the funds returned assets to a project multisig. Because the returned mix of ETH and DAI fell short of the token value, community members contributed a further 200,000 cvxCRV. Bent Finance said reimbursement of 512,696.06 cvxCRV-f was paid in full on 24 December 2021.
Sources
- HalbornSecondary · retrieved 2026-08-01
- CointelegraphSecondary · retrieved 2026-08-01
- CryptoPotatoSecondary · retrieved 2026-08-01
- CoinCodeCapSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Bent Finance hack — December 2021", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/bent-financehttps://itokenly.com/hacks/bent-financePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.