T
iTokenly

Growth DeFi hack — February 2021

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident(approximate)
Publicly disclosedFebruary 8, 2021
Target typeOther
Loss$1,400,000Price at time of incident
MethodContract logic errorThe single-asset deposit function of the stkGRO/rAAVE staking contract accepted a token address and a Uniswap pool address without checking that the token was one of the two assets in that pool. The attacker supplied a worthless token and a fake liquidity pool, and the contract credited the resulting fake LP shares as genuine GRO/rAAVE LP shares, minting staking shares against no real reserve. No flash loan was used and no price oracle was manipulated.
ChainsEthereum
OutcomePartially recovered

What happened

Growth DeFi was exploited on 8 February 2021 through the single-asset deposit function of its stkGRO/rAAVE staking contract on Ethereum. The team's post-mortem, published the same day, described the flaw precisely: the function accepted a token address and a Uniswap pool address without checking that the token was one of the two assets in the pool.

The attacker created a worthless ERC-20, paired it with GRO in a Uniswap V2 pool, and deposited it. The contract routed the deposit through the fake pool and credited the resulting fake LP shares as if they were genuine GRO/rAAVE LP shares, minting staking shares against no additional reserve. The attacker redeemed those shares for real GRO/rAAVE LP tokens, removed the liquidity to obtain GRO and rAAVE, and sold them on Uniswap for roughly 800 ETH in total. Growth DeFi withdrew the remaining treasury liquidity from the staking contracts once it detected the attack.

This incident is often filed as a flash loan or price oracle attack, and Smart Contract Hacking tags it that way. Neither description matches the post-mortem, and Smart Contract Hacking's own narrative describes no flash loan and no oracle step: the root cause was missing input validation on the token/pool pair.

The total drained is reported as $1.4 million, of which the team said 12 percent, or $168,000, belonged to users rather than the protocol treasury. It issued $168,000 of SAFE tokens pro rata to pre-exploit stakers, to be bought back at up to $1 each out of future protocol fees, and migrated rAAVE to a new non-rebasing token, PMINE. This was a deferred buyback commitment contingent on future revenue, not an immediate repayment, and covered only the user-owned share; there is no public confirmation that the buyback was completed.

No individual or group has been named as responsible.

Sources

  1. GROWTH DeFi (official post-mortem, via Internet Archive)Primary · retrieved 2026-08-01
  2. GROWTH DeFi (compensation accounting, via Internet Archive)Primary · retrieved 2026-08-01
  3. Smart Contract HackingSecondary · retrieved 2026-08-01
  4. ChainSecAggregator · retrieved 2026-08-01

Official post-mortem: https://growthdefi.medium.com/raave-farming-contract-exploit-explained-f3b6f0b3c1b3

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Growth DeFi hack — February 2021", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/growth-defi
https://itokenly.com/hacks/growth-defi

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.