There's been yet another massive crypto heist

scammers
(Image credit: Shutterstock / Brazhyk)

A flaw in the operations of Beanstalk Farms, a stablecoin protocol, has allowed an unknown threat actor to siphon $182 million from the network, it has emerged.

A stablecoin is a cryptocurrency token that’s pegged to a regular currency or another stable asset, such as gold. As such, stablecoins have a stable value compared to more volatile cryptocurrencies, such as bitcoin.

Beanstalk Farms is a stablecoin protocol that operates on the Ethereum network, and issues the BEAN governance token, which gives owners voting power for any changes to the network itself.

Share your thoughts on Cybersecurity and get a free copy of the Hacker's Manual 2022end of this survey

Share your thoughts on Cybersecurity and get a free copy of the Hacker's Manual 2022. Help us find how businesses are preparing for the post-Covid world and the implications of these activities on their cybersecurity plans. Enter your email at the end of this survey to get the bookazine, worth $10.99/£10.99.

Flash loans

Describing the incident in a Discord post, the company said the attacker discovered a vulnerability in its governance system, made possible with the help of a flash loan service. There was no malware, stolen passwords, or fake identities used in the attack.

Flash loans are like regular loans, the only difference being that they happen in a flash. These instant loans are made possible with the unique nature of blockchain technology. However, in this particular case, flash loans helped the attacker steal the money from the protocol. The threat actor used the flash loan service Aave to buy a large amount of BEAN.

Now in possession of a large proportion of BEAN, the attacker was able to pass a malicious governance proposal and siphon out all of the protocol’s funds into a private ETH wallet. 

“Beanstalk did not use a flash loan resistant measure to determine the % of Stalk that had voted in favor of the BIP,” the Discord post reads. “This was the fault that allowed the hacker to exploit Beanstalk.”

A part of the funds ($250,000) was sent to a Ukrainian relief wallet, CoinDesk reported. It is currently unclear whether the company will reimburse the affected customers.

Crypto hacks are becoming more devastating by the day. Earlier this year, hundreds of millions of dollars in cryptocurrency was stolen from the Ronin Network, which provides the "blockchain bridge" that powers NFT game Axie Infinity.

Via CoinDesk

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Ethereum
Hackers steal over $1bn in one of the biggest crypto thefts ever
A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.
LastPass 2022 hack fallout continues with millions of dollars more reportedly stolen
cryptocurrency
It's been a huge year for criminals stealing cryptocurrency - and North Korea was largely to blame
North Korean flag with a hooded hacker
FBI says North Korean Lazarus hackers were behind $1.5 billion Bybit crypto hack
Cryptocurrencies
Around $40 billion worth of illicit crypto transactions took place in 2024
Close up of a person touching an email icon.
Top US mineral firm hit by cyberattack that saw thieves steal $500,000
Latest in Software & Services
A man sitting at his desk in the evening and using a desktop computer
Office 2021 vs Office 2024: is it time to upgrade?
Microsoft 365 Business app logos
Office 2024 LTSC vs Microsoft 365 Business: what are the differences?
Windows 11 Start menu layout choices: Grid view
Windows 11 vs Linux for business: which operating system should you embrace?
A phone sitting on a laptop keyboard with the Microsoft Outlook logo on the screen.
Gmail vs Outlook for business: which email system is right for your organization?
Windows 11 logo
Windows 11 Pro vs Windows 11 Home: which version is right for you?
Canva HubSpot
HubSpot and Canva team up to level the creative playing field
Latest in News
GTA 5
GTA Online publisher Take-Two is gunning for a black market that’s basically heaven for cheaters
The Discovery+ homepage
Discovery+ just got a big update to its streaming app that makes it more like Max – here are 5 great new features to try
Two Android phones on a green and blue background showing Google Messages
Struggling with slow Google Messages photo transfers? Google says new update will make 'noticeable difference'
Google Meet create custom backgrounds
More AI features are coming to Google Workspace
Elayne, Egwene, and Nynaeve dressed regally and on horseback in The Wheel of Time season 3
'There's a reason why we do it': The Wheel of Time showrunner responds to fans who are still upset over the Prime Video show's plot alterations
A mockup of the possible Apple M3 Ultra logo
Performance isn't the only reason you should buy Apple's M3 Ultra Mac Studio - it's reportedly one of the most power-efficient processors too