Incident case file
Sign in to watchBarnBridge SMART Yield — Malicious Governance Proposal / _takeUnderlying Abuse
1 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: Attacker EOA: 0xF908610E9174c7cd6e9dfD371e238be4511297A1. Malicious controller contract: 0x66c6f3b4B4b458e6d764759Ecf122484ebEf7580 (deployed by attacker on July 6). Additional contract created during proposal execution on July 15: 0x8b5f73544e50f18791682d1bcb4bb5011ca81b00.
Timeline: July 6, 2026: attacker deposits 320,000 BOND (governance tokens) to BarnBridge:Barn contract to obtain voting power (tx 0x9e7c43de3dcb40855493014278a4a3a55ce3e6e086c49e26e107ed8e6d551850). Same day: attacker deploys the malicious controller contract 0x66c6f3b4B4b458e6d764759Ecf122484ebEf7580 and submits a governance proposal (tx 0x07ff84e9372b9166f54f3de69b92371c113a370f08b1bef1e116c10ee48b7009). The proposal calls yieldControllTo in CompoundController, which would update the controller address of the pool (CompoundProvider) and smartYield contracts to the attacker's malicious controller. July 11, 2026: attacker votes on their own malicious proposal (tx 0x152b146b703dd94f00cf7d7c97face011a841d8c04a2f7a3ae9610decbdcdcad). After the vote passes (BarnBridge is a legacy protocol with declining participation — easy to reach quorum with 320K BOND), the malicious proposal is added to the execution queue (tx 0x660048e026a8d2caa9f9d1e54ba8cdf197030ba8f99e8c0b935f950164ae4492). July 15, 2026: attacker executes the proposal (tx 0x2e28e0b1dda3fe40c2226d61f9726dc3174098c3332ec0ee8087d35f46a42826, block 25535097). This creates a new contract 0x8b5f73544e50f18791682d1bcb4bb5011ca81b00 and swaps the CompoundProvider's controller to the attacker's malicious one. The attacker then calls the privileged _takeUnderlying function in CompoundProvider, exploiting the pre-existing USDC approvals from ~50 user accounts to transfer their USDC into CompoundProvider, then uses transferFees on the malicious controller to sweep the aggregated funds. Total drain ~$776K USDC. GoPlus Security publishes the full breakdown (thread starting tweet 2077368534628458801, July 15 15:23 UTC). BarnBridge is a legacy protocol in decline since 2023 — classic attack surface for abandoned governance-controlled protocols. Users with USDC approvals to CompoundProvider 0xDAA037F99d168b552c0c61B7Fb64cF7819D78310 are urged to revoke immediately.
Sources and coverage
- Articlex.comhttps://x.com/GoPlusSecurity/status/2077368534628458801
- Articlex.comhttps://x.com/GoPlusSecurity/status/2077368538680189144
- Articlex.comhttps://x.com/GoPlusSecurity/status/2077368542421492021
- Articlex.comhttps://x.com/GoPlusSecurity/status/2077368546330587463
- Articlex.comhttps://x.com/GoPlusSecurity/status/2077368550801711389
- Articlex.comhttps://x.com/GoPlusSecurity/status/2077368554534703466
- Articlex.comhttps://x.com/GoPlusSecurity/status/2077368558707957967
- Articlex.comhttps://x.com/GoPlusSecurity/status/2077368561937564043
- Articleetherscan.iohttps://etherscan.io/tx/0x9e7c43de3dcb40855493014278a4a3a55ce3e6e086c49e26e107ed8e6d551850
- Articleetherscan.iohttps://etherscan.io/tx/0x07ff84e9372b9166f54f3de69b92371c113a370f08b1bef1e116c10ee48b7009
- Articleetherscan.iohttps://etherscan.io/tx/0x152b146b703dd94f00cf7d7c97face011a841d8c04a2f7a3ae9610decbdcdcad
- Articleetherscan.iohttps://etherscan.io/tx/0x660048e026a8d2caa9f9d1e54ba8cdf197030ba8f99e8c0b935f950164ae4492
- Articleetherscan.iohttps://etherscan.io/tx/0x2e28e0b1dda3fe40c2226d61f9726dc3174098c3332ec0ee8087d35f46a42826
- Articleetherscan.iohttps://etherscan.io/address/0xf908610e9174c7cd6e9dfd371e238be4511297a1
- Articlehacked.slowmist.iohttps://hacked.slowmist.io/
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)