← Radar

Incident case file

Sign in to watch

BarnBridge SMART Yield — Malicious Governance Proposal / _takeUnderlying Abuse

Incident date July 15, 2026

1 views

ClosedEthereumGovernance attackCluster: BAR-GOV-2026-07

Estimated loss

$776K

Victims identified

50
Victim group joining is coming soon.

Investigation

100%

Facts and investigation

Attacker: Attacker EOA: 0xF908610E9174c7cd6e9dfD371e238be4511297A1. Malicious controller contract: 0x66c6f3b4B4b458e6d764759Ecf122484ebEf7580 (deployed by attacker on July 6). Additional contract created during proposal execution on July 15: 0x8b5f73544e50f18791682d1bcb4bb5011ca81b00.

Funds moved to: Total ~$776K USDC drained via _takeUnderlying calls on CompoundProvider using pre-existing USDC approvals from ~50 user accounts. Cash-out path from attacker EOA 0xF908610E... not fully traced in this report — recommend Etherscan review of outgoing transfers post-July 15 block 25535097.
Attacker EOA 0xF908610E9174c7cd6e9dfD371e238be4511297A1. Attacker's malicious controller contract 0x66c6f3b4B4b458e6d764759Ecf122484ebEf7580 (deployed July 6). Compromised BarnBridge Governance contract 0x4cAE362D7F227e3d306f70ce4878E245563F3069. Vulnerable BarnBridge CompoundProvider 0xDAA037F99d168b552c0c61B7Fb64cF7819D78310 (USDC market). BarnBridge:Barn staking contract (where 320,000 BOND was staked to obtain voting power). ~50 user accounts with pre-existing USDC approvals to CompoundProvi

Timeline: July 6, 2026: attacker deposits 320,000 BOND (governance tokens) to BarnBridge:Barn contract to obtain voting power (tx 0x9e7c43de3dcb40855493014278a4a3a55ce3e6e086c49e26e107ed8e6d551850). Same day: attacker deploys the malicious controller contract 0x66c6f3b4B4b458e6d764759Ecf122484ebEf7580 and submits a governance proposal (tx 0x07ff84e9372b9166f54f3de69b92371c113a370f08b1bef1e116c10ee48b7009). The proposal calls yieldControllTo in CompoundController, which would update the controller address of the pool (CompoundProvider) and smartYield contracts to the attacker's malicious controller. July 11, 2026: attacker votes on their own malicious proposal (tx 0x152b146b703dd94f00cf7d7c97face011a841d8c04a2f7a3ae9610decbdcdcad). After the vote passes (BarnBridge is a legacy protocol with declining participation — easy to reach quorum with 320K BOND), the malicious proposal is added to the execution queue (tx 0x660048e026a8d2caa9f9d1e54ba8cdf197030ba8f99e8c0b935f950164ae4492). July 15, 2026: attacker executes the proposal (tx 0x2e28e0b1dda3fe40c2226d61f9726dc3174098c3332ec0ee8087d35f46a42826, block 25535097). This creates a new contract 0x8b5f73544e50f18791682d1bcb4bb5011ca81b00 and swaps the CompoundProvider's controller to the attacker's malicious one. The attacker then calls the privileged _takeUnderlying function in CompoundProvider, exploiting the pre-existing USDC approvals from ~50 user accounts to transfer their USDC into CompoundProvider, then uses transferFees on the malicious controller to sweep the aggregated funds. Total drain ~$776K USDC. GoPlus Security publishes the full breakdown (thread starting tweet 2077368534628458801, July 15 15:23 UTC). BarnBridge is a legacy protocol in decline since 2023 — classic attack surface for abandoned governance-controlled protocols. Users with USDC approvals to CompoundProvider 0xDAA037F99d168b552c0c61B7Fb64cF7819D78310 are urged to revoke immediately.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)