{"id":96163,"date":"2020-10-23T19:42:24","date_gmt":"2020-10-23T16:42:24","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/anonymous-devs-behind-a-defi-yield-farm-could-steal-1b-in-12-hours\/"},"modified":"2020-10-23T19:42:24","modified_gmt":"2020-10-23T16:42:24","slug":"anonymous-devs-behind-a-defi-yield-farm-could-steal-1b-in-12-hours","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/anonymous-devs-behind-a-defi-yield-farm-could-steal-1b-in-12-hours\/","title":{"rendered":"# Anonymous devs behind a DeFi yield farm could steal $1B in 12 hours"},"content":{"rendered":"<p>&#8220;<strong># Anonymous devs behind a DeFi yield farm could steal $1B in 12 hours <\/strong>&#8221;<\/p>\n<div data-v-5a136f3a=\"\">Harvest Finance, a decentralized finance project that succeeded in attracting over $1 billion in funds locked has an admin key that gives its holders the ability to mint tokens at will and steal users\u2019 funds.<\/p>\n<p>As noted by auditing companies <a rel=\"nofollow noopener noreferrer\" target=\"_blank\" href=\"https:\/\/github.com\/harvest-finance\/harvest\/blob\/master\/audits\/PeckShield-Harvest.pdf\">PeckShield<\/a> and <a rel=\"nofollow noopener noreferrer\" target=\"_blank\" href=\"https:\/\/github.com\/harvest-finance\/harvest\/blob\/master\/audits\/Haechi-Harvest.pdf\">Haechi<\/a>, the governance parameters are not set by a contract with clearly defined rules. An admin key, presumably held by the anonymous developers behind the project, could be used to arbitrarily mint new FARM tokens.<\/p>\n<p>This power could allow the governance key holders to create an unlimited number of tokens and drain funds in the token\u2019s Uniswap pool, which currently holds $12 million in USDC.<\/p>\n<p>Harvest Finance is an automated yield management system, featuring vault-based strategies similar to Yearn Finance. Haechi highlighted that in addition to the minting mechanics, the governance key holder has the ability to change the vault functionality at will, which could be exploited by submitting a bogus strategy that simply sends the funds to an attacker-controlled address.<\/p>\n<p>The holders of the governance key would thus have the theoretical possibility of stealing all of the $1.05 billion in assets committed to the protocol, in addition to the funds in the Uniswap pool.<\/p>\n<figure><img decoding=\"async\" src=\"https:\/\/s3.eu-central-1.amazonaws.com\/s3.cointelegraph.com\/uploads\/2020-10\/a73ce7d1-06db-431a-ab6a-a076b931106c.png\"\/><figcaption style=\"text-align: center;\">Source: <a rel=\"nofollow noopener noreferrer\" target=\"_blank\" href=\"https:\/\/defipulse.com\/harvest-finance\">DeFi Pulse<\/a><\/figcaption><\/figure>\n<p>In response to the audits, the team introduced a 12 hour time lock that should give enough advanced warning to users if any foul play is detected \u2014 but that requires constant community vigilance.<\/p>\n<p>The project is currently running a classical yield farm similar to many of the \u201cfood coins.\u201d Users can commit Ether (ETH), Wr<a href=\"https:\/\/buradabiliyorum.com\/en\/category\/download-scripts-themes-apps\/\" data-internallinksmanager029f6b8e52c=\"9\" title=\"Download Scripts &amp; Themes &amp; Apps\" target=\"_blank\" rel=\"noopener\">app<\/a>ed Bitcoin (BTC) and other assets, but the highest FARM yield can be found by submitting FARM tokens themselves, without necessarily requiring the additional layer of abstraction of Uniswap pool tokens. Such a circular dependency is characteristic of many crypto Ponzi schemes.<\/p>\n<p>The team is completely anonymous, though the project succeeded in attracting a relatively sizable community and has been involved in the community by doling out <a rel=\"nofollow noopener noreferrer\" target=\"_blank\" href=\"https:\/\/medium.com\/@harvestfinance\/week-8-update-welcome-to-the-good-life-migration-complete-cf72137fc6eb\">grants<\/a>.<\/p>\n<p>While nothing would suggest malicious intentions for now, the project is strongly centralized and prospective farmers should be aware that they are trusting an anonymous group of developers to resist the temptation to run off with their money, similarly to how the community initially trusted SushiSwap\u2019s founder.<\/p>\n<\/div>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong>\n<\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/news\/\" data-internallinksmanager029f6b8e52c=\"2\" title=\"News\" target=\"_blank\" rel=\"noopener\">News<\/a> articles, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/general\/\" target=\"_blank\" rel=\"noopener noreferrer\">General category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/cointelegraph.com\/news\/anonymous-devs-behind-a-defi-yield-farm-could-steal-1b-in-12-hours\" target=\"_blank\" rel=\"noopener noreferrer\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;# Anonymous devs behind a DeFi yield farm could steal $1B in 12 hours &#8221; Harvest Finance, a decentralized finance project that succeeded in attracting over $1 billion in funds locked has an admin key that gives its holders the ability to mint tokens at will and steal users\u2019 funds. As noted by auditing companies&#8230;<\/p>\n","protected":false},"author":1,"featured_media":96164,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/s3.eu-central-1.amazonaws.com\/s3.cointelegraph.com\/uploads\/2020-10\/58ffa316-a455-4d89-bcbb-d2113be1ab6a.jpg","fifu_image_alt":"","footnotes":""},"categories":[1],"tags":[74868,74891,4965],"class_list":["post-96163","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-general","tag-defi","tag-ethereum","tag-technology"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/96163","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=96163"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/96163\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/96164"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=96163"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=96163"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=96163"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}