Bearn.Fi Incident: Inconsistent Asset Denomination Between Vault & Strategy



Inconsistent Asset Denomination Between BvaultsBank And BvaultsStrategy

  1. It borrows a flashloan from CREAM with 7,804,239.111784605253208456 BUSD, which is returned at the last step with necessary fee to cover the flashloan cost.
  2. It deposits the borrowed funds into BvaultsBank, which are immediately sent to the associated BvaultsStrategy strategy, then to Alpaca Vault for yield. Due to the above deposit, the Alpaca Vault mints 7,598,066.589501626344403426 ibBUSD back to BvaultsStrategy.
  3. It farms with the received 7,598,066.589501626344403426 ibBUSD via the Alpaca FairLaunch.
  4. It withdraws the 7,804,239.111784605253208533 BUSD from BvaultsBank, which turns to be interpreted as withdrawing 7,804,239.111784605253208533 ibBUSD, or equivalently 8,016,006.09792806917101481 BUSD! In other words, the initial deposit of 7,804,239.111784605253208456 BUSD comes back with 8,016,006.09792806917101481 BUSD. It should be mentioned that the returned funds reside in the BvaultsStrategy and the user only gets back 7,804,239.111784605253208456 BUSD as requested in this round.
  5. In the next round, the user still deposits 7,804,239.111784605253208533 BUSD into BvaultsBank, cascadingly to BvaultsStrategy. But with the previous leftover from the last round, BvaultsStrategy credits the user with 8,016,006.09792806917101481 BUSD, which is used for yield again via Alpaca.
  6. It repeats the above steps to continue accumulating the credit and finally exits by draining the pool.
  7. It returns the flashloan with 7,806,580.383518140634784418 BUSD.

The Funds

About Us




A Blockchain Security Company (

Love podcasts or audiobooks? Learn on the go with our new app.

Recommended from Medium

This Torum XTM influencer is ready to cut his penis if BTC won’t go down to 42K

This Torum XTM influencer is ready to cut his penis if BTC won’t go down to 42K

Bitcoin before and after halving price analysis with the view of future

A creative exploring the value of NFTs

360Wellness — Digital Fitness $DEFIT In partnership with @FerrumNetwork and @YfdaiF , DEFIT is pr

Bitcoin; A (short term) outlook.

Cryptolocally and Polygon announce the P2P listing of MATIC and the integration of Polygon into…

6x winning trading algorithms explained (and are the future of trading)

Jinius Tu, Co-founder of Aion and known as the father of interoperability, joins AXIS as Co-founder

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store


A Blockchain Security Company (

More from Medium

Zencha Guide | How to StableSwap

Development of the Decentralized Finance (DeFi) Lottery System

RQBERT Attack Report & Compensation Plan

Enjoy free Contract Audit from HashEx