Revoke.cash logo

BarnBridge Governance Attack

Check if your address is affected.

15 Jul 2026
$780k stolen
Ethereum Logo

BarnBridge was a DeFi protocol whose SMART Yield pools lent out users' crypto on other lending platforms and offered either fixed or variable returns. It wound down in 2023, the year it settled charges with the US SEC for more than $1.7M. Its contracts stayed on-chain, and so did the approvals many users had given them. Because very few governance tokens were still staked in the abandoned DAO, an attacker needed only about $600 worth of them to pass a vote. They submitted a proposal disguised as a routine upgrade, and nobody voted against it.

When the proposal took effect on 15 July 2026, it handed control of the SMART Yield contracts to the attacker. Within about 12 minutes, they used that control to pull USDC directly from wallets that still had approvals from years earlier, taking roughly 776,600 USDC, worth about $777k. The stolen USDC was then swapped for around 415 ETH. Security firm Blockaid had publicly warned about the risky proposals and urged users to revoke shortly before the drain, but many of the old approvals were still active when the attack happened.

Blockaid also flagged a second queued proposal that could put approvals for DAI, USDT, GUSD and RAI to other BarnBridge SMART Yield contracts at risk. Those contracts are included in this entry as well. If you ever used BarnBridge, revoke all approvals to its contracts now, whatever the token. This attack shows that approvals to abandoned projects can become dangerous years after you stopped using them. Revoking protects what is still in your wallet, but it does not recover funds that were already taken.

Affected users remain at risk as long as they haven't revoked their approvals, so it is recommended to use the Revoke.cash Exploit Checker below to make sure that you're safe.

Sources:x.com•x.com

Next time, revoke it automatically

Revoke Ultimate monitors your approvals around the clock and revokes them automatically when an exploit like this one is identified, even while you sleep.

See how Auto-Revoking works →
Get Ultimate
Back to Exploits