Beanstalk, an Ethereum-based credit stablecoin protocol, suffered a governance exploit at roughly 12:24 UTC on April 17, 2022. Beanstalk Farms subsequently confirmed that the attacker used a flash loan to compromise the protocol’s voting mechanism and steal approximately $77 million in non-Bean user assets from its liquidity pools.
The incident mattered beyond the immediate loss. The attacker did not merely manipulate a token price or find an isolated withdrawal bug. Borrowed capital was converted into enough temporary governance power to approve and execute a malicious proposal. A system intended to distribute control among depositors became the mechanism through which its deposited assets were removed.
A vote financed for one transaction
Flash loans allow assets to be borrowed and repaid within one atomic blockchain transaction. Because the entire sequence either succeeds or reverts, the borrower generally does not post conventional collateral. That feature can support legitimate arbitrage and refinancing, but it can also provide enormous temporary balances when a protocol treats present token ownership as durable economic commitment.
Contemporaneous reporting on April 17, based on the Ethereum transaction record, found that the attacker used Aave liquidity and moved through assets including DAI, USDC and USDT before obtaining voting power in Beanstalk. The attacker then invoked Beanstalk’s emergency governance process to execute a proposal that transferred assets from the protocol.
The central weakness was the connection between freshly deposited liquidity and immediately usable voting influence. The attacker needed control only long enough to approve the proposal, remove the assets, unwind the borrowed positions and repay the flash loan. The transaction therefore demonstrated that nominally decentralized voting could remain vulnerable when governance weight could be assembled with short-lived capital.
The loss estimates measured different things
The figures circulating around the incident were not interchangeable. Crypto Briefing reported on April 17 that the attacker emerged with 24,830 ETH, valued by the publication at approximately $76 million at its reporting time. That dollar conversion was a contemporaneous estimate dependent on the ETH price and the publication’s unspecified intraday measurement point.
Beanstalk Farms’ April 19 incident account placed the theft at approximately $77 million in non-Bean user assets. Bloomberg reported on April 18 that blockchain-security firm PeckShield estimated approximately $182 million in total protocol losses while the attacker obtained about $80 million in crypto assets.
Those figures describe different measurement scopes: assets ultimately retained by the attacker, non-Bean liquidity removed from users and a broader estimate of protocol damage. This reconstruction does not combine them into a single definitive loss or treat the fluctuating dollar value of protocol-issued Bean tokens as realized attacker proceeds.
Immediate institutional consequences
Beanstalk’s official record says the development team paused the protocol and disabled its on-chain governance after learning of the exploit. That response limited further governance activity, but it could not reverse the completed transaction.
For decentralized-finance institutions, the episode underscored that governance code was part of the security perimeter. Auditing token and liquidity contracts alone could not address a system in which borrowed voting power could authorize privileged changes. Proposal delays, voting-power snapshots, execution timelocks and emergency controls were consequently not administrative details; they were defenses governing access to protocol assets.
What was knowable on April 17
The Ethereum transaction and the large asset outflow were visible on April 17, and same-date reporting identified a flash-loan-assisted governance attack. Final accounting, recovery prospects and a durable relaunch plan were not established on April 17. Beanstalk’s approximately $77 million figure and its description of the pause were published on April 19 and are used here as later confirmation of the event, not as information available in complete form during the attack date.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

