Harvest Finance said its USDC and USDT vaults suffered an economic attack beginning at 02:53:31 UTC on October 26, 2020, after an attacker manipulated asset values in Curve Finance’s Y pool. Harvest’s same-day postmortem estimated that the vault-value loss was about $33.8 million, or approximately 3.2% of the protocol’s total value locked immediately before the attack.
The event mattered beyond one yield-farming project. Harvest depended on other decentralized-finance protocols to invest depositor assets and calculate vault-share values. That composability made funds programmable, but it also allowed short-lived conditions created in one liquidity pool to influence deposits and withdrawals in another protocol.
How the transactions worked
Harvest reported that the attacker obtained large amounts of USDC and USDT through Uniswap and used them to move the relative values of stablecoins inside Curve’s Y pool. The altered pool valuation let the attacker deposit into a Harvest vault at a favorable share price, reverse the Curve trade and then redeem the newly issued shares after the calculated value recovered.
In the first documented sequence, the attacking contract swapped 17.222 million USDT for approximately 17.217 million USDC, deposited about 49.977 million USDC into Harvest and later withdrew approximately 50.597 million USDC. Harvest calculated a profit of about 619,409 USDC before flash-loan fees for that cycle.
The protocol said the attacker repeated the process across 17 transactions targeting the USDC vault and 13 targeting the USDT vault. Harvest’s existing three-percent arbitrage check did not stop the transactions because the value movement within each cycle remained below its configured threshold.
The loss figures measured different things
At 03:01:48 UTC, the attacking contract transferred 13 million USDC and 11 million USDT to another address, establishing the widely reported 24 million-token outflow. A subsequent transaction returned 1,761,898.396474 USDC and 718,914.048541 USDT to the Harvest deployer.
Those transfers should not be treated as interchangeable with Harvest’s $33.8 million loss estimate. The 24 million figure described stablecoins moved from the attacking contract, while $33.8 million represented Harvest’s calculation of the decline in affected vault value. The postmortem said the USDC vault’s share price moved from 0.980007 to 0.834953 and the USDT vault’s from 0.978874 to 0.844812. On-chain records verify transaction timing and token movements, but they do not independently settle the appropriate dollar-loss methodology.
Depositors and markets reacted
Harvest withdrew stablecoin and bitcoin-linked funds from shared Curve strategies while it investigated. The team said the DAI, TUSD, WBTC and renBTC vaults had not been attacked, although their strategies were also withdrawn as a precaution. It accepted responsibility for an engineering error and said remediation for affected users would be its priority.
The market response was immediate but difficult to reduce to one definitive snapshot. CoinDesk reported that CoinGecko data showed FARM, Harvest’s native token, falling 65% in less than one hour. The same report said DeFi Pulse measured Harvest’s total value locked falling from more than $1 billion before the incident to $673 million at 05:00 UTC. A later October 26 CoinDesk snapshot placed it at $430 million roughly 12 hours after the attack. These were moving, contemporaneous tracker readings—not a reconstructed exchange-level price series—and withdrawals cannot all be classified as attack losses.
Why the failure mattered
The attack demonstrated that a smart contract could execute as written while its economic assumptions failed. Flash liquidity compressed the capital requirement and let the attacker repeat a manipulation, deposit and withdrawal sequence before markets or administrators could respond.
Harvest proposed delaying share issuance, tightening checks and changing withdrawal mechanics, but those were event-day proposals rather than completed protections. As of October 26, the verified record established the attack, the affected vaults, the protocol’s loss estimate and its immediate response; recovery, governance compensation and the attacker’s identity remained unresolved.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

