# The Beanstalk Farms exploited **Published by:** [01dcat](https://paragraph.com/@01dcat/) **Published on:** 2022-04-18 **URL:** https://paragraph.com/@01dcat/the-beanstalk-farms-exploited ## Content What happened?Basically just from two TX https://etherscan.io/tx/0xd09b72275962b03dd96205f8077fdc08bec87c0ebd07e431aadc760f31f34b01 and https://etherscan.io/tx/0xcd314668aaa9bbfebaf1a0bd2b6553d01dd58899c508d4729fa7311dc5d33ad7HowThere are some code in Bean https://github.com/BeanstalkFarms/Beanstalk/blob/ee4720cdb449d5b6ff2b789083792c4395628674/protocol/contracts/farm/facets/GovernanceFacet/GovernanceFacet.solbasically this means you can approve a bip when you have enough token 2/3 portion of the tokensa BIP 18 be proposed — what is the BIP 18 — “Give 250,000 bean to Ukraine and 10,000 bean to the proposer.”https://etherscan.io/address/0x259a2795624b8a17bc7eb312a94504ad0f615d1e#codeFlashloan to get enough bean to approve the BIP with emergecyCommit to get the bean outvote for bip 18 + emergencyCommint bip 18HOLD ON, why something will go wrong, let’s look back the creation of the bip 18proposerWallet 0xe5ecf73603d98a0128f05ed30506ac7a663dbb69 is a smart contract this smart contract will be called from the bean and can transfer everything(bean,LP) to address 0x1c5dcdd006ea78a7e4783f9e6021c32935a10fb4this is the code https://etherscan.io/bytecode-decompiler?a=0xe5ecf73603d98a0128f05ed30506ac7a663dbb69The transaction looks likehttps://etherscan.io/tx/0x68cdec0ac76454c3b0f7af0b8a3895db00adf6daaf3b50a99716858c4fa54c6fA simple steps from https://twitter.com/peckshieldA remarkable noteYes. 250,000 USDC sent to Ukraine Crypto Donation, thank you hacker while you are getting 182M USD…… Originally published at https://01dcat.notion.site. ## Publication Information - [01dcat](https://paragraph.com/@01dcat/): Publication homepage - [All Posts](https://paragraph.com/@01dcat/): More posts from this publication - [RSS Feed](https://api.paragraph.com/blogs/rss/@01dcat): Subscribe to updates - [Twitter](https://twitter.com/levixie): Follow on Twitter