BarnBridge SmartYield CompoundProvider contract has a hijacked controller; users with active USDC allowances should revoke them immediately to prevent draining.
Security & Exploits ·
A security alert identified a hijacked controller in the BarnBridge SmartYield CompoundProvider contract, with an attacker gaining control over user fund permissions. The warning specified that active USDC allowances to the contract remain at risk, with approximately 25,019 USDC marked as potentially drainable, and urged affected users to revoke all approvals immediately.
The compromise appears to center on the SmartYield CompoundProvider contract at address 0xdaa037f99d168b552c0c61b7fb64cf7819d78310, where the controller has been compromised. Users who granted USDC token spending permissions to this contract face exposure if they do not remove those allowances before the hijacked controller can execute a drain.
The alert was issued as a whitehat warning without requests for funds, links, or bounties. The broader scope of the vulnerability—how many users remain exposed, whether other tokens or BarnBridge contracts are affected, and whether BarnBridge has issued an official response—remain unclear. Verification of the claim's accuracy and any remediation steps taken by the project have not been detailed.