BarnBridge SmartYield CompoundProvider controller hijacked; users with active USDC allowances to the contract face immediate drain risk.
Security & Exploits ·
A security researcher flagged a compromised controller on the BarnBridge SmartYield CompoundProvider contract, warning that users with active USDC allowances face immediate drainage risk. The alert identified approximately 25,019 USDC as vulnerable and urged holders to revoke all allowances to the affected contract immediately.
The CompoundProvider contract at address 0xdaa037f99d168b552c0c61b7fb64cf7819d78310 was identified as having its controller hijacked. The warning was issued without requesting funds, links, or bounties, suggesting a whitehat disclosure approach. Users who had previously approved token transfers to the contract remain exposed if those allowances have not been revoked.
What remains unclear is the extent of the compromise—whether other tokens or contracts are affected, what triggered the controller hijacking, and whether BarnBridge has issued an official statement or remediation plan. The alert provides no timeline for when the vulnerability was discovered or how long users have been at risk.