Researcher prevented a $3.17M loss by identifying and reporting exposed USDT in a BarnBridge approval before a malicious governance proposal.
Security & Exploits ·
A researcher identified and reported a critical vulnerability affecting approximately $3.17 million in USDT holdings before it could be exploited through a compromised BarnBridge governance system. The funds belonged to a single wallet holding 3,171,993.62 USDT with an active approval to a vulnerable provider contract; after receiving a warning relayed through SEAL 911, the owner moved the assets to safety.
The attack exploited BarnBridge's abandoned governance infrastructure, which remained active after the project shut down. Two addresses obtained sufficient voting power to pass proposals #14 and #15, which transferred controller permissions to upgradeable proxies under their control. This allowed the attackers to execute token transfers directly from user wallets via existing approvals without requiring deposits in BarnBridge itself. The malicious proposals ultimately resulted in approximately $1.06 million in confirmed losses across multiple wallets, with an additional $781,000 in USDC frozen by Circle and the $3.17 million in USDT protected through early intervention.
The researcher conducted independent work reconstructing the attack path, identifying affected contracts, and scanning historical approvals to locate vulnerable wallets. Warnings were initially issued through on-chain messaging and public communication channels with limited effect until escalated to SEAL 911 for amplification. The scope remains unclear regarding whether BarnBridge leadership has formally acknowledged the prevention effort or discussions about potential recognition have occurred.