📈 Get daily crypto insights that make you smarter about your money

$15 Million Drained from Andre Cronje’s Unfinished Eminence Protocol in Flash Loan Exploit

The decentralized finance community was rocked on September 29, 2020, by the news that Eminence.Finance — an unfinished DeFi protocol created by Yearn.Finance founder Andre Cronje — had been exploited for $15 million. The incident laid bare the risks of the “test in production” culture that had become prevalent in the DeFi space and triggered a wave of soul-searching among investors and developers alike.

TL;DR

  • Eminence.Finance, an unaudited DeFi protocol by YFI founder Andre Cronje, was exploited for $15 million
  • The attacker used a flash loan to mint EMN tokens at a tight bonding curve, then drained liquidity pools
  • $8 million was mysteriously returned to Cronje’s yearn.finance developer account by the hacker
  • Cronje announced refunds based on a pre-hack snapshot but received death threats, leading him to leave Twitter
  • The exploit highlights the dangers of investing in unaudited, unfinished smart contracts

Eminence was envisioned as a new in-game economy for a gaming multiverse, built on Ethereum. Cronje, whose Yearn.Finance protocol had become one of the most successful DeFi projects of 2020, had deployed early versions of the Eminence smart contracts on Uniswap as part of his well-known “test in prod” development process. He had publicly stated the project was “at least +3 weeks away” from completion and that the contracts were neither final nor audited.

How the Exploit Unfolded

Despite Cronje’s clear warnings about the unfinished state of the project, DeFi investors — often referred to as “degens” — began pouring funds into the Eminence contracts in anticipation of another Yearn-like success story. While Cronje was away, users flocked to the protocol, choosing factions within the planned gaming ecosystem and depositing assets into the liquidity pools.

A hacker seized the opportunity, exploiting the unaudited smart contracts using a flash loan attack. The method was deceptively simple: the attacker minted a large quantity of EMN tokens at the tight end of the bonding curve, then burned the EMN for other currencies within the protocol, and finally sold those currencies back for EMN at a profit. This cyclic exploitation drained approximately $15 million worth of deposited assets from the protocol.

A Partial Refund from an Unexpected Source

In an unusual twist, the hacker returned $8 million to Andre Cronje’s personal yearn.finance developer wallet. The motivation behind this partial refund remains unclear. Cronje publicly acknowledged the returned funds and committed to distributing them back to affected holders based on a pre-hack snapshot.

“As I am receiving a fair amount of threats, I have asked yearn treasury to assist with refunding the 8m the hacker sent. The multisig is safer and as such I feel more comfortable with them having the funds,” Cronje wrote on Twitter on September 29. “Funds will be returned to holders pre-hack snapshot.”

Cronje Faces Threats, Exits Twitter

The aftermath of the exploit turned ugly quickly. Cronje, who had built significant goodwill in the DeFi community through the success of Yearn.Finance, found himself on the receiving end of death threats from investors who had lost money in the Eminence exploit. The pressure prompted him to deactivate his Twitter account on September 29, leaving the community without one of its most prominent voices.

The incident prompted a broader discussion about the responsibilities of developers in the DeFi space. While Cronje had been transparent about the unfinished nature of the contracts, the culture of rushing into unaudited protocols — hoping to get in early on the next YFI — had led many investors to ignore clear warnings.

A Pattern of DeFi Exploits

The Eminence exploit came just days after the KuCoin exchange hack on September 25, where over $275 million in cryptocurrency was stolen from the Singapore-based exchange’s hot wallets. Together, the two incidents underscored the security challenges facing both centralized and decentralized corners of the cryptocurrency market in late September 2020.

With DeFi’s total value locked having ballooned to $11 billion, the sector’s rapid growth was attracting not just investors but also sophisticated attackers. The Eminence incident served as a costly reminder that in the world of decentralized finance, the line between innovation and exploitation can be razor-thin.

Why This Matters

The Eminence exploit is a cautionary tale about the intersection of developer experimentation and investor speculation in DeFi. Cronje’s “test in prod” approach, while innovative, created an environment where users could — and did — invest real money into unfinished products. The $15 million loss highlights the critical importance of smart contract audits and the need for investors to exercise greater due diligence before depositing funds into unaudited protocols. As DeFi continues to grow, the tension between rapid innovation and security will remain one of the sector’s defining challenges.

Disclaimer: This article is for informational purposes only and does not constitute financial advice. Always do your own research before making any investment decisions. Cryptocurrency investments carry significant risk.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

25 thoughts on “$15 Million Drained from Andre Cronje’s Unfinished Eminence Protocol in Flash Loan Exploit”

    1. Lukas H. hacker returning funds was probably fear not guilt. susrvey chains are short and that much EMN moving would get traced fast

      1. the $8M return was probably the hacker covering their tracks, not ethics. returning some to avoid the full weight of law enforcement chasing you is a classic move

        1. defi_witness_

          Dalia K. the hacker returning $8M was probably fear not ethics. DOJ was already investigating DeFi exploits by late 2020. returning funds = lighter sentencing

    1. dev_nul the $8M return was probably the hacker panicking about DOJ attention, not ethics. still wild that cronje got death threats for a project he literally told people not to use

      1. audit_pilot_ you genuinely cant engineer around FOMO. cronje put a warning up, people ignored it, $15M disappeared. no amount of code fixes human greed

        1. death threats over a project people aped into voluntarily with zero audit. crypto brings out the worst in everyone

  1. degen_archaeologist_

    people aped into an unfinished protocol because of the YFI brand. the bonding curve was literally still being tested and wallets went in anyway

  2. the bonding curve on EMN was so tight a single flash loan could drain the whole pool. nobody read the contract including the auditors because there were none

    1. flash_loan_rat_ no auditors AND a tight bonding curve. cronje was basically running an experiment and retail treated it like a product launch

      1. hbg_watcher_ the warning banner was in 6pt font at the bottom of the page. i actually went back and checked. calling that due diligence by users is generous

  3. cronje putting a warning banner up and people still depositing is the most defi thing ever. yield blinded everyone

    1. cronje literally put a disclaimer on the UI and people still dumped millions in. yield farming brain rot was at peak levels in sept 2020

    2. Niklas B. warning banner on the UI and people still deposited. YFI was doing 10x and due diligence went out the window. same story every cycle in defi

    3. Niklas B. death threats over a protocol he literally put a warning banner on. this community deserves what it gets sometimes

  4. the bonding curve being tight enough for a single flash loan to drain everything is the real story. nobody audited the math because the YFI brand was enough

    1. bonding_curve_rat

      Inkeri V. the bonding curve was so tight that a 50K flash loan moved the price 300%. any DEX with that kind of slippage on a single trade is basically a casino

  5. $8M returned and cronje still got death threats. the man put a literal disclaimer on the contract UI and people blamed him for their own greed

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$64,808.00-0.1%ETH$1,914.40+0.1%SOL$75.81+2.6%BNB$601.76+1.9%XRP$1.04+0.4%ADA$0.1989-1.0%DOGE$0.0700+0.1%DOT$0.8146-0.7%AVAX$6.48-1.2%LINK$8.29+1.3%UNI$3.98-0.4%ATOM$1.38+0.6%LTC$46.01+1.1%ARB$0.0781-0.2%NEAR$1.62+1.1%FIL$0.7128+3.4%SUI$0.6884+1.6%BTC$64,808.00-0.1%ETH$1,914.40+0.1%SOL$75.81+2.6%BNB$601.76+1.9%XRP$1.04+0.4%ADA$0.1989-1.0%DOGE$0.0700+0.1%DOT$0.8146-0.7%AVAX$6.48-1.2%LINK$8.29+1.3%UNI$3.98-0.4%ATOM$1.38+0.6%LTC$46.01+1.1%ARB$0.0781-0.2%NEAR$1.62+1.1%FIL$0.7128+3.4%SUI$0.6884+1.6%
Scroll to Top