
BlockSec Phalcon said an attacker gained DAO governance rights, upgraded Smart Yield controller logic and used a privileged function plus existing USDC approvals from 50 accounts to drain pooled funds.
BarnBridge SMART Yield (cUSDC) on Ethereum was attacked, with losses of about $776,000, in an incident that appears to have escalated from the governance-related approval risk flagged earlier. BlockSec Phalcon said the attacker obtained DAO governance rights, upgraded the SmartYield/controller proxy to a malicious implementation, and then used CompoundProvider's privileged _takeUnderlying function together with pre-existing USDC approvals from 50 user accounts to move pooled funds through transferFees. The case highlights how token approvals can become a direct loss vector when governance control and upgradeable contract logic are compromised.