Harvest's October 2020 exploit is one of the defining incidents in DeFi's history. An attacker used flash loans to manipulate the price of stablecoins inside a Curve pool that Harvest's strategy relied on, repeatedly draining value from the vaults — roughly $24m in total, of which a portion was returned.
What the incident taught the sector
It demonstrated that a yield strategy inherits every price assumption of every protocol it touches, and that flash loans make manipulating those assumptions cheap. Most modern strategies now use time-weighted or multi-source pricing specifically because of attacks like this one.
Where it stands now
Harvest continues to operate vaults across several EVM chains with no repeat incident. Its contracts have been revised and audited. But the protocol lost its position in the market and has not regained it, and the 30% performance fee is the highest in a category where the leader charges 4.5%.
The value question
A 30% fee on yield needs to be justified by outperformance that Harvest does not demonstrate. For the same underlying strategies, Beefy takes roughly a sixth as much.
Who should use it
Few people. Users with a specific vault only available here, at small size. For general auto-compounding, cheaper protocols with cleaner records are available on every chain Harvest operates on.