According to Beosin EagleEye security public opinion monitoring data, the Reaper Farm project was hacked. The Beosin security team found that because the owner address in _withdraw is controllable and there is no access control, calling the withdraw or redeem function can extract any user assets. The attacker (starting with 0x5636) used the attack contract (starting with 0x8162) to withdraw user funds through the vulnerable contract (starting with 0xcda5), and made accumulative profits of 62 ETH and 1.6 million DAI, worth about $1.7 million. Currently, the attacker (starting with 0x2c17) has passed Chain transfers all winning funds to Tornado.Cash.