Andre Cronje's Stealth Eminence Launch Drained of $15 Million Hours After Deployment
Andre Cronje's unannounced project Eminence became the center of a $15 million loss on the night of Monday, September 28 into Tuesday, September 29, 2020, after crowds of users piled into a mysterious token and an attacker drained the underlying contract within hours.
The episode began with a string of cryptic tweets from Cronje that sent the community scrambling for clues. Once fresh contracts appeared on-chain, deployed from the yEarn finance address, speculation turned into action. Hundreds of users worked together to piece together what the project actually was, hunting for any edge that might translate into profit.

Sleuths traced artwork posted from the eminence.finance Twitter account back to Eminence, Xander's Tales, an MMORPG that had never been finished. A tweet from the project's account on September 28 shared promotional imagery, and researcher Kiyo (@IslandKiyo) publicly floated the theory that Cronje was connected to the game's lead artist, predicting an NFT/DeFi hybrid built around a ticker called $ENM.
The deployed contracts turned out to include an EMN token that could be swapped for wrapped versions of other assets — eYFI, eAAVE, eSNX among them. This lined up neatly with an earlier tweet from Cronje describing a new, unusually complex yearn system built on top of Synthetix, Aave, Chainlink, and iearn.finance infrastructure across both L1 and L2, in which he mused about whether to publish documentation ahead of launch or simply ship it and let the market react.
Cronje's standing as one of DeFi's most prolific builders, paired with the buzz around the Eminence account, was enough to trigger a stampede. Roughly $15 million poured into the unaudited contract in exchange for EMN or its associated eTokens. Because EMN launched on a fairly flat bonding curve, a wave of users chose instead to buy it secondhand on Uniswap, opening up several hours of lucrative arbitrage for anyone willing to interact with the raw contract directly.
Then, at approximately 04:00 UTC, the entire $15 million sitting in the contract was emptied in a single attack.
Researcher @fifikobayashi laid out the mechanics shortly afterward: the attacker took out a flash loan to mint EMN, then pushed the EMN price down by burning tokens for eTokens — since EMN followed a bonding curve, reducing supply reduced price. The other half of the flash-loaned EMN was then burned back into DAI, which had been artificially inflated in value relative to EMN because of that same curve-driven price collapse, effectively shorting EMN against DAI.
What followed was unusual even by the standards of a space where exploits are common. Eleven minutes after pulling $15 million in DAI out of the contract, the attacker sent $8 million of it back to the Yearn: Deployer contract at 01:31:04 AM UTC, in a transaction visible on Etherscan.
The partial refund immediately fueled speculation about the attacker's identity, with some in the community suggesting — without evidence — that people close to Yearn itself might have been involved, including a tweet from Spicetoshi questioning whether Yearn contributor @bantg had run bots that pumped EMN before cashing out into growing DAI liquidity.
Regardless of who deposited into an unaudited contract, that choice ultimately left them holding the bag, and a number of commentators criticized Cronje for promoting an unfinished product in a way that made a FOMO-driven rush all but inevitable. Individual losses ranged widely — one account described spending $130,548 on EMN roughly 90 minutes before the drain and recovering only $368 when selling back out; another reported having put in over $100,000 shortly before the exploit.

Cronje said he had received multiple threats over the missing funds and asked the Yearn Treasury to help distribute the $8 million that had been returned. He also tweeted that he intended to keep building Eminence and continue deploying test contracts, noting he had upward of 100 such contracts live, more than half of which he estimated carried vulnerabilities, and asked the community to wait for official statements.
Yearn contributors Banteg and Klim K subsequently built a snapshot of EMN and eToken balances to calculate refund eligibility, publishing a reference list (values need to be divided by 1e18) — a project rektHQ noted it had no part in creating and could not vouch for as final. Banteg described the snapshot as covering bonding-curve rates for EMN, eCRV, eLINK, eAAVE, eYFI, and eSNX at block 10954410, spanning 3,656 addresses, built to distribute the 8 million DAI that had been returned.
The incident capped off a run of surprise, unaudited launches that had previously paid off handsomely for early participants, and while parts of Crypto Twitter continued to celebrate that kind of high-risk "degen" behavior, the fallout left a mark on Cronje's previously spotless reputation and raised broader questions for both builders and users about surprise launches going forward. For now, the community is left waiting for the actual game, Eminence: Xander's Tales, to eventually ship.
Get new scam files the moment we publish them — usually 2–3 emails a week.