Yearn Finance Loses $9M in Single-Transaction Exploit of yETH Vault


PeckShield says hackers minted unlimited yETH, drained a custom stETH/rETH pool, and laundered over $3 million in ETH through Tornado Cash.

Yearn Finance has suffered a major security breach, resulting in the loss of approximately $9 million.

The exploit targeted a legacy stable swap pool associated with the protocol’s yETH token that allowed the hackers to mint an infinite number of coins.

Flaw in the yETH Contract

Blockchain security firm Peckshield was the first to flag the incident via X, stating, “Yearn Finance suffered an attack resulting in a total loss of ~$9M.”

According to the analysts, the attacker abused a critical vulnerability in the yETH token contract that let them mint fresh yETH without posting adequate collateral, effectively inflating the token supply at will. This loophole was then used to drain liquidity from a pool outside of Yearn’s core vault products.

Targeted in the exploit was a custom-built contract designed to aggregate staked Ethereum derivatives such as stETH and rETH. The protocol later shared that the yUSND pool and Nerite’s vaults remained secure and were not impacted by the protocol failure. Following the attack, those responsible then laundered over $3 million in stolen ETH through Tornado Cash. Meanwhile, the remaining $6 million in various staked Ethereum assets remain in their wallet address (0xa80d…c822) as of the latest blockchain scans.

Yearn also confirmed the compromise on X. It reported that $0.9 million was lost from the yETH-WETH stableswap pool on Curve, while an additional $8 million was drained from the affected pool. Impacted users were also advised to open a support ticket on the project’s Discord.

Early Investigation Findings

The platform announced that it has assembled a war room, comprising SEAL911 and its audit partner, Chain Security, with a full postmortem investigation underway.

You may also like:

Early findings suggest that the incident shares a similar level of technical complexity with the recent Balancer hack. That unauthorized access resulted in more than $120 million being stolen across the platform’s main protocol and several forks.

On-chain analysts traced the Balancer event to a precision-loss bug in the integer fixed-point arithmetic used to calculate scaling factors within Composable Stable Pools, which are optimized for near-parity asset pairs like USDC/USDT or WETH/stETH.

SlowMist later shared that the flaw led to subtle but repeated price discrepancies during swaps, particularly when attackers executed multiple operations within a single transaction using the batch swap function.

Meanwhile, Yearn’s incident follows shortly after Korean exchange Upbit suffered its own security lapse, which resulted in the loss of $50 million in Ethereum.

SPECIAL OFFER (Exclusive)

SECRET PARTNERSHIP BONUS for CryptoPotato readers: Use this link to register and unlock $1,500 in exclusive BingX Exchange rewards (limited time offer).

Source link

Wayne Jones

https://cryptopotato.com/yearn-finance-loses-9m-in-single-transaction-exploit-of-yeth-vault/

2025-12-01 10:34:00

bitcoin
Bitcoin (BTC) $ 86,620.00 5.17%
ethereum
Ethereum (ETH) $ 2,838.52 5.70%
tether
Tether (USDT) $ 0.99996 0.03%
xrp
XRP (XRP) $ 2.04 7.05%
bnb
BNB (BNB) $ 824.86 6.13%
usd-coin
USDC (USDC) $ 0.999714 0.01%
tron
TRON (TRX) $ 0.277876 1.00%
staked-ether
Lido Staked Ether (STETH) $ 2,837.76 5.65%
dogecoin
Dogecoin (DOGE) $ 0.137334 8.05%
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.03 0.00%
cardano
Cardano (ADA) $ 0.386195 8.29%
whitebit
WhiteBIT Coin (WBT) $ 55.68 5.22%
wrapped-steth
Wrapped stETH (WSTETH) $ 3,462.43 5.70%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 86,456.00 5.25%
bitcoin-cash
Bitcoin Cash (BCH) $ 523.28 3.06%
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 3,075.40 5.69%
usds
USDS (USDS) $ 0.999699 0.01%
leo-token
LEO Token (LEO) $ 9.89 0.39%
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999876 0.01%
chainlink
Chainlink (LINK) $ 12.17 6.89%
hyperliquid
Hyperliquid (HYPE) $ 31.23 7.01%
monero
Monero (XMR) $ 414.31 0.39%
stellar
Stellar (XLM) $ 0.232128 8.06%
weth
WETH (WETH) $ 2,838.30 5.69%
wrapped-eeth
Wrapped eETH (WEETH) $ 3,069.98 5.70%
ethena-usde
Ethena USDe (USDE) $ 0.999084 0.02%
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 86,692.00 5.09%
zcash
Zcash (ZEC) $ 363.83 20.16%
litecoin
Litecoin (LTC) $ 77.85 7.62%
hedera-hashgraph
Hedera (HBAR) $ 0.133685 6.55%
avalanche-2
Avalanche (AVAX) $ 13.00 7.80%
sui
Sui (SUI) $ 1.37 10.53%
shiba-inu
Shiba Inu (SHIB) $ 0.000008 5.48%
dai
Dai (DAI) $ 0.99905 0.07%
world-liberty-financial
World Liberty Financial (WLFI) $ 0.149744 6.25%
susds
sUSDS (SUSDS) $ 1.08 0.23%
ethena-staked-usde
Ethena Staked USDe (SUSDE) $ 1.21 0.02%
paypal-usd
PayPal USD (PYUSD) $ 0.999766 0.02%
crypto-com-chain
Cronos (CRO) $ 0.102261 5.27%
usdt0
USDT0 (USDT0) $ 0.999621 0.05%
the-open-network
Toncoin (TON) $ 1.51 3.52%
uniswap
Uniswap (UNI) $ 5.58 9.56%
polkadot
Polkadot (DOT) $ 2.05 9.60%
mantle
Mantle (MNT) $ 0.988566 9.23%
canton-network
Canton (CC) $ 0.084045 3.27%
usd1-wlfi
USD1 (USD1) $ 0.998927 0.04%
bittensor
Bittensor (TAO) $ 269.87 7.85%
aave
Aave (AAVE) $ 165.75 10.46%
bitget-token
Bitget Token (BGB) $ 3.47 3.97%
memecore
MemeCore (M) $ 1.39 3.76%