The Yearn Finance attack caused initial damage of about 3 million USD.


Yearn Finance has been attacked by a new vulnerability targeting its yETH product, a synthetic token representing a basket of LSTs like stETH and rETH. The attacker managed to create nearly unlimited yETH and drained liquidity in a single transaction, extracting around 1,000 ETH worth approximately 3 million USD. Part of the stolen funds was transferred through Tornado Cash to obscure the trail.
On-chain data shows that the attacker deployed several new smart contracts specifically for the attack, then executed self-destruct functions immediately after the transaction. The exact total damage is still being assessed. Before the attack, the yETH pool had about 11 million USD in TVL.
Yearn has stated that this incident is limited to yETH and confirmed that Yearn Vaults (V2 and V3) remain unaffected. The selected Morpho vaults are also safe. The yETH and st-yETH tokens are not used as collateral in any lending markets, limiting the risk of contagion.
This is not the first time Yearn has encountered security issues. Back in 2021, the yDAI vault was exploited for 11 million USD. Founder Andre Cronje has not been active in the project since 2022.
$BTC
ETH0,41%
STETH0,38%
BTC1,13%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
0/400
No comments
  • Pin

Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)