Telegram (AI) YouTube Facebook X
Ру
Yearn Finance DeFi Project Hacked for $9 Million

Yearn Finance DeFi Project Hacked for $9 Million

Yearn Finance protocol hacked for $9 million; attackers exploited yETH vulnerability.

On November 30, unknown attackers targeted the Yearn Finance protocol, resulting in a total loss of $9 million, according to blockchain security experts PeckShield.

Details

The project team confirmed the hack, emphasizing that it was due to a vulnerability in the Yearn Ether (yETH) product code.

According to PeckShield, the attackers minted nearly infinite tokens, draining the entire pool in a single transaction of 1000 ETH (~$3 million).

The stolen funds were immediately sent by the hackers to the crypto mixer Tornado Cash.

Yearn developers stated that the affected contract is a custom version of popular stableswap code, not linked to other protocol products. Yearn V2/V3 remain secure, they emphasized.

Preliminary data indicated the following approximate losses:

  • $8 million from the affected stableswap pool;
  • $0.9 million from the yETH-WETH stable swap pool on Curve.

“Initial analysis showed that the complexity of the hack is similar to the recent Balancer exploit, so please be patient as we conduct our analysis. No other Yearn product uses code similar to the one affected,” the project team added.

Impact

Following the incident, the Yearn token — YFI — fell by 5.5%. At the time of writing, the asset is trading around $3900 with a market capitalization of $132.6 million.

image
Hourly chart of YFI/USDT on Binance. Source: TradingView.

TVL of the protocol decreased from $432 million to $410 million over the past day. At its peak in November 2021, the figure was $6.7 billion.

image
Source: DefiLlama.

This latest incident is not the first hack of Yearn. In 2021, an unknown party extracted $2.8 million from the v1 yDAI pool. The project promptly compensated affected users for their losses.

In December 2023, due to a “faulty scenario” in a multisig transaction, the protocol lost 63% of its treasury funds in the Lp yCRV pool. The incident occurred during a “routine token fee conversion process” and resulted in the exchange of 3,794,894 yCRV for 779,958 yvDAI. The team clarified that the loss amounted to $1.4 million.

In November 2025, on-chain researcher tanuki42 discovered an undisclosed hack of the market maker DWF Labs for $44 million.

Подписывайтесь на ForkLog в социальных сетях

Telegram (основной канал) Facebook X
Нашли ошибку в тексте? Выделите ее и нажмите CTRL+ENTER

Рассылки ForkLog: держите руку на пульсе биткоин-индустрии!

We use cookies to improve the quality of our service.

By using this website, you agree to the Privacy policy.

OK