PeckShield says hackers minted unlimited yETH, drained a custom stETH/rETH pool, and laundered over $3 million in ETH through Tornado Cash.PeckShield says hackers minted unlimited yETH, drained a custom stETH/rETH pool, and laundered over $3 million in ETH through Tornado Cash.

Yearn Finance Loses $9M in Single-Transaction Exploit of yETH Vault

2025/12/01 18:34

Yearn Finance has suffered a major security breach, resulting in the loss of approximately $9 million.

The exploit targeted a legacy stable swap pool associated with the protocol’s yETH token that allowed the hackers to mint an infinite number of coins.

Flaw in the yETH Contract

Blockchain security firm Peckshield was the first to flag the incident via X, stating, “Yearn Finance suffered an attack resulting in a total loss of ~$9M.”

According to the analysts, the attacker abused a critical vulnerability in the yETH token contract that let them mint fresh yETH without posting adequate collateral, effectively inflating the token supply at will. This loophole was then used to drain liquidity from a pool outside of Yearn’s core vault products.

Targeted in the exploit was a custom-built contract designed to aggregate staked Ethereum derivatives such as stETH and rETH. The protocol later shared that the yUSND pool and Nerite’s vaults remained secure and were not impacted by the protocol failure. Following the attack, those responsible then laundered over $3 million in stolen ETH through Tornado Cash. Meanwhile, the remaining $6 million in various staked Ethereum assets remain in their wallet address (0xa80d…c822) as of the latest blockchain scans.

Yearn also confirmed the compromise on X. It reported that $0.9 million was lost from the yETH-WETH stableswap pool on Curve, while an additional $8 million was drained from the affected pool. Impacted users were also advised to open a support ticket on the project’s Discord.

Early Investigation Findings

The platform announced that it has assembled a war room, comprising SEAL911 and its audit partner, Chain Security, with a full postmortem investigation underway.

Early findings suggest that the incident shares a similar level of technical complexity with the recent Balancer hack. That unauthorized access resulted in more than $120 million being stolen across the platform’s main protocol and several forks.

On-chain analysts traced the Balancer event to a precision-loss bug in the integer fixed-point arithmetic used to calculate scaling factors within Composable Stable Pools, which are optimized for near-parity asset pairs like USDC/USDT or WETH/stETH.

SlowMist later shared that the flaw led to subtle but repeated price discrepancies during swaps, particularly when attackers executed multiple operations within a single transaction using the batch swap function.

Meanwhile, Yearn’s incident follows shortly after Korean exchange Upbit suffered its own security lapse, which resulted in the loss of $50 million in Ethereum.

The post Yearn Finance Loses $9M in Single-Transaction Exploit of yETH Vault appeared first on CryptoPotato.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Polygon Tops RWA Rankings With $1.1B in Tokenized Assets

Polygon Tops RWA Rankings With $1.1B in Tokenized Assets

The post Polygon Tops RWA Rankings With $1.1B in Tokenized Assets appeared on BitcoinEthereumNews.com. Key Notes A new report from Dune and RWA.xyz highlights Polygon’s role in the growing RWA sector. Polygon PoS currently holds $1.13 billion in RWA Total Value Locked (TVL) across 269 assets. The network holds a 62% market share of tokenized global bonds, driven by European money market funds. The Polygon POL $0.25 24h volatility: 1.4% Market cap: $2.64 B Vol. 24h: $106.17 M network is securing a significant position in the rapidly growing tokenization space, now holding over $1.13 billion in total value locked (TVL) from Real World Assets (RWAs). This development comes as the network continues to evolve, recently deploying its major “Rio” upgrade on the Amoy testnet to enhance future scaling capabilities. This information comes from a new joint report on the state of the RWA market published on Sept. 17 by blockchain analytics firm Dune and data platform RWA.xyz. The focus on RWAs is intensifying across the industry, coinciding with events like the ongoing Real-World Asset Summit in New York. Sandeep Nailwal, CEO of the Polygon Foundation, highlighted the findings via a post on X, noting that the TVL is spread across 269 assets and 2,900 holders on the Polygon PoS chain. The Dune and https://t.co/W6WSFlHoQF report on RWA is out and it shows that RWA is happening on Polygon. Here are a few highlights: – Leading in Global Bonds: Polygon holds 62% share of tokenized global bonds (driven by Spiko’s euro MMF and Cashlink euro issues) – Spiko U.S.… — Sandeep | CEO, Polygon Foundation (※,※) (@sandeepnailwal) September 17, 2025 Key Trends From the 2025 RWA Report The joint publication, titled “RWA REPORT 2025,” offers a comprehensive look into the tokenized asset landscape, which it states has grown 224% since the start of 2024. The report identifies several key trends driving this expansion. According to…
Share
BitcoinEthereumNews2025/09/18 00:40