Yearn Finance Suffers USD 9M Hack After Critical yETH Contract Exploit

Cryptocurrencies are considered a high-risk asset class. Investing in them may result in the loss of part or all of your capital. The content on this website is intended solely for informational and educational use and should not be interpreted as financial or investment advice.
Why Trust Us
Why Trust Us
Yearn Finance Suffers USD 9M Hack After Critical yETH Contract Exploit

Decentralized finance protocol Yearn Finance confirmed on the 30th that its yETH-related liquidity pools were hacked, resulting in the theft of approximately USD 9 million worth of crypto assets.

According to on-chain analysis, the attacker exploited a critical vulnerability in a legacy yETH contract, enabling them to mint an unlimited amount of yETH without posting any collateral. The attacker then drained liquidity from Balancer pools and later routed part of the stolen funds through the privacy mixer Tornado Cash, making recovery increasingly difficult.

How the Attack Happened

Blockchain security researchers identified that the exploit stemmed from a severe flaw in an old yETH contract still accessible within the protocol. The vulnerability allowed the attacker to mint yETH with no collateral, bypassing supply restrictions entirely.

Key findings include:

  • The attacker minted about 235 trillion yETH in a single transaction.
  • They used these tokens to drain liquidity from Balancer pools linked to Yearn.
  • Yearn Finance reported the total loss at around USD 9 million.
  • Before the attack, yETH pools held approximately USD 11 million, meaning the majority of assets were wiped out.

This exploit occurred on Ethereum (ETH), where Yearn’s smart contracts and vaults operate.

Stolen Funds Routed Through Tornado Cash

Of the funds extracted, 1,000 ETH—worth roughly USD 4.68 million—was sent to Tornado Cash, a privacy protocol often used to obscure transaction trails. The move significantly complicates efforts to trace or recover the stolen assets.

Security firm PeckShield estimates that the attacker’s wallet still holds around USD 6 million, suggesting additional movements may follow.

The incident highlights an ongoing concern in DeFi: legacy contracts and permissionless mixer tools remain prime vectors for large-scale hacks.

Yearn’s Response and User Guidance

Yearn Finance has urged users to stop interacting with yETH until further notice. The project emphasized that the exploit did not affect Yearn’s core products, including:

  • V2 Vaults
  • V3 Vaults

Yearn is now working with leading cybersecurity teams, including SEAL 911 and ChainSecurity, to investigate the exploit, patch vulnerabilities, and evaluate further protective measures.

Meanwhile, users are being reminded of the importance of rigorous wallet security: self-custody remains the final line of defense in the crypto ecosystem.

 

By Patrick Johnson

Patrick Johnson is a seasoned crypto journalist and analyst with a sharp eye for emerging trends in blockchain, DeFi, NFTs, and Web3 innovation. With a background in tech writing and years of experience tracking digital assets, Patrick breaks down complex topics into clear, actionable insights for investors, builders, and curious readers alike. His work spans market analysis, crypto regulation, decentralized finance ecosystems, and interviews with founders shaping the next phase of the internet. Patrick's writing has appeared in leading crypto publications and has earned a reputation for depth, clarity, and a no-hype approach to crypto journalism. When he’s not decoding the latest protocol upgrade or reporting on DAO governance shifts, you’ll find him experimenting with smart contracts or hiking off-grid, because even crypto authors need to unplug sometimes.