PeckShield says hackers minted unlimited yETH, drained a custom stETH/rETH pool, and laundered over $3 million in ETH through Tornado Cash.PeckShield says hackers minted unlimited yETH, drained a custom stETH/rETH pool, and laundered over $3 million in ETH through Tornado Cash.

Yearn Finance Loses $9M in Single-Transaction Exploit of yETH Vault

2025/12/01 18:34

Yearn Finance has suffered a major security breach, resulting in the loss of approximately $9 million.

The exploit targeted a legacy stable swap pool associated with the protocol’s yETH token that allowed the hackers to mint an infinite number of coins.

Flaw in the yETH Contract

Blockchain security firm Peckshield was the first to flag the incident via X, stating, “Yearn Finance suffered an attack resulting in a total loss of ~$9M.”

According to the analysts, the attacker abused a critical vulnerability in the yETH token contract that let them mint fresh yETH without posting adequate collateral, effectively inflating the token supply at will. This loophole was then used to drain liquidity from a pool outside of Yearn’s core vault products.

Targeted in the exploit was a custom-built contract designed to aggregate staked Ethereum derivatives such as stETH and rETH. The protocol later shared that the yUSND pool and Nerite’s vaults remained secure and were not impacted by the protocol failure. Following the attack, those responsible then laundered over $3 million in stolen ETH through Tornado Cash. Meanwhile, the remaining $6 million in various staked Ethereum assets remain in their wallet address (0xa80d…c822) as of the latest blockchain scans.

Yearn also confirmed the compromise on X. It reported that $0.9 million was lost from the yETH-WETH stableswap pool on Curve, while an additional $8 million was drained from the affected pool. Impacted users were also advised to open a support ticket on the project’s Discord.

Early Investigation Findings

The platform announced that it has assembled a war room, comprising SEAL911 and its audit partner, Chain Security, with a full postmortem investigation underway.

Early findings suggest that the incident shares a similar level of technical complexity with the recent Balancer hack. That unauthorized access resulted in more than $120 million being stolen across the platform’s main protocol and several forks.

On-chain analysts traced the Balancer event to a precision-loss bug in the integer fixed-point arithmetic used to calculate scaling factors within Composable Stable Pools, which are optimized for near-parity asset pairs like USDC/USDT or WETH/stETH.

SlowMist later shared that the flaw led to subtle but repeated price discrepancies during swaps, particularly when attackers executed multiple operations within a single transaction using the batch swap function.

Meanwhile, Yearn’s incident follows shortly after Korean exchange Upbit suffered its own security lapse, which resulted in the loss of $50 million in Ethereum.

The post Yearn Finance Loses $9M in Single-Transaction Exploit of yETH Vault appeared first on CryptoPotato.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Spot XRP ETFs Nears $1B AUM Milestone as Streak of No Outflows Continues

Spot XRP ETFs Nears $1B AUM Milestone as Streak of No Outflows Continues

The post Spot XRP ETFs Nears $1B AUM Milestone as Streak of No Outflows Continues appeared on BitcoinEthereumNews.com. The U.S. Spot XRP ETFs is now near the $1 billion mark of assets under management in less than a month since their launch. This follows from the product maintaining consistent inflows with no single outflow recorded yet. XRP ETFs See Continuous Inflows Since Launch Since its first launch on November 14, spot XRP funds have seen continued inflows. According to data from SoSoValue, the total inflows into these funds have now risen to $881.25 million. The funds attracted $12.84 million of new money yesterday. The daily trading volumes remained stable at $26.74 million. Source: SoSoValue Reaching nearly $1 billion in less than 30 days makes the product among the fastest growing crypto investment products in the United States. Notably, Spot Solana ETFs also accumulated over $600 million since their launch. On the other hand, Bitcoin and Ethereum ETFs are holding about $58 billion and about $13 billion in assets under management respectively. Much of the early growth traces back to the first Canary Capital’s XRP ETF. Its opening on November 13 brought one of the strongest crypto ETF openings to date. It saw more than $59 million in first-day trading volume and $245 million in net inflows. Shortly after Canary’s launch, firms like Grayscale, Bitwise, and Franklin Templeton introduced their own XRP products. Bitwise’s fund also did well on its launch, recording over $105 million in early inflows. Meanwhile, the market is getting ready for yet another addition. 21Shares’ U.S. spot XRP fund also got the green light from the SEC. It will trade under the ticker TOXR on the Cboe BZX Exchange. XRP Products Keep Gaining Momentum in the Market The token’s funds continued to expand this week. REX Shares and Tuttle Capital have launched the T-REX 2X Long XRP Daily Target ETF. This new ETF allows traders…
Share
BitcoinEthereumNews2025/12/05 14:11
Headwind Helps Best Wallet Token

Headwind Helps Best Wallet Token

The post Headwind Helps Best Wallet Token appeared on BitcoinEthereumNews.com. Google has announced the launch of a new open-source protocol called Agent Payments Protocol (AP2) in partnership with Coinbase, the Ethereum Foundation, and 60 other organizations. This allows AI agents to make payments on behalf of users using various methods such as real-time bank transfers, credit and debit cards, and, most importantly, stablecoins. Let’s explore in detail what this could mean for the broader cryptocurrency markets, and also highlight a presale crypto (Best Wallet Token) that could explode as a result of this development. Google’s Push for Stablecoins Agent Payments Protocol (AP2) uses digital contracts known as ‘Intent Mandates’ and ‘Verifiable Credentials’ to ensure that AI agents undertake only those payments authorized by the user. Mandates, by the way, are cryptographically signed, tamper-proof digital contracts that act as verifiable proof of a user’s instruction. For example, let’s say you instruct an AI agent to never spend more than $200 in a single transaction. This instruction is written into an Intent Mandate, which serves as a digital contract. Now, whenever the AI agent tries to make a payment, it must present this mandate as proof of authorization, which will then be verified via the AP2 protocol. Alongside this, Google has also launched the A2A x402 extension to accelerate support for the Web3 ecosystem. This production-ready solution enables agent-based crypto payments and will help reshape the growth of cryptocurrency integration within the AP2 protocol. Google’s inclusion of stablecoins in AP2 is a massive vote of confidence in dollar-pegged cryptocurrencies and a huge step toward making them a mainstream payment option. This widens stablecoin usage beyond trading and speculation, positioning them at the center of the consumption economy. The recent enactment of the GENIUS Act in the U.S. gives stablecoins more structure and legal support. Imagine paying for things like data crawls, per-task…
Share
BitcoinEthereumNews2025/09/18 01:27