The post Yearn Finance V1’s legacy Yearn TUSD vault hacked appeared on BitcoinEthereumNews.com. A legacy version of the decentralized finance protocol Yearn hasThe post Yearn Finance V1’s legacy Yearn TUSD vault hacked appeared on BitcoinEthereumNews.com. A legacy version of the decentralized finance protocol Yearn has

Yearn Finance V1’s legacy Yearn TUSD vault hacked

A legacy version of the decentralized finance protocol Yearn has suffered an exploit, reviving concerns about misconfigured and immutable smart contracts that have held funds on the network years after being deprecated.

In an X post on Wednesday, Security firm PeckShield reported YearnFinanceV1’s hack resulted in losses of about $300,000. The stolen funds were swapped into 103 Ether and now sit at address 0x0F21…4066, according to Etherscan images shared by the firm.

The hackers took advantage of an outdated Yearn vault tied to TrueUSD, known as the “iearn TUSD vault,” which is still deployed on Ether despite being superseded by newer versions. A configuration flaw helped the attackers manipulate share prices through several transactions.

Yearn Finance misconfigured vault triggered price manipulation 

According to an analysis from pseudonymous crypto researcher and University of Science and Technology of China alumnus Weilin Li, the vault configured one of its strategies as a Fulcrum sUSD vault and calculated its share price using only the sUSD balance deposited.

This opened the door to so-called “donation attacks,” in which an attacker transfers assets directly into a vault to distort accounting metrics. After sending Fulcrum sUSD tokens into the Yearn TUSD vault, the perpetrators were able to artificially inflate the vault’s reported share price.

The issue was compounded by a rebalance function that withdraws all underlying assets in sUSD, an asset not included in the vault’s share price calculations. When the rebalance started, the vault’s share price tanked steeply and created a “price shock.”

Per PeckShield Alert’s Etherscan snapshot, the attacker executed sequenced flash loans by firstly borrowing large amounts of TUSD and sUSD without an upfront collateral. They then deposited sUSD to mint Fulcrum sUSD tokens before depositing TUSD into the Yearn TUSD vault. 

At that stage, all underlying assets of the TUSD vault consisted of Fulcrum sUSD tokens. The exploiter withdrew from the Yearn TUSD vault and called the rebalance function, forcing Fulcrum to redeem everything into sUSD. Because sUSD was excluded from share price calculations, the vault’s accounting collapsed, effectively driving the share price toward zero.

The attacker then transferred a small amount of TUSD back into the vault, pushing the share price to extremely low levels, and minted an outsized number of Yearn TUSD tokens at minimal cost. He ultimately counted gains by selling the cheaply acquired Yearn TUSD tokens on Curve pools, extracting value from liquidity providers before repaying the flash loans.

Yearn Finance recaps 2023 vulnerability, researcher recounts

Researcher Li found that the exploit was similar to an attack carried out in 2023, leading to losses exceeding $10 million. The immutable yUSDT contract targeted in that earlier incident was deployed more than three years ago, during the early days of iearn when the late Andre Cronje led the protocol.

Pessimistic security analysts had issued a warning about the vulnerability on social media before the exploit, but since immutable smart contracts cannot be patched or paused once deployed, it was inevitable.

 “iearn finance, Smoothswap, be careful. This address 0x5bac20…ed8e9cdfe0 got 10 ETH from Tornado and deploys contracts with flashloans using your addresses,” PS’ Nikiti Kirillov wrote.

A Yearn team member known as storming0x admitted the attack happened and reassured users that its current contracts were safe. Yet, Rekt News observers revealed it took 1,156 days for the DeFi protocol to spot a multimillion-dollar vulnerability.

Yearn yUSDT token contract generated yield from a basket of yield-bearing positions, including USDT deposits on Aave, Compound, dYdX and BzX’s Fulcrum. Since launch, however, yUSDT contained a copy-and-paste error which referenced the Fulcrum USDC address instead of the Fulcrum USDT contract. 

Using just 10,000 USDT, hackers were able to mint approximately 1.2 quadrillion yUSDT, draining value from the system before cashing out.

The Yearn incident comes less than a week after Cryptopolitan featured a $2.7 million drainage from an old contract belonging to Ribbon Finance, the rebranded version of Aevo. That attack involved repeated interactions with a proxy admin contract at address 0x9D7b…8ae6B76. The attacker invoked functions such as transferOwnership and setImplementation to manipulate price-feed proxies through delegate calls.

Don’t just read crypto news. Understand it. Subscribe to our newsletter. It’s free.

Source: https://www.cryptopolitan.com/yearn-finance-tusd-vault-hacked/

Market Opportunity
FINANCE Logo
FINANCE Price(FINANCE)
$0.0001944
$0.0001944$0.0001944
+1.03%
USD
FINANCE (FINANCE) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

IP Hits $11.75, HYPE Climbs to $55, BlockDAG Surpasses Both with $407M Presale Surge!

IP Hits $11.75, HYPE Climbs to $55, BlockDAG Surpasses Both with $407M Presale Surge!

The post IP Hits $11.75, HYPE Climbs to $55, BlockDAG Surpasses Both with $407M Presale Surge! appeared on BitcoinEthereumNews.com. Crypto News 17 September 2025 | 18:00 Discover why BlockDAG’s upcoming Awakening Testnet launch makes it the best crypto to buy today as Story (IP) price jumps to $11.75 and Hyperliquid hits new highs. Recent crypto market numbers show strength but also some limits. The Story (IP) price jump has been sharp, fueled by big buybacks and speculation, yet critics point out that revenue still lags far behind its valuation. The Hyperliquid (HYPE) price looks solid around the mid-$50s after a new all-time high, but questions remain about sustainability once the hype around USDH proposals cools down. So the obvious question is: why chase coins that are either stretched thin or at risk of retracing when you could back a network that’s already proving itself on the ground? That’s where BlockDAG comes in. While other chains are stuck dealing with validator congestion or outages, BlockDAG’s upcoming Awakening Testnet will be stress-testing its EVM-compatible smart chain with real miners before listing. For anyone looking for the best crypto coin to buy, the choice between waiting on fixes or joining live progress feels like an easy one. BlockDAG: Smart Chain Running Before Launch Ethereum continues to wrestle with gas congestion, and Solana is still known for network freezes, yet BlockDAG is already showing a different picture. Its upcoming Awakening Testnet, set to launch on September 25, isn’t just a demo; it’s a live rollout where the chain’s base protocols are being stress-tested with miners connected globally. EVM compatibility is active, account abstraction is built in, and tools like updated vesting contracts and Stratum integration are already functional. Instead of waiting for fixes like other networks, BlockDAG is proving its infrastructure in real time. What makes this even more important is that the technology is operational before the coin even hits exchanges. That…
Share
BitcoinEthereumNews2025/09/18 00:32
Why IPO Genie ($IPO) Is Being Called a Top Crypto Presale by Analysts

Why IPO Genie ($IPO) Is Being Called a Top Crypto Presale by Analysts

IPO Genie ($IPO) is being called a top crypto presale by analysts, offering AI-driven market insights, robust tokenomics, and data-backed investor growth.
Share
Blockchainreporter2025/12/18 22:00
Headwind Helps Best Wallet Token

Headwind Helps Best Wallet Token

The post Headwind Helps Best Wallet Token appeared on BitcoinEthereumNews.com. Google has announced the launch of a new open-source protocol called Agent Payments Protocol (AP2) in partnership with Coinbase, the Ethereum Foundation, and 60 other organizations. This allows AI agents to make payments on behalf of users using various methods such as real-time bank transfers, credit and debit cards, and, most importantly, stablecoins. Let’s explore in detail what this could mean for the broader cryptocurrency markets, and also highlight a presale crypto (Best Wallet Token) that could explode as a result of this development. Google’s Push for Stablecoins Agent Payments Protocol (AP2) uses digital contracts known as ‘Intent Mandates’ and ‘Verifiable Credentials’ to ensure that AI agents undertake only those payments authorized by the user. Mandates, by the way, are cryptographically signed, tamper-proof digital contracts that act as verifiable proof of a user’s instruction. For example, let’s say you instruct an AI agent to never spend more than $200 in a single transaction. This instruction is written into an Intent Mandate, which serves as a digital contract. Now, whenever the AI agent tries to make a payment, it must present this mandate as proof of authorization, which will then be verified via the AP2 protocol. Alongside this, Google has also launched the A2A x402 extension to accelerate support for the Web3 ecosystem. This production-ready solution enables agent-based crypto payments and will help reshape the growth of cryptocurrency integration within the AP2 protocol. Google’s inclusion of stablecoins in AP2 is a massive vote of confidence in dollar-pegged cryptocurrencies and a huge step toward making them a mainstream payment option. This widens stablecoin usage beyond trading and speculation, positioning them at the center of the consumption economy. The recent enactment of the GENIUS Act in the U.S. gives stablecoins more structure and legal support. Imagine paying for things like data crawls, per-task…
Share
BitcoinEthereumNews2025/09/18 01:27