TLDR
It was caused by an infinite?mint flaw in a legacy yETH contract that let an attacker mint massive yETH and drain liquidity from pools, not Yearns core vaults per reporting.
- Yearns yETH stableswap used custom code that allowed minting a large amount of yETH, triggering the incident per the projects statement on X.
- Estimated losses are about $9 million, and Yearn V2/V3 vaults were explicitly said to be unaffected in the same notice above.
- The attacker minted roughly 235 trillion yETH and moved ~1,000 ETH via Tornado Cash; the attack ran in about 30 minutes per analysis and a security thread on X.
Deep Dive
1. Root Cause
The core issue was an infinite?mint vulnerability in the yETH token logic inside a custom stableswap implementation, allowing the creation of enormous yETH that could be swapped for real assets. Yearn clarified the affected contract was a bespoke version of stableswap code and not shared with other Yearn products, and confirmed vaults were safe in its statement on X. Multiple outlets describe the bug as a legacy yETH contract minting weakness rather than a flaw in the V2/V3 vault architecture here.
The breakage was in a specialized yETH contract, not in Yearns widely used vault system, so blast radius was limited to that pool and related liquidity.
2. Impact and Scope
Yearns initial tally cited about $9 million in losses across the affected stableswap pools, with a separate note that V2/V3 vaults were not at risk in the notice above. Coverage summarized that roughly 1,000 ETH (~$3 million) was routed through Tornado Cash shortly after the drain, while other assets remained in the attackers wallets pending investigation here.
If you held yETH or provided liquidity to the impacted pools, you were directly exposed; holders of assets in Yearns V2/V3 vaults were not impacted by this bug.
3. Attack Path
Reports indicate the attacker minted an extreme supply (about 235 trillion yETH) and quickly removed ETH and LSTs from Balancer-linked pools before laundering ~1,000 ETH via Tornado Cash per this breakdown. A security thread noted the sequence from preparation to execution took roughly 30 minutes, underscoring the speed and pre?planning typical of on?chain exploits on X.
Infinite?mint plus swift execution allows attackers to convert fabricated tokens into real value before defenses or responders can react.
Conclusion
The Yearn yETH incident stemmed from an infinite?mint bug in a legacy, custom stableswap contract, enabling mass yETH creation and rapid liquidity drains. Losses near $9 million and a confirmed isolation from Yearns V2/V3 vaults point to a localized contract failure rather than systemic protocol risk. For exposure management, focus on contract provenance and upgrade paths; mint logic and pool integrations are critical failure points in composite DeFi products.
