TLDR
Yearn Finances yETH stableswap pool was halted after an exploit in a custom yETH contract enabled infinite minting of yETH and drained liquidity, per a Yearn statement.
- Cause: a flaw in the legacy yETH token logic allowed minting a massive supply in one transaction, triggering a pool drain (report).
- Impact: roughly $9 million in losses across yETH pools, with no effect on Yearn V2/V3 vaults (Yearn statement).
- Status: a war room is active with auditors; initial recovery of about $2.4 million was announced (update).
Deep Dive
1. Cause And Mechanism
The halt followed an exploit at 21:11 (UTC) on 30 Nov involving a legacy yETH stableswap implementation that deviated from standard code, enabling the attacker to mint an enormous amount of yETH in one transaction.
- The vulnerability was in a custom yETH contract path, not in the broader Yearn Vault infrastructure, per the Yearn statement.
- Coverage describes an arithmetic infinite mint flaw in the older yETH token logic that let the attacker siphon liquidity rapidly from the pool (report).
- Helper contracts were reportedly deployed minutes before and self-destructed after use, complicating forensics (report).
The halt was a containment step for a legacy code-path issue, not a systemic failure of Yearns main vaults.
2. Impact And Scope
Losses were concentrated in yETH stableswap pools, with no reported impact on Yearn V2/V3 vaults.
- Early estimates cited about $8 million lost in the main yETH stableswap pool and $0.9 million in the yETH-WETH pool on Curve, totaling roughly $9 million (the Yearn statement above).
- Funds included ETH and liquid staking tokens, with around 1,000 ETH moved through Tornado Cash shortly after the attack (report).
- Yearn reiterated that V2/V3 vaults and curated Morpho vaults were unaffected, narrowing the blast radius to legacy yETH paths (Yearn post).
Users interacting only with current Yearn vaults were not in the exploit path, but liquidity providers in the yETH stableswap pools faced direct losses.
3. Recovery And Next Steps
Yearn has engaged auditors and incident responders and reported an initial recovery of funds.
- A war room with SEAL 911 and ChainSecurity is active, and a post?mortem is underway (the Yearn statement above).
- Yearn said it recovered about $2.4 million (857.49 pxETH) linked to the attackers wallets, with plans to return recovered assets to affected users (update).
- The team is reviewing older contracts to prevent similar incidents and has provided support channels via Discord while the audit completes (Yearn statement).
Avoid interacting with legacy yETH contracts until the post?mortem is published; affected users should follow Yearns support guidance.
Conclusion
The yETH pool halt was a targeted response to an exploit in a legacy, custom yETH contract that enabled infinite minting and rapid liquidity drain. Losses were largely confined to yETH stableswap pools, with Yearns main vaults unaffected, and recovery efforts already returning part of the stolen assets. Monitoring official updates and the forthcoming post?mortem will clarify remediation and any compensation process.
