TLDR
Yearn Finance (YFI) halted yETH pools because a bug in a custom stableswap contract enabled an infinite mint of yETH, which was used to drain pool liquidity, prompting an immediate pause to contain losses per a Yearn update on X.
- The exploit minted a huge amount of yETH due to a numerical/invariant bug in legacy yETH code, not Yearns V2/V3 vaults per a post?mortem link on X.
- Losses were about $9 million ($8M main pool, $0.9M yETH?WETH on Curve) per the incident update.
- Yearn isolated the issue and convened a war room with security teams; V2/V3 vaults remained unaffected per the initial notice.
Deep Dive
1. Root Cause
The yETH pools were halted after an infinite mint exploit in a custom stableswap contract, allowing attackers to mint massive yETH and drain real assets from pools. Yearns post?mortem points to a combination of a low?level numerical bug and invariant management issues in the yETH logic, distinct from its vault architecture, per a post?mortem link on X and analysis summarized by Yahoo Finance.
- Yearn confirmed the exploit was in the yETH stableswap code, unrelated to other Yearn products per a Yearn update on X.
- Media coverage described the mechanism as an infinite mint of yETH used to drain Balancer and related pools per Crypto.news.
The halt was a defensive response to a contract?level flaw, not a systemic failure of Yearns vaults.
2. Impact
Yearn reported approximately $9 million in losses: $8M from the affected stableswap pool and $0.9M from a yETH?WETH pool on Curve, with around 1,000 ETH routed through Tornado Cash per a Yearn incident update and corroborated coverage by Yahoo Finance.
- The attacker minted an extremely large supply of yETH in a single transaction around the incident window, then used it to pull real assets from pools per Yahoo Finance.
- Follow?ups noted some assets remained in attacker wallets while a portion was mixed via Tornado Cash per Crypto.news.
The halt limited further damage while the team assessed losses and traced funds.
3. Containment And Scope
Yearn moved yETH pools into halt mode, activated a war room with SEAL911 and ChainSecurity, and confirmed V2/V3 vaults were unaffected per its initial notice and detailed incident update.
- The team emphasized isolation of the bug to yETH stableswap code, reassuring vault users per the incident update.
- A formal post?mortem was published for root?cause transparency and remediation steps per the post?mortem link on X.
If your exposure was through yETH pools, monitoring recovery and remediation steps is key; vault depositors were outside the blast radius per the notices above.
Conclusion
Yearn halted yETH pools because a contract?level bug enabled unlimited yETH minting that drained liquidity. Losses were contained to the affected pools, and V2/V3 vaults remained safe per official updates. The decisive pause, war room coordination, and post?mortem indicate a targeted response to a legacy code path rather than a broader protocol failure.
