Need help? Support
BITCOIN
Tether Dominance USDT.D

Which DeFi protocol was hacked?

Published 391 words 2 min read

TLDR

Yearn Finance (YFI) was the DeFi protocol hacked this week, with about $9 million drained from its yETH StableSwap pool after an infinite-mint style exploit was triggered by a math bug in the contract (coverage).

  1. Cause. A numerical bug let the attacker mint roughly 235 trillion yETH and siphon funds from yETH pools (details).
  2. Scope. Yearn said the incident was isolated to the custom yETH StableSwap, with core vaults unaffected (post mortem summary).
  3. Recovery. Roughly $2.4 million in assets were secured with partner support and will be returned to users (see the report above).

Deep Dive

1. Exploit Mechanics

The attacker exploited a low-level math error to mint near-infinite yETH, drained the pool in a single transaction, and routed about 1,000 ETH through Tornado Cash to obfuscate flows (incident recap). This class of infinite mint bugs typically stems from arithmetic or invariant-management mistakes that let supply inflate while price accounting appears consistent (see the coverage above for context).

What this means

Math and invariant errors are subtle and can pass audits. Pools holding derivative tokens and complex pricing logic deserve extra caution.

2. Impact and Containment

Initial loss estimates were around $9 million, including roughly $8 million from the main yETH StableSwap and about $0.9 million from a yETH-WETH pool on Curve (loss breakdown). Yearn emphasized that V2 and V3 vaults were unaffected and that the issue was isolated to custom yETH code (see the post mortem summary above).

What this means

If you only used Yearns standard vaults, direct exposure to this incident was limited. Users of the affected yETH pools were the primary risk cohort.

3. Response and Market Context

Yearn coordinated with partners and recovered about 857.49 pxETH (approximately $2.4 million) for restitution to impacted users (recovery noted). The hack followed a month in which Balancer suffered a cross-chain exploit exceeding $116 million, underscoring ongoing DeFi security pressure (context).

What this means

Recovery is possible when incidents are contained quickly and liquidity is traceable, but broader exploit frequency remains a systemic risk for complex DeFi primitives.

Conclusion

Yearn Finance was the high-profile DeFi hack this week, driven by a contract arithmetic flaw in its yETH pool that enabled infinite minting and a roughly $9 million drain. The affected code was isolated, some funds were recovered, and broader sector risk remains elevated given recent large exploits like Balancers. Keep an eye on official Yearn updates and consider limiting exposure to complex pool mechanics until post-mortems and fixes are fully deployed.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top