TLDR
Yearn Finance (YFI) suffered the weeks leading DeFi exploit. Its yETH pool was hit by an infinite mint bug, with about $9 million drained, the largest disclosed DeFi loss in the past 7 days (Yearn post, news report).
- Scope. yETH stableswap custom code was impacted; Yearns main V2/V3 vaults were not affected (Yearn post).
- Cause and recovery. A numerical bug enabled infinite yETH minting; about $2.4 million equivalent was later recovered (analysis).
- Runner?up. USPD stablecoin saw a separate proxy?admin exploit of roughly $1 million (incident report).
Deep Dive
1. Yearn Led On Losses
The single largest DeFi exploit this week was Yearns yETH incident at roughly $9 million, outpacing other reported protocol losses in the period. Yearn confirmed the totals and scope publicly, noting the impact was isolated to the yETH stableswap pool and a smaller yETH?WETH pool on Curve, while V2/V3 vaults remained safe (Yearn post). Media coverage matched the size and sequence, highlighting this as the weeks dominant DeFi security event (news report).
In weekly terms, Yearns exploit set the tone for DeFi risk, with the largest disclosed loss and broad market attention relative to smaller incidents.
2. Bug Mechanics And Partial Recovery
Yearns post?mortem describes a combination of a low?level numerical bug and a high?level invariant issue that enabled infinite mint behavior in custom stableswap logic for yETH. The attacker minted a large amount of yETH, swapped into ETH and LSTs, and exited; later, coordinated efforts helped recover 857.49 pxETH (around $2.4 million) for users (analysis, post?mortem note).
- Root cause. A math/invariant flaw in custom stableswap code specific to yETH enabled infinite mint behavior (analysis).
- Scope control. Yearn said no other products used the same code path, limiting contagion (Yearn post).
- Recovery. Coordination with partners led to retrieval of part of the stolen value (~$2.4 million) (analysis).
Losses were material but not systemic across Yearn. Custom code paths can concentrate risk; diversity and isolation of modules help limit blast radius.
3. Runner?Up Incident (USPD)
The USPD stablecoin faced a distinct proxy?admin seize?and?mint exploit, with unauthorized minting and about $1 million in stETH outflows reported. The team urged revoking approvals and outlined how the attacker captured proxy control during deployment before executing the drain months later (incident report).
- Attack vector. Hidden proxy control enabled a later upgrade and mint event, not a logic bug in the audited contract.
- Impact. Around $1 million equivalent in losses.
- Action items. Team guidance emphasized revokes and investigation.
Beyond math bugs, proxy and admin?key hygiene remain a prime attack surface. Verification of deployment patterns and proxy governance is critical.
Conclusion
This weeks headline DeFi loss was Yearns yETH infinite mint exploit at about $9 million, with scope contained to custom stableswap code and partial recovery reported. A separate USPD proxy?admin exploit around $1 million underscored that deployment and upgrade controls are as critical as core contract math. Together, they highlight two dominant risk classes to watch now: numerical/invariant bugs in complex AMM logic and proxy governance vulnerabilities.
