TLDR
Notable user?impacting incidents this week include a Yearn Finance legacy vault exploit, a whale multisig takeover, and widespread wallet?drainer attacks tied to a React vulnerability.
- Yearn Finance legacy iEarn vault was exploited for about $300,000, with funds swapped to roughly 103 ETH per a report this week (coverage).
- A whales multisig was taken over minutes after creation and drained in stages, with losses estimated up to ~$40 million (incident report).
- Wallet?drainer campaigns are actively exploiting React CVE?2025?55182 across websites, prompting urgent patching advisories (security alert).
Deep Dive
1. Yearn Legacy Vault
A deprecated Yearn Finance (YFI) iEarn vault was hit for roughly $300,000, with the exploiter converting the take to about 103 ETH. Reports emphasize that current Yearn vaults were not affected, as the issue was limited to an old iEarn contract from early iterations of the protocol. See details and the teams clarification in this weeks coverage of the exploit (report).
If you interacted with older Yearn iEarn contracts, review approvals and balances. Current Yearn vaults were reported as unaffected, but legacy exposure still carries risk.
2. Whale Multisig Takeover
Forensics indicate an attacker seized control of a whales multisig minutes after it was created, likely due to key compromise or misconfiguration, and then drained funds over weeks. Analysis cites ~$27.3 million confirmed drained and suggests total losses may exceed $40 million, with laundering via Tornado Cash and an Aave position still under attacker control (summary).
Operational security failures can nullify multisig benefits. If you recently created high?value wallets, verify signer devices, threshold settings, and any ownership changes on?chain.
3. Wallet?Drainer Campaigns via React CVE
Security groups warn of active wallet?drainer injections on legitimate sites via React CVE?2025?55182, an RCE affecting React Server Components that received patches on Dec 3. Users are facing malicious signature prompts and permit traps on otherwise trusted front ends (technical brief). Separately, researchers also highlight near?daily Fake Zoom social?engineering attacks linked to North Korea that seed malware and steal wallet keys, with cumulative losses estimated around $300 million (research recap).
Even trusted sites can be compromised. Developers should patch React Server Components immediately and audit front?end assets. Users should verify transaction recipients and avoid signing unexpected permit requests.
Conclusion
This weeks user?impacting incidents cluster around legacy DeFi code, operational security lapses in wallet setup, and supply?chain or social?engineering vectors that corrupt trusted interfaces. The practical takeaway is simple: patch and audit quickly, verify signer setups, and treat any unusual signature prompt or fix file as high risk.
