TLDR
Losses this week came mainly from a legacy Yearn iEarn vault exploit, active wallet?drainer campaigns abusing a React vulnerability, and a handful of targeted wallet compromises.
- Yearn Finance iEarn legacy vault exploit drained about $300,000%%CKPROTECTED2%%, with current Yearn vaults unaffected per a report.
- A critical React CVE enabled wallet?drainer code on legitimate crypto sites, prompting broad patch advisories and active?exploitation warnings in a security update.
- Additional losses included a ZEROBASE frontend breach over $240,000%%CKPROTECTED2%% in user funds per a notice.
Deep Dive
1. Yearn Legacy Vault
The largest single DeFi incident this week was a legacy iEarn contract tied to Yearn Finance, with attackers extracting roughly $300,000%%CKPROTECTED3%% and converting to about 103 ETH. Current Yearn vaults were not impacted, and the issue was constrained to an old immutable contract, according to coverage that also noted follow?on token pressure and TVL slippage since an earlier December incident (CoinDesk, The Defiant).
Legacy contracts can become soft targets. When protocols modernize, older artifacts may still carry residual risk even if core vaults are sound.
2. Frontend Drainers via React CVE
Security teams flagged active exploitation of a critical React Server Components vulnerability that allows unauthenticated code execution and wallet?drainer script injection on otherwise legitimate sites. Operators were urged to patch immediately and review signature flows, with emphasis that even non?Web3 sites using vulnerable packages could be conduits for attacks (Cointelegraph, Finance Magnates).
Losses here are diffuse and user?driven. The main driver is social and UI trust. Users and projects should treat unexpected signature prompts and front?end changes as high risk until patched.
3. Targeted Wallet and Smaller Platform Hits
Losses also came from smaller, targeted compromises. ZEROBASE suffered a frontend breach exceeding $240,000%%CKPROTECTED4%% across more than 270 users, highlighting phishing and authorization hijacks on BNB Chain interfaces (notice). Separately, individual compromises hit users, including a crypto executive whose wallet was drained of over $30,000%%CKPROTECTED6%% tied to a legacy Thirdweb bridge contract exposure (report), and a Singapore entrepreneur who lost over $100,000%%CKPROTECTED8%% to malware packaged as a beta game launcher (case study).
The weeks long tail losses skew toward front?end impersonation, stale approvals, and targeted malware rather than a single mega?exploit. Vigilance on signatures and software provenance matters.
Conclusion
This weeks losses were driven by three patterns working in parallel: legacy contract exposure at Yearns iEarn, front?end supply?chain attacks exploiting a React CVE, and targeted user compromises. Near term, the biggest risk is not a single giant hack but many smaller drains via front?end trust and stale approvals. Monitoring official incident posts and treating unexpected signature prompts with skepticism can materially reduce exposure.
