Yearn Finance's yETH Exploited: Millions Drained

An infinite-mint vulnerability in the legacy yETH token contract led to significant losses for Yearn Finance users.

Author
Branden Chen
Senior Crypto AnalystDecember 1, 2025
Bitcoin trading chart with upward trend

Yearn Finance's yETH Exploited: Millions Drained

Yearn Finance experienced a major exploit targeting its yETH product, resulting in the loss of approximately $2.8 million. The vulnerability stemmed from an infinite-mint flaw in the yETH token contract, allowing the attacker to create a massive amount of yETH and subsequently drain liquidity from Balancer pools.

What Happened?

  • The attack occurred when a malicious wallet exploited the infinite-mint vulnerability to create roughly 235 trillion yETH tokens in a single transaction.
  • The attacker then used these newly minted tokens to drain assets, primarily ETH and Liquid Staking Tokens (LSTs), from Balancer liquidity pools.
  • Approximately 1,000 ETH was laundered through Tornado Cash in the aftermath.
  • Several helper contracts used in the exploit were self-destructed shortly after to conceal the trail.

Impact and Response

Yearn Finance has stated that V2 and V3 Vaults were unaffected, and the vulnerability was isolated to the legacy yETH implementation. The protocol's Total Value Locked (TVL) remains above $600 million, suggesting that core systems were not compromised.

Market Reaction

Interestingly, the price of YFI initially spiked following news of the exploit. This appears to be due to short-sellers covering their positions after initial claims of a broader "Yearn exploit" prompted heavy shorting. The thin liquidity of YFI amplified this price movement.

Key Takeaways

  • The exploit highlights the importance of thorough security audits, especially for older contracts.
  • Even seemingly isolated vulnerabilities can have significant financial consequences.
  • Market reactions to exploits can be unpredictable, especially for low-liquidity assets.

Ongoing investigations aim to determine if any recovery options exist for the stolen funds. Users are advised to stay informed about official Yearn Finance announcements.

Investment Considerations

As always, investors should consider their risk tolerance and investment timeline before making allocation decisions. Bitcoin remains a volatile asset despite increasing institutional adoption.

This article is for informational purposes only and should not be considered investment advice. Always consult with a qualified financial advisor.

Related Posts

Balancer Proposes Reimbursement Plan After $128M Exploit

DeFi protocol outlines how it will distribute recovered funds to affected liquidity providers following a major security breach.

GMX Exchange Hit by $40 Million Exploit

Decentralized exchange GMX pauses trading after a significant security breach impacting its V1 platform on Arbitrum.

Hackers Exploit ETH Surge: $72M Profit Realized

Cybercriminals cash in on Ether's price rally, converting stolen ETH into substantial stablecoin profits.

Crypto Hacks: September Losses Dip, But Danger Still Lurks

Despite a 22% decrease, over $127 million was pilfered in September 2025, highlighting ongoing security vulnerabilities in the crypto space. UXLINK and SwissBorg took the biggest hits.