Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Circle stock faces technical sell signal amid UAE license

    December 10, 2025

    Did BSTR get its bitcoin from Tether?

    December 10, 2025

    Validated, staking on eth2: #4 – Keys 🔑

    December 10, 2025
    Facebook X (Twitter) Instagram YouTube
    X (Twitter) Instagram YouTube LinkedIn
    Block Hub News
    • Lithosphere News Releases
    • Altcoins
      • Bitcoin
      • Coinbase
      • Litecoin
    • Crypto
    • Ethereum
    • Blockchain
    Block Hub News
    You are at:Home » Yearn Finance exploited as $3M flows to Tornado Cash
    Crypto

    Yearn Finance exploited as $3M flows to Tornado Cash

    James WilsonBy James WilsonDecember 1, 2025No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email



    Yearn Finance is dealing with a fresh security breach after an attacker exploited its yETH token contract and drained millions in ETH and liquid staking assets from Balancer pools.

    Summary

    • The exploit targeted an older yETH contract, allowing the attacker to mint an unlimited supply of tokens and empty the Balancer pool.
    • Around 1,000 ETH moved through Tornado Cash shortly after the attack, with more assets still held across the attacker’s wallets.
    • Yearn confirmed the issue is isolated from its V2 and V3 Vaults and is preparing a detailed report on the incident.

    The incident unfolded late on Nov. 30 when an attacker triggered an infinite-mint flaw inside the yETH contract. They then minted an impossibly large supply of yETH, more than 235 trillion tokens, in a single transaction. 

    With those tokens, the attacker moved quickly through Balancer pools, removing real assets, including ETH and popular staking derivatives. Initial traces show close to $3 million flowing through Tornado Cash shortly after the exploit, while the attacker’s address still holds additional assets tied to the event.

    Exploit isolated to legacy yETH product

    Blockchain data shows the yETH stableswap pool was emptied within minutes, leaving a roughly $2.8 million hole. Yearn Finance(YFI) said the issue sits within an older implementation of yETH and does not touch its V2 or V3 Vaults. Protocols built on Yearn V3, including Katana, also reported no exposure.

    We are investigating an incident involving the yETH LST stableswap pool.

    Yearn Vaults (both V2 and V3) are not affected.

    — yearn (@yearnfi) November 30, 2025

    Several helper contracts appeared just moments before the attack and vanished through self-destruct calls once the pool was drained, making the trail harder to follow.

    Security teams reviewing the transactions, including auditors tracking Yearn’s older products, linked the event to a long-standing minting weakness inside the yETH token logic, rather than a problem in Yearn’s current vault architecture.

    The protocol maintains a live bug bounty program with rewards reaching $200,000 for critical discoveries, though no recovery path has been announced yet.

    On-chain movement intensifies after liquidity drain

    Soon after the pool collapsed, X user Togbo flagged several movements of 100 ETH batches passing through Tornado Cash. Around 1,000 ETH in total was mixed in the hours following the exploit. The attacker still retains additional assets worth several million dollars across multiple wallets.

    some other balancer related stuff looking like an exploit considering heavy interactions with tornado

    yearn, rocket pool, origin, dinero and other LST going around pic.twitter.com/wUuexeQJyg

    — Togbe (@Togbe0x) November 30, 2025

    The yETH pool carried roughly $11 million before the breach, and while the final loss number is still under review, Yearn said user funds inside active vaults remain safe.

    This incident adds to the protocol’s long record of managing legacy risks, coming years after its 2021 yDAI exploit and a 2023 treasury misconfiguration that did not affect depositors. YFI slipped about 4% after the event and traded near $4,002 at press time.





    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleWill Larry Ellison’s TikTok be safer than Chinese TikTok?
    Next Article Devcon Scholars Returns & Announcing Devcon Week!
    James Wilson

    Related Posts

    Circle stock faces technical sell signal amid UAE license

    December 10, 2025

    US regulator OKs banks to handle cryptocurrency transactions

    December 10, 2025

    Visa survey reveals AI, crypto influence on holiday shopping

    December 9, 2025
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Circle stock faces technical sell signal amid UAE license

    December 10, 20250 Views

    Did BSTR get its bitcoin from Tether?

    December 10, 20250 Views

    Validated, staking on eth2: #4 – Keys 🔑

    December 10, 20250 Views

    US regulator OKs banks to handle cryptocurrency transactions

    December 10, 20250 Views
    Don't Miss

    Devconnect is back! See you this year in Istanbul.

    By Olivia MartinezNovember 28, 2025

    Dear Ethereum community, builders, and researchers, At the first-ever Devconnect last year in Amsterdam in…

    BTC, ETH, XRP eye recovery

    November 19, 2025

    Ethereum.org Translation Program: Milestones and Updates

    December 4, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    Demo
    X (Twitter) Instagram YouTube LinkedIn
    Our Picks

    Circle stock faces technical sell signal amid UAE license

    December 10, 2025

    Did BSTR get its bitcoin from Tether?

    December 10, 2025

    Validated, staking on eth2: #4 – Keys 🔑

    December 10, 2025
    Most Popular

    Devconnect is back! See you this year in Istanbul.

    November 28, 202525 Views

    BTC, ETH, XRP eye recovery

    November 19, 20254 Views

    Ethereum.org Translation Program: Milestones and Updates

    December 4, 20253 Views
    © 2025 - 2026

    Type above and press Enter to search. Press Esc to cancel.