Yearn Finance Suspected of Attack, Hacker Sends 1,000 ETH of Stolen Funds to Tornado Cash
BlockBeats News, December 1st, according to The Block, Yearn Finance appears to have been attacked, with its Yearn Ether (yETH) product, which aggregates popular Liquid Staking Tokens (LST), being drained of millions of dollars' worth of LST assets.
Blockchain data shows that the attacker exploited a carefully crafted vulnerability to mint nearly an infinite amount of yETH tokens in a single transaction, completely draining the pool. The attack transaction resulted in 1,000 ETH (valued at approximately $3 million at current prices) being sent to the Tornado Cash privacy protocol. This attack involved multiple newly deployed smart contracts, some of which self-destructed after the transaction. The exact scale of the loss is currently unclear, but prior to the attack, the yETH pool's size was around $11 million.
This hack was first discovered by user X, Togbe, who noticed the attack while monitoring large transfers. "On-net transfer shows an over mint of yETH that allowed the attacker to drain the pool somehow and make a profit of around 1,000 ETH," Togbe stated in the message. "Part of the ETH was sacrificed along the way for reasons unknown, but they still made a profit in the end."
"We are investigating the incident involving the yETH LST StableSwap pool," Yearn stated on X, "Yearn's V2 and V3 Vaults are unaffected."
Yearn Finance previously suffered an attack in 2021, affecting its yDAI insurance vault, resulting in a loss of $11 million, with the hacker ultimately profiting $2.8 million. In December 2023, the protocol saw a 63% loss in one of its vault positions due to a scripting error, but user funds were unaffected. Yearn's founder, Andre Cronje, started the project in 2020 and departed two years later.
You may also like

In the next 5 years, Vitalik will scale Ethereum like this

Sam Altman and the End of the World Capitalism

Wall Street Rings Inflation Alarm Bells Amid Iran Tensions, What Does It Mean for Cryptocurrency?

Qwen Open Source Model Enters Mobile, Nasdaq Tests Water Prediction Market, What's the Overseas Crypto Community Talking About Today?

MegaETH Co-founder: 48 Hours After Escaping Dubai, I Reassess the Entire Crypto Scene

Morning Report | Strategy increased its holdings by 3,015 bitcoins last week; BitMine increased its holdings by 50,928 ETH last week; Vitalik elaborated on the Ethereum execution layer roadmap

Why is it said that there are structural opportunities in encrypted AI?

Make Probability an Asset: A Forward-Looking Perspective on Predictive Market Agents

Consumer application issues

Arthur Hayes: The flames of war in the Middle East rise, Bitcoin is bullish

Legendary investor Naval: In the AI era, traditional software engineers have no value?

More absurd than knowing about the war in advance is knowing in advance about the assassination of Soleimani

Key Market Insights on March 2nd, how much did you miss?

How to systematically track high-performing addresses on Polymarket?

From Stanford Lab to Silicon Valley Streets: How OpenMind is Solving the "Last Mile" Problem of the Machine Economy?

PlanX: Reconstructing On-Chain Execution with AI, Moving Towards a New Paradigm

US Judge Allows Binance Unregistered Token Lawsuit to Advance
Key Takeaways: A federal judge in Manhattan dismissed Binance’s petition to resolve a securities lawsuit through private arbitration,…

Crypto VC Paradigm Plans $1.5 Billion Expansion into AI and Robotics
Key Takeaways: Paradigm is setting up a new $1.5 billion fund to explore AI, robotics, and other emerging…