Cryptocurrency [loss] $304,400

Tweet by PeckShield

2025-12-16 [vendor] Yearn Finance [chain] ethereum
Primary Source ↗
Financial Loss $304,400 (304,400 USD)
Blockchain(s) Ethereum

Incident Details

Only weeks after losing $6.6 million to an infinite mint exploit, a Yearn Finance smart contract has again been exploited, allowing an attacker to make off with around 103 ETH (~$300,000). The affected contract is a legacy contract that was part of the Yearn v1 project (once known as iearn). The attacker used a flash loan to manipulate the price of tokens in the vault, allowing them to withdraw the iearn assets, which they then swapped for ETH.This is Yearn’s fourth hack, following the $6.6 million theft in November, an $11 million exploit in 2023, and an $11 million exploit in 2021. Yearn also lost around $1.4 million in 2023 in connection to the Euler Finance attack.

Total loss estimated at $304,400.

Technical Details

Initial Attack Vector
Flash loan attack on smart contract
Vendor / Product
Yearn Finance

Timeline

  1. 2025-12-16 Breach occurred
  2. 2025-12-16 Publicly disclosed