Cryptocurrency
[loss] $304,400
Tweet by PeckShield
Primary Source ↗Financial Loss
$304,400
(304,400 USD)
Blockchain(s)
Ethereum
Incident Details
Only weeks after losing $6.6 million to an infinite mint exploit, a Yearn Finance smart contract has again been exploited, allowing an attacker to make off with around 103 ETH (~$300,000). The affected contract is a legacy contract that was part of the Yearn v1 project (once known as iearn). The attacker used a flash loan to manipulate the price of tokens in the vault, allowing them to withdraw the iearn assets, which they then swapped for ETH.This is Yearn’s fourth hack, following the $6.6 million theft in November, an $11 million exploit in 2023, and an $11 million exploit in 2021. Yearn also lost around $1.4 million in 2023 in connection to the Euler Finance attack.
Total loss estimated at $304,400.
Technical Details
- Initial Attack Vector
- Flash loan attack on smart contract
- Vendor / Product
- Yearn Finance
Timeline
- 2025-12-16 Breach occurred
- 2025-12-16 Publicly disclosed