Close Menu
Altcoin ObserverAltcoin Observer
  • Regulation
  • Bitcoin
  • Altcoins
  • Market
  • Analysis
  • DeFi
  • Security
  • Ethereum
Categories
  • Altcoins (2,408)
  • Analysis (2,561)
  • Bitcoin (3,164)
  • Blockchain (1,936)
  • DeFi (2,312)
  • Ethereum (2,225)
  • Event (89)
  • Exclusive Deep Dive (1)
  • Landscape Ads (2)
  • Market (2,367)
  • Press Releases (10)
  • Reddit (1,829)
  • Regulation (2,212)
  • Security (3,042)
  • Thought Leadership (3)
  • Videos (43)
Hand picked
  • Everything you need to know about the Yearn Finance exploit
  • USDC Cross-Chain Integration Connects HyperCore and HyperEVM
  • Galaxy Digital transfers 900 Bitcoins to a newly created wallet
  • Jamie Dimon rejects Trump media claim of ‘unbanking’
  • Major Bank CEOs to Meet with Senators to Discuss Crypto Market Regulation (C:NYSE)
We are social
  • Facebook
  • Twitter
  • Instagram
  • YouTube
Facebook X (Twitter) Instagram
  • About us
  • Disclaimer
  • Terms of service
  • Privacy policy
  • Contact us
Facebook X (Twitter) Instagram YouTube LinkedIn
Altcoin ObserverAltcoin Observer
  • Regulation
  • Bitcoin
  • Altcoins
  • Market
  • Analysis
  • DeFi
  • Security
  • Ethereum
Events
Altcoin ObserverAltcoin Observer
Home»Bitcoin»Everything you need to know about the Yearn Finance exploit
Bitcoin

Everything you need to know about the Yearn Finance exploit

December 9, 2025No Comments
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Yearn Finance published a detailed analysis of last week’s yETH exploit, explaining how a digital breach in one of its legacy stablecoin exchange pools allowed an attacker to create a nearly unlimited amount of LP tokens and steal approximately $9 million in assets.

The DeFi platform said it has already recovered part of the stolen funds.

In the reportYearn said the attack hit the yETH weighted stablecoin exchange pool at block 23,914,086 on November 30, 2025.

Disclosure of incidents

DISCOVER: Top 20 cryptocurrencies to buy in 2025

Which Yearn products were affected and which remained safe?

The breach followed what the team described as “a complex sequence of operations” that pushed the pool’s internal solver into a divergent state and then triggered an arithmetic overflow.

Yearn noted that its v2 and v3 safes, along with the rest of its products, “have not been affected.” The impact has remained limited to yETH and related systems.

The attacker targeted a custom stableswap pool containing several liquid staking tokens: apxETH, sfrxETH, wstETH, cbETH, rETH, ETHx, mETH, and wOETH, as well as a yETH/WETH curve pool.

According to Yearn’s asset snapshot, the pools held a mix of LST and 298.35 WETH before the exploit occurred.

Yearn’s autopsy divides the attack into three clear stages.

In the first stage, the attacker used a series of unbalanced add_liquidity deposits that pushed the pool’s fixed-point solver into a state it was not designed for.

This move caused the inner product term, Π, to fall to zero. Once this happened, the weighted stable swap invariant failed, allowing the attacker to create many more yETH LP tokens than the value they had actually deposited.

With these inflated LP tokens in hand, the attacker moved on to the next phase.

They repeatedly called remove_liquidity and related functions, removing almost all of the LST liquidity. The bulk of the losses fell on the liquidity owned by the protocol within the staking contract.

DISCOVER: 9+ Best High Risk, High Reward Cryptocurrencies to Buy in 2025

What funds do you aspire to recover so far, and who will receive them?

According to Strivethis sequence drove the pool’s internal supply to zero even though ERC-20 balances still showed tokens in the contract.

In the last step, the attacker slipped into a “bootstrap” initialization path that was only intended for the first launch of the pool.

By sending a counterfeit dust-level setup that violated a key domain rule, they triggered a dangerous subtraction. This substream created a massive batch of new yETH LP tokens and completed the feat.

Yearn said the underflow was so severe that it created what the team called an “infinite mint.” The attacker used this flaw to drain the yETH/ETH curve pool.

The project said it has collected 857.49 pxETH so far with the help of the Plume and Dinero teams. A recovery operation took place on December 1.

Yearn plans to return recovered assets to yETH depositors on a pro-rata basis, using balances immediately before the exploit. Any subsequent recoveries, whether due to attacker cooperation or further tracing efforts, will also be returned to depositors. The timeline published by Yearn shows that a war room formed approximately 20 minutes after the breach.

The SEAL 911 Task Force joined shortly after. Investigators say the attacker sent 1,000 ETH to Tornado Cash later that night and transferred the remaining funds through the mixer on December 5.

An earlier report from The Block indicated that approximately $3 million in ETH was transferred via Tornado Cash in the hours following the attack.

The post-mortem also reminds users that YIP-72 governs yETH. He highlights the product’s “Use at our own risk” clause, which states that Yearn contributors and YFI governance are not responsible for covering losses.

The report states that all recovered funds will be returned to affected users.

DISCOVER: 15+ Coinbase Lists to Watch in 2025

The post Everything You Need to Know About Yearn Finance Exploit appeared first on 99Bitcoins.



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleUSDC Cross-Chain Integration Connects HyperCore and HyperEVM

Related Posts

Bitcoin

South Korea strengthens its grip on crypto exchanges and imposes standards at the banking level

December 9, 2025
Bitcoin

Paradigm Leads Crown Real-Anchor Stablecoin BRLV With $13.5M Round Support

December 8, 2025
Bitcoin

Dogecoin Reports Growing Troubles – Is a Drop to $0.081 Next?

December 8, 2025
Add A Comment
Leave A Reply Cancel Reply

Single Page Post
Share
  • Facebook
  • Twitter
  • Instagram
  • YouTube
Featured Content
Event

Game On with the Titans of Gaming: Global Games Show 2025 Unveils Star Speaker Lineup

December 8, 2025

Abu Dhabi, UAE – VAP Group has officially unveiled the lineup of power-packed global speakers…

Event

Global Blockchain Show 2025 to Spotlight Web3 Innovation in Abu Dhabi

December 8, 2025

Abu Dhabi, UAE – The Global Blockchain Show 2025 will take place at the prestigious…

1 2 3 … 66 Next
  • Facebook
  • Twitter
  • Instagram
  • YouTube

USDC Cross-Chain Integration Connects HyperCore and HyperEVM

December 9, 2025

ZCash (ZEC) price jumps 8%, recovery or dead cat rebound?

December 9, 2025

Double Zero climbs 10% after 25% drop – 2Z recovery begins?

December 8, 2025
Facebook X (Twitter) Instagram LinkedIn
  • About us
  • Disclaimer
  • Terms of service
  • Privacy policy
  • Contact us
© 2025 Altcoin Observer. all rights reserved by Tech Team.

Type above and press Enter to search. Press Esc to cancel.

bitcoin
Bitcoin (BTC) $ 90,419.23
ethereum
Ethereum (ETH) $ 3,120.22
tether
Tether (USDT) $ 1.00
xrp
XRP (XRP) $ 2.07
bnb
BNB (BNB) $ 893.23
usd-coin
USDC (USDC) $ 1.00
solana
Wrapped SOL (SOL) $ 133.39
staked-ether
Lido Staked Ether (STETH) $ 3,119.90
tron
TRON (TRX) $ 0.280623
dogecoin
Dogecoin (DOGE) $ 0.141433