Yearn Finance Recovers $2.4M After $9M Exploit of Legacy yETH Pool
Yearn Finance is in the process of recovering assets after a complex exploit that drained around $9 million from its legacy yETH pools on Sunday. The attacker exploited a flaw in an outdated contract, allowing them to mint an excessive number of yETH tokens, which were then used to withdraw liquidity from Curve's stableswap and smaller yETH-WETH pools.
As of now, Yearn has recovered approximately $2.4 million of the stolen assets. The recovery effort is ongoing with the help of external security teams, including SEAL 911, ChainSecurity, and Plume Network. The team confirmed that their V2 and V3 products, which are central to Yearn's current operations, were unaffected by the exploit, which only targeted the older yETH pool.
This incident marks the third attack on Yearn since 2021 and highlights the vulnerability of legacy DeFi contracts. The attacker manipulated an unchecked arithmetic bug in the minting logic of the yETH pool, creating an astronomical supply of tokens. The post-mortem reveals that the exploit involved a series of batched actions and temporary smart contracts designed to handle the minting process before self-destructing.
The exploit has raised concerns about the risks posed by outdated DeFi contracts, with many still holding user funds despite being inactive or lightly maintained. The recovery efforts have underscored the importance of cross-team cooperation and real-time monitoring in decentralized finance (DeFi) ecosystems. Yearn has assured users that any recovered funds will be returned to affected depositors.
While the investigation continues, Yearn remains focused on recovering more assets and addressing potential vulnerabilities in its legacy systems. The breach serves as a reminder of the risks associated with older contracts in the rapidly evolving DeFi space.
Subscribe Now

