Yearn Finance reported that the legacy yETH product fell sufferer to an exploit that allowed attackers to mint giant quantities of faux tokens and change them for actual belongings.
Based on on-chain alerts and protocol statements, the attacker created a near-infinite provide of yETH in a single transaction and used these tokens to withdraw ETH and liquidity staking derivatives from the liquidity pool.
This incident was first reported on November 30, 2025, with a reported complete impression of roughly $9 million.
#PecShieldAlert yearn finance @yearnfi The assault resulted in a complete lack of roughly $9 million.
The exploit concerned minting a virtually infinite variety of yETH tokens and depleting the pool in a single transaction.
~1K $ETH (roughly $3 million price) despatched #TornadoCashwhereas the exploiters… pic.twitter.com/IXNygpwoWa
— PeckShield Alert (@PeckShieldAlert) December 1, 2025
How the exploit works
primarily based on reportattackers exploited a flaw within the yETH minting logic to generate on the order of 235 trillion tokens without delay.
These nugatory tokens had been exchanged for actual belongings from Balancer and Curve swimming pools related to the product, emptying their liquidity in minutes. Chain watchers and safety researchers have proven that mints and subsequent swaps unfold in a short time on the blockchain.
On November thirtieth at 21:11 UTC, an incident associated to the yETH stableswap pool occurred and a considerable amount of yETH was minted. The affected contracts are customized variations of the favored Stableswap code which are unrelated to different Yearn merchandise. Yearn V2/V3 vaults usually are not in danger.
— Yearn (@yearnfi) December 1, 2025
What belongings had been taken?
The report revealed that roughly $8 million was withdrawn from the principle yETH steady swap pool and roughly $900,000 was withdrawn from the yETH-WETH pool.
Moreover, roughly 1,000 ETH (valued at roughly $3 million on the time of the switch) was transferred to Twister Money in an try and cowl their tracks. The attackers transformed the pretend yETH into a combination of ETH and liquidity staking tokens earlier than making an attempt to launder the funds.
Impression on Yearn’s core product
Based on Yearn officers and follow-up studies, violation This was restricted to older legacy implementations of the yETH product and didn’t have an effect on Yearn’s predominant V2 and V3 vaults.
Sediment within the affected pool was remoted whereas the workforce and exterior specialists started an investigation. This quarantine is alleged to have resulted in a big portion of person funds held in lively vaults being untouched.
Market response and widespread issues
Cryptocurrency markets got here beneath promoting strain because the information unfold, and merchants thought of the dangers of mixing liquid staking tokens with customized swap codes.
yearn finance The corporate mentioned it was working with an exterior safety workforce to conduct a autopsy investigation and repair the vulnerability. The workforce named within the report consists of exterior auditors and blockchain researchers who’re monitoring stolen funds and advising on restoration choices, in line with the report.
The protocol discover alerted customers to affected legacy merchandise and urged warning whereas the assessment continues.
Featured picture from Unsplash, chart from TradingView

