Gm to everyone who woke up to @yearnfi attack.
Here's your morning note on what has happened ↓
When: November 30, 2025.
Affected product: yETH (Yearn Ether)
Losses: $8-9 million.
Attack flow:
• Deployment: Attacker deployed custom smart contracts designed specifically for this exploit
• Execution Single transaction minted massive amounts of yETH tokens
• Drainage: Used minted tokens to drain approximately $8M from the yETH pool and ~$900K from the yETH-WETH pool on Curve
• Laundering: Transferred 1,000 ETH (~$3M) to Tornado Cash
• Cleanup: Self-destructed attack contracts to remove evidence
What was affected:
✅ yETH product only – the legacy liquid staking token aggregator
✅ yETH-WETH Curve pool – secondary impact
What was NOT affected:
❌ Yearn V2 Vaults
❌ Yearn V3 Vaults
❌ Other Yearn products
This guy → @Togbe0x → Helped to identify this early.
Key lessons:
• This case highlights the ongoing risk of legacy code in DeFi protocols
• Demonstrates that even battle-tested protocols can have hidden vulnerabilities in older products
• Shows the value of modular architecture – isolating products prevented contagion
• The infinite mint vulnerability is a classic DeFi attack vector that continues to plague protocols
• Proper access controls and mint limits are critical for token contracts
Be safe.
1.75萬
135
本頁面內容由第三方提供。除非另有說明,OKX 不是所引用文章的作者,也不對此類材料主張任何版權。該內容僅供參考,並不代表 OKX 觀點,不作為任何形式的認可,也不應被視為投資建議或購買或出售數字資產的招攬。在使用生成式人工智能提供摘要或其他信息的情況下,此類人工智能生成的內容可能不準確或不一致。請閱讀鏈接文章,瞭解更多詳情和信息。OKX 不對第三方網站上的內容負責。包含穩定幣、NFTs 等在內的數字資產涉及較高程度的風險,其價值可能會產生較大波動。請根據自身財務狀況,仔細考慮交易或持有數字資產是否適合您。



