A legacy version of the decentralized finance protocol Yearn has suffered an exploit, reviving concerns about misconfigured and immutable smart contracts that haveA legacy version of the decentralized finance protocol Yearn has suffered an exploit, reviving concerns about misconfigured and immutable smart contracts that have

YearnFinanceV1 suffers $300,000 exploit to legacy TUSD vault

2025/12/17 18:45
4 min di lettura
Per feedback o dubbi su questo contenuto, contattateci all'indirizzo [email protected].

A legacy version of the decentralized finance protocol Yearn has suffered an exploit, reviving concerns about misconfigured and immutable smart contracts that have held funds on the network years after being deprecated.

In an X post on Wednesday, Security firm PeckShield reported YearnFinanceV1’s hack resulted in losses of about $300,000. The stolen funds were swapped into 103 Ether and now sit at address 0x0F21…4066, according to Etherscan images shared by the firm.

The hackers took advantage of an outdated Yearn vault tied to TrueUSD, known as the “iearn TUSD vault,” which is still deployed on Ether despite being superseded by newer versions. A configuration flaw helped the attackers manipulate share prices through several transactions.

Yearn Finance misconfigured vault triggered price manipulation 

According to an analysis from pseudonymous crypto researcher and University of Science and Technology of China alumnus Weilin Li, the vault configured one of its strategies as a Fulcrum sUSD vault and calculated its share price using only the sUSD balance deposited.

This opened the door to so-called “donation attacks,” in which an attacker transfers assets directly into a vault to distort accounting metrics. After sending Fulcrum sUSD tokens into the Yearn TUSD vault, the perpetrators were able to artificially inflate the vault’s reported share price.

The issue was compounded by a rebalance function that withdraws all underlying assets in sUSD, an asset not included in the vault’s share price calculations. When the rebalance started, the vault’s share price tanked steeply and created a “price shock.”

Per PeckShield Alert’s Etherscan snapshot, the attacker executed sequenced flash loans by firstly borrowing large amounts of TUSD and sUSD without an upfront collateral. They then deposited sUSD to mint Fulcrum sUSD tokens before depositing TUSD into the Yearn TUSD vault. 

At that stage, all underlying assets of the TUSD vault consisted of Fulcrum sUSD tokens. The exploiter withdrew from the Yearn TUSD vault and called the rebalance function, forcing Fulcrum to redeem everything into sUSD. Because sUSD was excluded from share price calculations, the vault’s accounting collapsed, effectively driving the share price toward zero.

The attacker then transferred a small amount of TUSD back into the vault, pushing the share price to extremely low levels, and minted an outsized number of Yearn TUSD tokens at minimal cost. He ultimately counted gains by selling the cheaply acquired Yearn TUSD tokens on Curve pools, extracting value from liquidity providers before repaying the flash loans.

Yearn Finance recaps 2023 vulnerability, researcher recounts

Researcher Li found that the exploit was similar to an attack carried out in 2023, leading to losses exceeding $10 million. The immutable yUSDT contract targeted in that earlier incident was deployed more than three years ago, during the early days of iearn when the late Andre Cronje led the protocol.

Pessimistic security analysts had issued a warning about the vulnerability on social media before the exploit, but since immutable smart contracts cannot be patched or paused once deployed, it was inevitable.

 “iearn finance, Smoothswap, be careful. This address 0x5bac20…ed8e9cdfe0 got 10 ETH from Tornado and deploys contracts with flashloans using your addresses,” PS’ Nikiti Kirillov wrote.

A Yearn team member known as storming0x admitted the attack happened and reassured users that its current contracts were safe. Yet, Rekt News observers revealed it took 1,156 days for the DeFi protocol to spot a multimillion-dollar vulnerability.

Yearn yUSDT token contract generated yield from a basket of yield-bearing positions, including USDT deposits on Aave, Compound, dYdX and BzX’s Fulcrum. Since launch, however, yUSDT contained a copy-and-paste error which referenced the Fulcrum USDC address instead of the Fulcrum USDT contract. 

Using just 10,000 USDT, hackers were able to mint approximately 1.2 quadrillion yUSDT, draining value from the system before cashing out.

The Yearn incident comes less than a week after Cryptopolitan featured a $2.7 million drainage from an old contract belonging to Ribbon Finance, the rebranded version of Aevo. That attack involved repeated interactions with a proxy admin contract at address 0x9D7b…8ae6B76. The attacker invoked functions such as transferOwnership and setImplementation to manipulate price-feed proxies through delegate calls.

Get seen where it counts. Advertise in Cryptopolitan Research and reach crypto’s sharpest investors and builders.

Opportunità di mercato
Logo TrueUSD
Valore TrueUSD (TUSD)
$0.9999
$0.9999$0.9999
-0.01%
USD
Grafico dei prezzi in tempo reale di TrueUSD (TUSD)
Disclaimer: gli articoli ripubblicati su questo sito provengono da piattaforme pubbliche e sono forniti esclusivamente a scopo informativo. Non riflettono necessariamente le opinioni di MEXC. Tutti i diritti rimangono agli autori originali. Se ritieni che un contenuto violi i diritti di terze parti, contatta [email protected] per la rimozione. MEXC non fornisce alcuna garanzia in merito all'accuratezza, completezza o tempestività del contenuto e non è responsabile per eventuali azioni intraprese sulla base delle informazioni fornite. Il contenuto non costituisce consulenza finanziaria, legale o professionale di altro tipo, né deve essere considerato una raccomandazione o un'approvazione da parte di MEXC.

Potrebbe anche piacerti

RWAs Will Run on Two Blockchain Rails, Says Redstone Co-Founder

RWAs Will Run on Two Blockchain Rails, Says Redstone Co-Founder

The post RWAs Will Run on Two Blockchain Rails, Says Redstone Co-Founder appeared on BitcoinEthereumNews.com. Institutional adoption of real-world assets (RWAs)
Condividi
BitcoinEthereumNews2026/03/10 12:01
The HackerNoon Newsletter: New frontiers in Human AI Interface (9/19/2025)

The HackerNoon Newsletter: New frontiers in Human AI Interface (9/19/2025)

How are you, hacker? 🪐 What’s happening in tech today, September 19, 2025? The HackerNoon Newsletter brings the HackerNoon homepage straight to your inbox. On this day, First Smiley Emoticon Created by Fahlman in 1982, US-led Invasion Restores Democracy to Haiti in 1994, New Zealand Grants Women's Suffrage in 1893, and we present you with these top quality stories. From Spacecraft From the 90s, or Why Humanity Uses Last Centurys Technology in Space to New frontiers in Human AI Interface, let’s dive right in. Spacecraft From the 90s, or Why Humanity Uses Last Centurys Technology in Space By @nftbro [ 9 Min read ] In “small space”, the priorities are different: low cost, rapid iteration, and the use of CubeSats on Raspberry Pi and Linux containers. Read More. New frontiers in Human AI Interface By @zbruceli [ 12 Min read ] Recent tech advances are breaking free from 20 years of 5-inch screen limits, unlocking full human senses in computing through AI interfaces and wearables. Read More. Microsoft’s LinkedIn Still Sucks, But Outsmarting Its Algorithm Is Hilariously Easy By @frankmorgan [ 3 Min read ] A cheeky experiment uses ChatGPT to slip LinkedIn’s walled garden, proving off-platform links still win—and why MS’s Dismal Platform must pivot or die. Read More. AI Startup Surge Risks Repeating Tech’s Last Funding Mania By @youcefhq [ 4 Min read ] The AI startup frenzy and FOMO are inflating round sizes and valuations. But too much capital too early often leads to mediocre outcomes. Remake of 2020–22? Read More. Passive Income in Crypto: Why Waiting for Altseason Is a Bad Strategy By @MichaelJerlis [ 4 Min read ] Discover the most reliable passive income strategies in crypto for 2025 — from tokenized treasuries to staking, lending, farming, and more. Read More. 🧑‍💻 What happened in your world this week? It's been said that writing can help consolidate technical knowledge, establish credibility, and contribute to emerging community standards. Feeling stuck? We got you covered ⬇️⬇️⬇️ ANSWER THESE GREATEST INTERVIEW QUESTIONS OF ALL TIME We hope you enjoy this worth of free reading material. Feel free to forward this email to a nerdy friend who'll love you for it.See you on Planet Internet! With love, The HackerNoon Team ✌️
Condividi
Hackernoon2025/09/20 00:02
CME pushes Solana, XRP into derivatives spotlight with new options

CME pushes Solana, XRP into derivatives spotlight with new options

CME Group is launching options for Solana and XRP futures this October. The move signals a major shift, acknowledging that institutional liquidity is now firmly expanding beyond the established dominance of Bitcoin and Ether. According to a press release dated…
Condividi
Crypto.news2025/09/18 01:18