Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnSquareMore
Yearn recovers $2.4 million in stolen assets stemming from 'unchecked arithmetic' bug

Yearn recovers $2.4 million in stolen assets stemming from 'unchecked arithmetic' bug

The BlockThe Block2025/11/30 16:00
By:By Daniel Kuhn

Quick Take OG DeFi protocol Yearn Finance lost about $9 million in an exploit on Sunday, after an attacker was able to mint a near-infinite amount of yETH tokens and drain a Yearn Ether stableswap pool. The team said a recovery mission is ongoing and that its V2 and V3 protocols are not at risk.

Yearn recovers $2.4 million in stolen assets stemming from 'unchecked arithmetic' bug image 0

The Yearn Finance team has recovered approximately $2.4 million worth of stolen assets from the most recent exploit of the legacy DeFi protocol, as total estimated losses approach $9 million, according to an update on Monday. A coordinated recovery mission is “active and ongoing,” a post on X reads.

On Sunday, a vulnerability in the once-popular yield-farming protocol was exploited to drain assets from the Yearn Ether (yETH) stableswap pool and smaller yETH‑WETH pool on Curve. The attack, the third targeting Yearn since 2021, was of a “similar high complexity” to the recent Balancer hack, Yearn said. 

According to a post-mortem published on Monday, the “root cause” stems from an “unchecked arithmetic” bug and other “contributing design issues” that enabled the attacker to mint the 2.3544x10^56 yETH tokens  — a near infinite amount — used to drain liquidity from the protocol. 

“The actual exploit transactions follow this pattern: the huge mint is followed by a sequence of withdrawals that move real assets to the attacker, while the yETH token supply is effectively meaningless,” according to the postmortem. 

Yearn notes that the attack was targeted and should not impact its V2 or V3 vaults. “Any assets successfully recovered will be returned to affected depositors,” the team added. 

As The Block previously reported , the attacker was able to move at least 1,000 ETH and several liquid staking tokens to the Tornado Cash anonymizer. Yearn, together with crypto security firms SEAL 911 and ChainSecurity, worked with Plume network to recover 857.49 pxETH as of press time. 

BlockScout said that the hacker deployed self-destructing “helper contracts” as part of the attack. These code inserts are specialized auxiliary smart contracts that are used to perform automated tasks, and often abused during flash loan attacks that require multiple steps within a single transaction. 

The attacker, for instance, used a helper contract to manipulate the vulnerable yETH function, mint an absurd amount of tokens, and drain the protocol, before detonating itself. “Self-destruct removes bytecode, making the contract unreadable afterward, but creation transactions and logs are preserved,” Blockscout said.

"Initial analysis indicated this hack has a similar high complexity level to the recent Balancer hack, so please bear with us as we perform the post-mortem analysis," Yearn said on Sunday. "There is no other Yearn product using similar code to what was impacted."


0
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

South Korea Demands Swift Action on Stablecoin Regulations

In Brief South Korea's ruling party pressures government to regulate the stablecoin market swiftly. A consortium model involving banks for stablecoin issuance is being considered. The regulation aims to strengthen monetary sovereignty and balance U.S. stablecoin dominance.

Cointurk2025/12/02 11:45
South Korea Demands Swift Action on Stablecoin Regulations

Discover How Pi Network Tackles Crypto’s Biggest Challenges Head-On

In Brief Pi Network still trades under $0.30 as 2025 nears its end. The next 3-5 years are vital for Pi Network and wider crypto adoption. Innovation and correct frameworks are crucial for the future of cryptocurrencies.

Cointurk2025/12/02 11:45
Discover How Pi Network Tackles Crypto’s Biggest Challenges Head-On
© 2025 Bitget