logo

Hackers Exploit Critical Yearn Finance’s yETH Pool Vulnerability to Steal $9 Million in Ethereum

ID: 7bc775d7-880b-5051-9a49-e57d22cf58af

STIX ID: report--7bc775d7-880b-5051-9a49-e57d22cf58af

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2025-12-03

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

On November 30, 2025, Yearn Finance’s yETH pool was exploited for about $9 million after an attacker used flash-loaned deposit/withdraw cycles to poison cached packed_vbs storage values; when the pool supply hit zero, stale cached balances caused the protocol to mint 235 septillion yETH tokens for a final 16 wei deposit, enabling the attacker to drain assets, swap to WETH, and launder funds via Tornado Cash. The incident highlights a critical state-management vulnerability in the pool’s internal accounting where gas-optimization caching failed to reset, demonstrating how subtle logic flaws in DeFi contracts can enable highly capital-efficient attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.