Hackers Exploit Critical Yearn Finance’s yETH Pool Vulnerability to Steal $9 Million in Ethereum
ID: 7bc775d7-880b-5051-9a49-e57d22cf58af
STIX ID: report--7bc775d7-880b-5051-9a49-e57d22cf58af
Feed Name: cybersecurityNews.com
On November 30, 2025, Yearn Finance’s yETH pool was exploited for about $9 million after an attacker used flash-loaned deposit/withdraw cycles to poison cached packed_vbs storage values; when the pool supply hit zero, stale cached balances caused the protocol to mint 235 septillion yETH tokens for a final 16 wei deposit, enabling the attacker to drain assets, swap to WETH, and launder funds via Tornado Cash. The incident highlights a critical state-management vulnerability in the pool’s internal accounting where gas-optimization caching failed to reset, demonstrating how subtle logic flaws in DeFi contracts can enable highly capital-efficient attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
