Summary
Yearn Ether (yETH) is a liquid staking token aggregation vault developed by Yearn Finance, launched under YIP-72 as a self-governed, permissionless product. On November 30, 2025, the yETH weighted stableswap pool was exploited via an arithmetic underflow and stale cache vulnerability, resulting in approximately $9 million in losses — the third major security incident involving a Yearn product since 2021. Approximately $2.4 million was partially recovered; roughly $6.6 million remains unrecovered, with a significant portion laundered through Tornado Cash.
Connected Entities
1 entitiesTimeline(9 events)
2020-07-17
Yearn Finance launches, founded by Andre Cronje. YFI governance token distributed with no pre-mine or team allocation.
2021-02-04
Yearn v1 DAI vault exploited via flash loan attack across 160 nested transactions. $11 million drained from vault; attacker nets approximately $2.8 million. Tether freezes $1.7 million USDT.
CoinDesk2023-04-13
Legacy yUSDT contract exploited due to misconfigured Fulcrum address. Attacker mints 1.2 quadrillion yUSDT; approximately $11.54 million drained and laundered via Tornado Cash. V2 vaults unaffected.
CoinDesk / Halborn2023-03-13
Yearn Finance suffers estimated $1.4 million indirect loss from Euler Finance attack.
Web3 Is Going Great2025-11-30
yETH weighted stableswap pool exploited at block 23,914,086 (~21:11 UTC). Attacker deposits 16 wei, mints 235 septillion yETH via stale cache + arithmetic underflow vulnerability. Approximately $9 million in LSTs drained.
The Defiant / Check Point Research2025-12-01
Yearn Finance coordinates with Plume and Dinero teams to recover 857.49 pxETH ($2.39 million). Attacker transfers first batches totaling 1,000 ETH to Tornado Cash in 100 ETH increments.
crypto.news / coinpaper2025-12-17
Yearn v1 legacy TUSD vault ('iearn TUSD') exploited via flash loan donation attack for approximately $300,000 (~103 ETH). Fourth exploit of a Yearn product in recent history.
crypto.news / web3isgoinggreat2025-12-01
Yearn publishes official yETH exploit post-mortem and announces technical remediation plan.
Yearn Finance (X/Twitter)2026-01-01
YIP-90 'yETH Optimistic Recovery Plan' proposed. Treasury to deploy ~1,600 ETH in yield-bearing strategies to fund gradual depositor restitution; immediate recovery floor set at approximately 30.38% of pre-exploit positions.
Yearn Governance ForumDecision Log
- hash: CoTnQxNHzVagYtHz1G5LbLRD88NNqoNT23XVC9iToEZf
- hash: 4qpCMwYpGRkqtdFH7fpkMSg2is5gkBFUcRp3hxoYa3oS
- hash: 316QN1H6WWGA85eofxBZpjh48r29kjLgohkFujhXzAHR
- hash: 51sBCFSRsFi5KjzmJZ56k5BbKxAdfyaCTXC41b5H3LiV
- hash: H5KrduXCTKwnKvnxLDj4QRLKmw3EKBjrE7vNTiZCuseV
This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.
model: claude-sonnet-4-6
generated: 5/4/2026, 2:54:20 AM
last updated: 6/14/2026, 11:15:46 PM
avoid.net — verified advice for a post-truth world