Yearn security posts incident disclosure on the yETH hack, including recovery of 857.49 pxETH with the assistance of Plume and Dinero teams


5 recorded changes
Want your article here?
Promote with Leviathan News

5 recorded changes
Want your article here?
Promote with Leviathan NewsTL;DR: Yearn’s yETH pool was exploited after an attacker broke the pool’s math, forcing the invariant to collapse and over-minting massive amounts of LP tokens. They used those fake LP tokens to drain all LSTs, then re-entered an unprotected initialization path to infinite-mint yETH and drain the Curve yETH/ETH pool too. The issue came from missing math checks, unsafe arithmetic, and an old bootstrap path left open. About 857 pxETH was recovered, but yETH is “use at your own risk,” so reimbursement depends on recovered funds only.
Top comment by @Danicjade

𝕏/@yearnfi ·

𝕏/@banteg ·

𝕏/@yAuditDAO ·

𝕏/@NourHaridy ·

𝕏/@BirchHill_io ·

𝕏/@johnnyonline_ ·

𝕏/@yearnfi ·

𝕏/@banteg ·

𝕏/@yAuditDAO ·

𝕏/@NourHaridy ·

𝕏/@BirchHill_io ·

𝕏/@johnnyonline_ ·
🚀 Love DeFi? Ready to dive in and start earning $SQUID while making an impact?