TL;DR: Yearn’s yETH pool was exploited after an attacker broke the pool’s math, forcing the invariant to collapse and over-minting massive amounts of LP tokens. They used those fake LP tokens to drain all LSTs, then re-entered an unprotected initialization path to infinite-mint yETH and drain the Curve yETH/ETH pool too. The issue came from missing math checks, unsafe arithmetic, and an old bootstrap path left open. About 857 pxETH was recovered, but yETH is “use at your own risk,” so reimbursement depends on recovered funds only.

Top comment by @Danicjade

More coverage

Explore the topic

More on Yearn

Comments