A legacy version of the decentralized finance protocol Yearn has suffered an exploit, reviving concerns about misconfigured and immutable smart contracts that haveA legacy version of the decentralized finance protocol Yearn has suffered an exploit, reviving concerns about misconfigured and immutable smart contracts that have

YearnFinanceV1 suffers $300,000 exploit to legacy TUSD vault

A legacy version of the decentralized finance protocol Yearn has suffered an exploit, reviving concerns about misconfigured and immutable smart contracts that have held funds on the network years after being deprecated.

In an X post on Wednesday, Security firm PeckShield reported YearnFinanceV1’s hack resulted in losses of about $300,000. The stolen funds were swapped into 103 Ether and now sit at address 0x0F21…4066, according to Etherscan images shared by the firm.

The hackers took advantage of an outdated Yearn vault tied to TrueUSD, known as the “iearn TUSD vault,” which is still deployed on Ether despite being superseded by newer versions. A configuration flaw helped the attackers manipulate share prices through several transactions.

Yearn Finance misconfigured vault triggered price manipulation 

According to an analysis from pseudonymous crypto researcher and University of Science and Technology of China alumnus Weilin Li, the vault configured one of its strategies as a Fulcrum sUSD vault and calculated its share price using only the sUSD balance deposited.

This opened the door to so-called “donation attacks,” in which an attacker transfers assets directly into a vault to distort accounting metrics. After sending Fulcrum sUSD tokens into the Yearn TUSD vault, the perpetrators were able to artificially inflate the vault’s reported share price.

The issue was compounded by a rebalance function that withdraws all underlying assets in sUSD, an asset not included in the vault’s share price calculations. When the rebalance started, the vault’s share price tanked steeply and created a “price shock.”

Per PeckShield Alert’s Etherscan snapshot, the attacker executed sequenced flash loans by firstly borrowing large amounts of TUSD and sUSD without an upfront collateral. They then deposited sUSD to mint Fulcrum sUSD tokens before depositing TUSD into the Yearn TUSD vault. 

At that stage, all underlying assets of the TUSD vault consisted of Fulcrum sUSD tokens. The exploiter withdrew from the Yearn TUSD vault and called the rebalance function, forcing Fulcrum to redeem everything into sUSD. Because sUSD was excluded from share price calculations, the vault’s accounting collapsed, effectively driving the share price toward zero.

The attacker then transferred a small amount of TUSD back into the vault, pushing the share price to extremely low levels, and minted an outsized number of Yearn TUSD tokens at minimal cost. He ultimately counted gains by selling the cheaply acquired Yearn TUSD tokens on Curve pools, extracting value from liquidity providers before repaying the flash loans.

Yearn Finance recaps 2023 vulnerability, researcher recounts

Researcher Li found that the exploit was similar to an attack carried out in 2023, leading to losses exceeding $10 million. The immutable yUSDT contract targeted in that earlier incident was deployed more than three years ago, during the early days of iearn when the late Andre Cronje led the protocol.

Pessimistic security analysts had issued a warning about the vulnerability on social media before the exploit, but since immutable smart contracts cannot be patched or paused once deployed, it was inevitable.

 “iearn finance, Smoothswap, be careful. This address 0x5bac20…ed8e9cdfe0 got 10 ETH from Tornado and deploys contracts with flashloans using your addresses,” PS’ Nikiti Kirillov wrote.

A Yearn team member known as storming0x admitted the attack happened and reassured users that its current contracts were safe. Yet, Rekt News observers revealed it took 1,156 days for the DeFi protocol to spot a multimillion-dollar vulnerability.

Yearn yUSDT token contract generated yield from a basket of yield-bearing positions, including USDT deposits on Aave, Compound, dYdX and BzX’s Fulcrum. Since launch, however, yUSDT contained a copy-and-paste error which referenced the Fulcrum USDC address instead of the Fulcrum USDT contract. 

Using just 10,000 USDT, hackers were able to mint approximately 1.2 quadrillion yUSDT, draining value from the system before cashing out.

The Yearn incident comes less than a week after Cryptopolitan featured a $2.7 million drainage from an old contract belonging to Ribbon Finance, the rebranded version of Aevo. That attack involved repeated interactions with a proxy admin contract at address 0x9D7b…8ae6B76. The attacker invoked functions such as transferOwnership and setImplementation to manipulate price-feed proxies through delegate calls.

Get seen where it counts. Advertise in Cryptopolitan Research and reach crypto’s sharpest investors and builders.

Market Opportunity
TrueUSD Logo
TrueUSD Price(TUSD)
$0.9991
$0.9991$0.9991
0.00%
USD
TrueUSD (TUSD) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Bitcoin and Ethereum ETFs See $232M in Outflows as Traders De‑Risk Ahead of Christmas

Bitcoin and Ethereum ETFs See $232M in Outflows as Traders De‑Risk Ahead of Christmas

U.S. spot Bitcoin and Ethereum ETFs recorded combined net outflows of approximately $232 million on Wednesday, as traders trimmed exposure ahead of the Christmas holiday and year‑end liquidity slowdown.
Share
MEXC NEWS2025/12/26 16:51
MICA Rules Come into Effect! Another European Country Issues a Very Strong Warning to Crypto Exchanges! Here Are the Details

MICA Rules Come into Effect! Another European Country Issues a Very Strong Warning to Crypto Exchanges! Here Are the Details

The post MICA Rules Come into Effect! Another European Country Issues a Very Strong Warning to Crypto Exchanges! Here Are the Details appeared on BitcoinEthereumNews
Share
BitcoinEthereumNews2025/12/26 15:25
Ethereum Hits Losing Streak: How Massive Liquidations Impact ETH Price

Ethereum Hits Losing Streak: How Massive Liquidations Impact ETH Price

Ethereum has entered a sharp losing streak, with cascading liquidations and technical weakness fueling volatility across the market. A wave of $1.8 billion in long liquidations on September 23 wiped out more than 370,000 traders, leaving Ethereum (ETH) particularly exposed. This market update is powered by Outset PR, the first data-driven crypto PR agency that equips blockchain projects with precise, effective strategies to boost visibility.  $1.8B Liquidations Trigger ETH Sell-Off The crypto market’s heavy reliance on leverage has once again backfired. ETH futures accounted for over $500 million of the $1.8 billion long liquidation, underscoring Ethereum’s vulnerability to sudden drawdowns. Leverage risk: With the average funding rate at +0.0029%, traders were heavily overexposed. Domino effect: When ETH broke below $4,150, stop-losses and margin calls triggered a cascading sell-off. Open interest: ETH derivatives open interest surged 19% in 24h, showing volatility was amplified by excessive speculation. The high-leverage environment created a fragile setup where a single breakdown sparked a chain reaction of forced selling. Technical Weakness Adds Pressure ETH also faces mounting technical headwinds after failing to hold critical levels. Pivot breakdown: ETH slipped below its 24h pivot point at $4,250. Resistance: The 38.2% Fibonacci retracement at $4,624 now serves as resistance. Beyond that, MACD histogram at -33.17 signals clear bearish momentum, while the RSI at 40.46 is weak but not oversold, leaving room for further downside. Price targets: Short-term traders are eyeing $4,092 (September 23 low) as the next support.Long-term structure remains intact as long as ETH holds above the 200-day EMA ($3,403), suggesting investors aren’t panic-selling yet. PR with C-Level Clarity: Outset PR’s Proprietary Techniques Deliver Tangible Results  If PR has ever felt like trying to navigate a foggy road without headlights, Outset PR brings clarity with data. It builds strategies based on both retrospective and real-time metrics, which helps to obtain results with a long-lasting effect.  Outset PR replaces vague promises with concrete plans tied to perfect publication timing, narratives that emphasize the product-market fit, and performance-based media selection. Clients gain a forward-looking perspective: how their story will unfold, where it will land, and what impact it may create.  While most crypto PR agencies rely on standardized packages and mass-blast outreach, Outset PR takes a tailored approach. Each campaign is calibrated to match the client’s specific goals, budget, and growth stage. This is PR with a personal touch, where strategy feels handcrafted and every client gets a solution that fits. Outset PR’s secret weapon is its exclusive traffic acquisition tech and internal media analytics.  Proprietary Tech That Powers Performance One of Outset PR’s most impactful tools is its in-house user acquisition system. It fuses organic editorial placements with SEO and lead-generation tactics, enabling clients to appear in high-discovery surfaces and drive multiples more traffic than through conventional PR alone. Case in point: Crypto exchange ChangeNOW experienced a sustained 40% boost in reach after Outset PR amplified a well-polished organic coverage with a massive Google Discover campaign, powered by its proprietary content distribution engine.   Drive More Traffic with Outset PR’s In-house Tech Outset PR Notices Media Trends Ahead of the Crowd Outset PR obtains unique knowledge through its in-house analytical desk which gives it a competitive edge. The team regularly provides valuable insights into the performance of crypto media outlets based on the criteria like: domain activity month-on-month visibility shifts audience geography source of traffic By consistently publishing analytical reports, identifying performance trends, and raising the standards of media targeting across the industry, Outset PR unlocks a previously untapped niche in crypto PR, which poses it as a trendsetter in this field.  Case in point: The careful selection of media outlets has helped Outset PR increase user engagement for Step App in the US and UK markets. Outset PR Engineers Visibility That Fits the Market One of the biggest pain points in Web3 PR is the disconnect between effort and outcome: generic messaging, no product-market alignment, and media hits that generate visibility but leave business impact undefined. Outset PR addresses this by offering customized solutions. Every campaign begins with a thorough research and follows a clearly mapped path from spend to the result. It's data-backed and insight-driven with just the right level of boutique care. Outlook Ethereum’s latest slump highlights the double-edged sword of leverage. Excessive positioning fueled sharp liquidations, while technical weakness reinforced the bearish momentum. Yet, with the 200-day EMA still holding firm, long-term holders remain calm for now. This analysis was brought to you by Outset PR, the first data-driven crypto PR agency. Just as Ethereum’s market path hinges on reclaiming key levels, Outset PR helps projects reclaim visibility and momentum with strategies grounded in data and measurable results. You can find more information about Outset PR here: Website: outsetpr.io Telegram: t.me/outsetpr  X: x.com/OutsetPR    Disclaimer: This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.
Share
Coinstats2025/09/23 23:29