MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: Hackers Exploit Critical Yearn Finance’s yETH Pool Vulnerability to Steal $9 Million in Ethereum
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • kpk ETH Primekpk ETH Prime(KPK ETH PRIME)$2,034.900.01%
  • bitcoinBitcoin(BTC)$71,242.002.58%
  • ethereumEthereum(ETH)$2,110.663.95%
  • kpk ETH Yieldkpk ETH Yield(KPK ETH YIELD)$2,031.88-0.04%
  • tetherTether(USDT)$1.00-0.03%
  • binancecoinBNB(BNB)$660.242.52%
  • rippleXRP(XRP)$1.402.06%
  • usd-coinUSDC(USDC)$1.00-0.02%
  • solanaSolana(SOL)$89.284.33%
  • tronTRON(TRX)$0.289929-0.06%
Smart Contracts

Hackers Exploit Critical Yearn Finance’s yETH Pool Vulnerability to Steal $9 Million in Ethereum

Last updated: December 3, 2025 11:55 pm
Published: 3 months ago
Share

The decentralized finance sector witnessed a devastating breach targeting Yearn Finance’s yETH pool, resulting in the theft of approximately $9 million on November 30, 2025.

The attacker executed a highly sophisticated exploit, minting an astronomical 235 septillion yETH tokens while depositing a mere 16 wei — an amount worth less than a fraction of a cent.

This incident highlights the fragility of complex mathematical invariants in smart contracts, where gas optimization strategies can inadvertently introduce catastrophic security flaws.

The core vulnerability lay within the protocol’s internal accounting mechanism, specifically its use of cached storage variables known as packed_vbs.

Designed to reduce transaction costs by storing virtual balance information, these variables failed to reset correctly when the pool’s liquidity supply dropped to zero.

While the main supply counter reset, the cached values retained phantom balances from previous transactions, creating a critical discrepancy between the actual and recorded state of the pool.

Check Point security analysts noted the malware’s behavior and identified that this was not a simple code error but a logic flaw in state management.

By manipulating the interaction between deposit and withdrawal functions, the attacker tricked the system into believing the pool held vast value when it was effectively empty.

The exploit represents one of the most capital-efficient attacks in history, requiring negligible upfront capital to drain millions in Ethereum-based assets.

The Mechanics of State Poisoning

The attack unfolded through a meticulous process of state poisoning, exploiting the protocol’s failure to clear its cache.

The perpetrator initiated over ten cycles of deposits and withdrawals using flash-loaned funds, deliberately leaving minute residual values in the packed_vbs storage slots.

This repetitive action poisoned the storage with accumulated data that persisted even after the attacker withdrew all legitimate liquidity, bringing the pool’s total supply to zero.

Crucially, the protocol’s add_liquidity function contained a fatal assumption: it presumed that a zero supply meant a pristine, empty pool.

When the attacker deposited their final 16 wei, the system read the stale, non-zero values from the poisoned cache instead of calculating based on the new deposit.

This miscalculation triggered the minting of septillions of LP tokens, granting the attacker absolute control over the pool’s assets, which were subsequently swapped for WETH and laundered through Tornado Cash.

This case serves as a stark reminder that complex DeFi systems require explicit state management to prevent such high-value exploits.

Follow us on Google News, LinkedIn, and X to Get More Instant Updates, Set CSN as a Preferred Source in Google.

Read more on Cyber Security News

This news is powered by Cyber Security News Cyber Security News

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

Cardano (ADA) Eyes $2 in 2025, But This Crypto Could Explode 12,100% from Below $0.003 · Cardano Feed
UAE RAK BANK receives in principle approval to launch AED stablecoin – Cryptopolitan
Ruvi AI (RUVI) Could Replace Tron (TRX) in Investor Portfolios; Experts Highlight Rapid Growth and Massive ROI Potential
Best Crypto to Buy Now (Nov. 10): XRP, Cardano, Pepe
Spark Q4 2025 Financial Report

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article Information Technology and Market Research News
Next Article Invesco Releases 2026 Investment Outlook “Resilience and Rebalancing”
© Market Alert News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Prove your humanity


Lost your password?

%d