MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: Yearn recovers $2.4 million in stolen assets stemming from ‘unchecked arithmetic’ bug
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$68,516.002.37%
  • ethereumEthereum(ETH)$1,988.982.13%
  • tetherTether(USDT)$1.00-0.01%
  • rippleXRP(XRP)$1.464.13%
  • binancecoinBNB(BNB)$633.494.12%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$86.364.12%
  • tronTRON(TRX)$0.2858970.21%
  • dogecoinDogecoin(DOGE)$0.1005882.64%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.040.64%
DeFi

Yearn recovers $2.4 million in stolen assets stemming from ‘unchecked arithmetic’ bug

Last updated: December 2, 2025 5:30 am
Published: 3 months ago
Share

The team said a recovery mission is ongoing and that its V2 and V3 protocols are not at risk.

The Yearn Finance team has recovered approximately $2.4 million worth of stolen assets from the most recent exploit of the legacy DeFi protocol, as total estimated losses approach $9 million, according to an update on Monday. A coordinated recovery mission is “active and ongoing,” a post on X reads.

On Sunday, a vulnerability in the once-popular yield-farming protocol was exploited to drain assets from the Yearn Ether (yETH) stableswap pool and smaller yETH‑WETH pool on Curve. The attack, the third targeting Yearn since 2021, was of a “similar high complexity” to the recent Balancer hack, Yearn said.

According to a post-mortem published on Monday, the “root cause” stems from an “unchecked arithmetic” bug and other “contributing design issues” that enabled the attacker to mint the 2.3544×10^56 yETH tokens — a near infinite amount — used to drain liquidity from the protocol.

“The actual exploit transactions follow this pattern: the huge mint is followed by a sequence of withdrawals that move real assets to the attacker, while the yETH token supply is effectively meaningless,” according to the postmortem.

Yearn notes that the attack was targeted and should not impact its V2 or V3 vaults. “Any assets successfully recovered will be returned to affected depositors,” the team added.

As The Block previously reported, the attacker was able to move at least 1,000 ETH and several liquid staking tokens to the Tornado Cash anonymizer. Yearn, together with crypto security firms SEAL 911 and ChainSecurity, worked with Plume network to recover 857.49 pxETH as of press time.

BlockScout said that the hacker deployed self-destructing “helper contracts” as part of the attack. These code inserts are specialized auxiliary smart contracts that are used to perform automated tasks, and often abused during flash loan attacks that require multiple steps within a single transaction.

The attacker, for instance, used a helper contract to manipulate the vulnerable yETH function, mint an absurd amount of tokens, and drain the protocol, before detonating itself. “Self-destruct removes bytecode, making the contract unreadable afterward, but creation transactions and logs are preserved,” Blockscout said.

“Initial analysis indicated this hack has a similar high complexity level to the recent Balancer hack, so please bear with us as we perform the post-mortem analysis,” Yearn said on Sunday. “There is no other Yearn product using similar code to what was impacted.”

Read more on The Block

This news is powered by The Block The Block

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

Analysts Reveal the Best Cryptos to Buy This Month: Dogecoin and Pepe Rally, Yet MoonBull’s 9,256% ROI Presale Soars
Liquid Staking Tokens Aren’t Securities, SEC Says. What That Means for Crypto Investors.
From Repair To Reinvention – How EU Financial Markets Regulation Has Evolved And What It Signals For The Next Decade
Bitcoin Bull Run Targets Are Rising — Ozak AI Price Prediction May Outperform
A Pivotal Moment in Sports Web3: Atleta’s $ATLA Token Generation Event and MEXC Listing

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article DFlow Introduces Tokenized Prediction Markets API on Solana (SOL)
Next Article Yearn Finance Recovers $2.4M after pxETH Exploit Incident
© Market Alert News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Prove your humanity


Lost your password?

%d