BanklessTimes
Home Articles Yearn Finance yETH Pool Suffers $9M Loss in Latest DeFi Exploit

Yearn Finance yETH Pool Suffers $9M Loss in Latest DeFi Exploit

Simon Simba
Simon Simba
Simon is a writer with five years experience in crypto and iGaming. He currently works as a freelance writer at BanklessTimes where he focuses on simplifying daily crypto developments for readers. He discovered crypto in 2022 while writing news about NFTs for a news website in the US, and has since written for two other international NFT projects, and a Web3 gaming agency.
Updated: December 1st, 2025
Editor:
Joseph Alalade
Joseph Alalade
Editor:
Joseph Alalade
News Lead and Editor
Joseph is a content writer and editor who has actively participated in crypto for over 6 years. He enjoys educating others about Web3 and covering its updates, regulatory developments, and exciting stories.

Yearn Finance’s yETH pool experienced a complex exploit that resulted in the loss of approximately $9 million in assets. This incident, involving an older yETH contract and its associated liquidity pools, occurred on November 30. The event had a swift impact on the overall market sentiment for major tokens, including Bitcoin and Ethereum.

Infinite Mint Vulnerability Drains yETH Liquidity

Blockchain security alerts and Yearn’s own incident statements indicate that the attacker exploited a vulnerability. This allowed the creation of an effectively unlimited amount of yETH, the protocol’s index token representing a basket of liquid‑staking derivatives on Ethereum. In a single transaction, the exploiter minted on the order of 235 trillion yETH.

The attacker then used those tokens to remove real assets, primarily ETH and liquid‑staking tokens, from Balancer and Curve liquidity pools tied to the product.​

Yearn has said the flaw lay in the yETH token and pool logic, not in its newer V2 and V3 vault infrastructure. Additionally, the compromised contracts were part of legacy or isolated components rather than current core strategies.

On‑chain data and subsequent forensic summaries put the total economic impact near $9 million, including about $8 million drained from the main stableswap pool and roughly $900,000 from a related yETH‑WETH pool. Approximately 1,000 ETH, around $3 million at recent prices, was quickly routed through Tornado Cash, with additional funds still sitting in attacker‑controlled wallets.

DeFi Security Concerns

Developers and independent researchers have described the exploit as an “infinite‑mint” or pricing‑manipulation attack enabled by a combination of faulty invariants, rate‑update logic, and reliance on contracts that had not been fully upgraded or decommissioned.

Analysts noted that the attacker deployed several helper contracts shortly before the transaction and then self‑destructed them afterward, a pattern seen in other advanced DeFi exploits aimed at obscuring the on‑chain trail.​

The incident follows earlier security events in the DeFi sector and adds to November’s running tally of more than $100 million in crypto lost to hacks and scams across multiple protocols.

In response, Yearn has been working with external audit and incident‑response groups, including on‑chain security collectives, to dissect the root cause and propose remediation steps for users and liquidity providers, while reiterating that active vaults remain operational and segregated from the affected yETH contracts.

READ MORE: SEI Price Prediction as Buyers Defend a Key Level

Follow Bankless Times on Google News

We`ve got crypto covered – every trend, every insight, every move that matters. Add us to your feed and stay ahead of the market.

Contributors

Simon Simba
Simon is a writer with five years experience in crypto and iGaming. He currently works as a freelance writer at BanklessTimes where he focuses on simplifying daily crypto developments for readers. He discovered crypto in 2022 while writing news about NFTs for a news website in the US, and has since written for two other international NFT projects, and a Web3 gaming agency.