Yearn Finance recovers $2.4 million after $9 million exploit. Complex attack drains assets from Yearn’s yETH pools, vulnerabilities found. Recovery efforts ongoing, security firms assist with asset retrieval process. Yearn Finance has managed to recover approximately $2.4 million of stolen assets following a significant exploit targeting its legacy protocol. This breach, which occurred over the weekend, led to total losses reaching an estimated $9 million. The team is actively working to recover further assets, with a coordinated recovery mission underway. Also Read: Cryptocurrency Market Sees Bitcoin Rise, Ethereum, XRP, BNB, DOGE Decline in 24 Hours Exploit Details and Technical Breakdown On Sunday, a vulnerability within the protocol was exploited, allowing an attacker to drain funds from Yearn’s Ether (yETH) stableswap pool and a smaller yETH-WETH pool on Curve Finance. This attack is the third such event since 2021 and bears striking similarities to the recent Balancer exploit in terms of its complexity. The vulnerability stemmed from an “unchecked arithmetic” bug and other design flaws in the code, allowing the attacker to mint an astronomical number of yETH tokens approximately 2.3544×10^56 thereby draining liquidity from the pools. The post-mortem analysis revealed that the attacker used this huge mint to perform a series of withdrawals, transferring real assets to their own wallet, while the minted yETH tokens held no intrinsic value. These exploitations were followed by the use of self-destructing helper contracts, which are auxiliary smart contracts often abused in flash loan attacks. These contracts were deployed to manipulate the vulnerable yETH function and execute the attack before self-destructing and removing their bytecode from the blockchain. Yearn Finance reassured its users that the exploit does not affect its V2 or V3 vaults. The team is committed to returning any recovered assets to the affected depositors. The attack itself was highly targeted, and measures are in place to prevent similar occurrences in the future. Recovery Efforts and Collaboration with Security Firms In collaboration with crypto security firms SEAL 911 and ChainSecurity, Yearn Finance, alongside Plume network, has successfully recovered 857.49 pxETH, with more recovery efforts ongoing. The stolen funds, including at least 1,000 ETH, were moved through the Tornado Cash anonymizer, making the investigation and recovery process even more challenging. Despite the magnitude of the attack, Yearn has stressed that there are no other products currently using the same vulnerable code. As the recovery process continues, the team remains focused on mitigating the impact on affected users and restoring their funds as quickly as possible. Also Read: Egrag Crypto: XRP Monthly Chart Is Flashing Something Big, Here’s What’s Next The post Yearn Finance Recovers $2.4 Million After Latest Exploit, Estimated Losses Near $9 Million appeared first on 36Crypto. Yearn Finance recovers $2.4 million after $9 million exploit. Complex attack drains assets from Yearn’s yETH pools, vulnerabilities found. Recovery efforts ongoing, security firms assist with asset retrieval process. Yearn Finance has managed to recover approximately $2.4 million of stolen assets following a significant exploit targeting its legacy protocol. This breach, which occurred over the weekend, led to total losses reaching an estimated $9 million. The team is actively working to recover further assets, with a coordinated recovery mission underway. Also Read: Cryptocurrency Market Sees Bitcoin Rise, Ethereum, XRP, BNB, DOGE Decline in 24 Hours Exploit Details and Technical Breakdown On Sunday, a vulnerability within the protocol was exploited, allowing an attacker to drain funds from Yearn’s Ether (yETH) stableswap pool and a smaller yETH-WETH pool on Curve Finance. This attack is the third such event since 2021 and bears striking similarities to the recent Balancer exploit in terms of its complexity. The vulnerability stemmed from an “unchecked arithmetic” bug and other design flaws in the code, allowing the attacker to mint an astronomical number of yETH tokens approximately 2.3544×10^56 thereby draining liquidity from the pools. The post-mortem analysis revealed that the attacker used this huge mint to perform a series of withdrawals, transferring real assets to their own wallet, while the minted yETH tokens held no intrinsic value. These exploitations were followed by the use of self-destructing helper contracts, which are auxiliary smart contracts often abused in flash loan attacks. These contracts were deployed to manipulate the vulnerable yETH function and execute the attack before self-destructing and removing their bytecode from the blockchain. Yearn Finance reassured its users that the exploit does not affect its V2 or V3 vaults. The team is committed to returning any recovered assets to the affected depositors. The attack itself was highly targeted, and measures are in place to prevent similar occurrences in the future. Recovery Efforts and Collaboration with Security Firms In collaboration with crypto security firms SEAL 911 and ChainSecurity, Yearn Finance, alongside Plume network, has successfully recovered 857.49 pxETH, with more recovery efforts ongoing. The stolen funds, including at least 1,000 ETH, were moved through the Tornado Cash anonymizer, making the investigation and recovery process even more challenging. Despite the magnitude of the attack, Yearn has stressed that there are no other products currently using the same vulnerable code. As the recovery process continues, the team remains focused on mitigating the impact on affected users and restoring their funds as quickly as possible. Also Read: Egrag Crypto: XRP Monthly Chart Is Flashing Something Big, Here’s What’s Next The post Yearn Finance Recovers $2.4 Million After Latest Exploit, Estimated Losses Near $9 Million appeared first on 36Crypto.

Yearn Finance Recovers $2.4 Million After Latest Exploit, Estimated Losses Near $9 Million

  • Yearn Finance recovers $2.4 million after $9 million exploit.
  • Complex attack drains assets from Yearn’s yETH pools, vulnerabilities found.
  • Recovery efforts ongoing, security firms assist with asset retrieval process.

Yearn Finance has managed to recover approximately $2.4 million of stolen assets following a significant exploit targeting its legacy protocol. This breach, which occurred over the weekend, led to total losses reaching an estimated $9 million. The team is actively working to recover further assets, with a coordinated recovery mission underway.


Also Read: Cryptocurrency Market Sees Bitcoin Rise, Ethereum, XRP, BNB, DOGE Decline in 24 Hours


Exploit Details and Technical Breakdown

On Sunday, a vulnerability within the protocol was exploited, allowing an attacker to drain funds from Yearn’s Ether (yETH) stableswap pool and a smaller yETH-WETH pool on Curve Finance. This attack is the third such event since 2021 and bears striking similarities to the recent Balancer exploit in terms of its complexity. The vulnerability stemmed from an “unchecked arithmetic” bug and other design flaws in the code, allowing the attacker to mint an astronomical number of yETH tokens approximately 2.3544×10^56 thereby draining liquidity from the pools.


The post-mortem analysis revealed that the attacker used this huge mint to perform a series of withdrawals, transferring real assets to their own wallet, while the minted yETH tokens held no intrinsic value. These exploitations were followed by the use of self-destructing helper contracts, which are auxiliary smart contracts often abused in flash loan attacks. These contracts were deployed to manipulate the vulnerable yETH function and execute the attack before self-destructing and removing their bytecode from the blockchain.


Yearn Finance reassured its users that the exploit does not affect its V2 or V3 vaults. The team is committed to returning any recovered assets to the affected depositors. The attack itself was highly targeted, and measures are in place to prevent similar occurrences in the future.


Recovery Efforts and Collaboration with Security Firms

In collaboration with crypto security firms SEAL 911 and ChainSecurity, Yearn Finance, alongside Plume network, has successfully recovered 857.49 pxETH, with more recovery efforts ongoing. The stolen funds, including at least 1,000 ETH, were moved through the Tornado Cash anonymizer, making the investigation and recovery process even more challenging.


Despite the magnitude of the attack, Yearn has stressed that there are no other products currently using the same vulnerable code. As the recovery process continues, the team remains focused on mitigating the impact on affected users and restoring their funds as quickly as possible.


Also Read: Egrag Crypto: XRP Monthly Chart Is Flashing Something Big, Here’s What’s Next


The post Yearn Finance Recovers $2.4 Million After Latest Exploit, Estimated Losses Near $9 Million appeared first on 36Crypto.

Market Opportunity
4 Logo
4 Price(4)
$0.02573
$0.02573$0.02573
+2.38%
USD
4 (4) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

LMAX Group Deepens Ripple Partnership With RLUSD Collateral Rollout

LMAX Group Deepens Ripple Partnership With RLUSD Collateral Rollout

LMAX Group has revealed a multi-year partnership with Ripple to integrate traditional finance with digital asset markets. As part of the agreement, LMAX will introduce
Share
Tronweekly2026/01/16 23:00
Pastor Involved in High-Stakes Crypto Fraud

Pastor Involved in High-Stakes Crypto Fraud

A gripping tale of deception has captured the media’s spotlight, especially in foreign outlets, centering on a cryptocurrency fraud case from Denver, Colorado. Eli Regalado, a pastor, alongside his wife Kaitlyn, was convicted, but what makes this case particularly intriguing is their unconventional defense.Continue Reading:Pastor Involved in High-Stakes Crypto Fraud
Share
Coinstats2025/09/18 00:38
Fed rate decision September 2025

Fed rate decision September 2025

The post Fed rate decision September 2025 appeared on BitcoinEthereumNews.com. WASHINGTON – The Federal Reserve on Wednesday approved a widely anticipated rate cut and signaled that two more are on the way before the end of the year as concerns intensified over the U.S. labor market. In an 11-to-1 vote signaling less dissent than Wall Street had anticipated, the Federal Open Market Committee lowered its benchmark overnight lending rate by a quarter percentage point. The decision puts the overnight funds rate in a range between 4.00%-4.25%. Newly-installed Governor Stephen Miran was the only policymaker voting against the quarter-point move, instead advocating for a half-point cut. Governors Michelle Bowman and Christopher Waller, looked at for possible additional dissents, both voted for the 25-basis point reduction. All were appointed by President Donald Trump, who has badgered the Fed all summer to cut not merely in its traditional quarter-point moves but to lower the fed funds rate quickly and aggressively. In the post-meeting statement, the committee again characterized economic activity as having “moderated” but added language saying that “job gains have slowed” and noted that inflation “has moved up and remains somewhat elevated.” Lower job growth and higher inflation are in conflict with the Fed’s twin goals of stable prices and full employment.  “Uncertainty about the economic outlook remains elevated” the Fed statement said. “The Committee is attentive to the risks to both sides of its dual mandate and judges that downside risks to employment have risen.” Markets showed mixed reaction to the developments, with the Dow Jones Industrial Average up more than 300 points but the S&P 500 and Nasdaq Composite posting losses. Treasury yields were modestly lower. At his post-meeting news conference, Fed Chair Jerome Powell echoed the concerns about the labor market. “The marked slowing in both the supply of and demand for workers is unusual in this less dynamic…
Share
BitcoinEthereumNews2025/09/18 02:44