The post Yearn hacker loses $2.4M of $9M loot as tokens burned from wallet appeared on BitcoinEthereumNews.com. Yearn Finance suffered a $9 million hack on Sunday evening, marking the long-established decentralized finance platform’s fifth incident in as many years.  The attack, which occurred just after 9pm UTC, hit the yield farm’s yETH stableswap pool, extracting various ether (ETH) liquid staking tokens (LSTs). Of these, 850 of Redacted Cartel’s LST, pxETH, (worth $2.4 million) was burned by the issuer, with an equivalent amount simultaneously minted to the team’s multisig. Read more: DeFi yield aggregator Yearn discloses September incident in yUSND vault An on-chain message warned the hacker of this possibility approximately eight hours earlier. It reads, “your erc20s are at risk of being burnt and/or blacklisted,” and advises to “deposit them to a pool or swap to ETH to prevent such happenings.” In addition to the earlier warning, the hacker’s address received two fake bounty offers. Later, a Yearn deployer address urged the attacker to “open a communication channel” for the purposes of “discussing terms constructively.” Read more: DeFi platform Yearn exploits itself, begs for money back Yearn’s third hack The hack was down to a combination of a “numerical bug: unchecked underflow/overflow” and an “invariant-management issue,” according to the post-mortem report published by Yearn’s pseudonymous “bunny talisman” Banteg. This led to the attacker minting 235e36 yETH tokens which it then used to withdraw the underlying LSTs. Banteg was keen to point out that yETH is separate to Yearn’s core vault products and “doesn’t share any code with vaults.” One observer pointed out the efficiency of the hack transaction, which covered the entire attack flow. They claim it “deployed attack contracts, conducted the attack, tornado cashed part of the profits, and self-destructed the contracts.” Launched in September 2023, it took over two years for someone to exploit the vulnerability in the yETH pool. Earlier that year, a yUSDT vault lost… The post Yearn hacker loses $2.4M of $9M loot as tokens burned from wallet appeared on BitcoinEthereumNews.com. Yearn Finance suffered a $9 million hack on Sunday evening, marking the long-established decentralized finance platform’s fifth incident in as many years.  The attack, which occurred just after 9pm UTC, hit the yield farm’s yETH stableswap pool, extracting various ether (ETH) liquid staking tokens (LSTs). Of these, 850 of Redacted Cartel’s LST, pxETH, (worth $2.4 million) was burned by the issuer, with an equivalent amount simultaneously minted to the team’s multisig. Read more: DeFi yield aggregator Yearn discloses September incident in yUSND vault An on-chain message warned the hacker of this possibility approximately eight hours earlier. It reads, “your erc20s are at risk of being burnt and/or blacklisted,” and advises to “deposit them to a pool or swap to ETH to prevent such happenings.” In addition to the earlier warning, the hacker’s address received two fake bounty offers. Later, a Yearn deployer address urged the attacker to “open a communication channel” for the purposes of “discussing terms constructively.” Read more: DeFi platform Yearn exploits itself, begs for money back Yearn’s third hack The hack was down to a combination of a “numerical bug: unchecked underflow/overflow” and an “invariant-management issue,” according to the post-mortem report published by Yearn’s pseudonymous “bunny talisman” Banteg. This led to the attacker minting 235e36 yETH tokens which it then used to withdraw the underlying LSTs. Banteg was keen to point out that yETH is separate to Yearn’s core vault products and “doesn’t share any code with vaults.” One observer pointed out the efficiency of the hack transaction, which covered the entire attack flow. They claim it “deployed attack contracts, conducted the attack, tornado cashed part of the profits, and self-destructed the contracts.” Launched in September 2023, it took over two years for someone to exploit the vulnerability in the yETH pool. Earlier that year, a yUSDT vault lost…

Yearn hacker loses $2.4M of $9M loot as tokens burned from wallet

For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Yearn Finance suffered a $9 million hack on Sunday evening, marking the long-established decentralized finance platform’s fifth incident in as many years. 

The attack, which occurred just after 9pm UTC, hit the yield farm’s yETH stableswap pool, extracting various ether (ETH) liquid staking tokens (LSTs).

Of these, 850 of Redacted Cartel’s LST, pxETH, (worth $2.4 million) was burned by the issuer, with an equivalent amount simultaneously minted to the team’s multisig.

Read more: DeFi yield aggregator Yearn discloses September incident in yUSND vault

An on-chain message warned the hacker of this possibility approximately eight hours earlier. It reads, “your erc20s are at risk of being burnt and/or blacklisted,” and advises to “deposit them to a pool or swap to ETH to prevent such happenings.”

In addition to the earlier warning, the hacker’s address received two fake bounty offers. Later, a Yearn deployer address urged the attacker to “open a communication channel” for the purposes of “discussing terms constructively.”

Read more: DeFi platform Yearn exploits itself, begs for money back

Yearn’s third hack

The hack was down to a combination of a “numerical bug: unchecked underflow/overflow” and an “invariant-management issue,” according to the post-mortem report published by Yearn’s pseudonymous “bunny talisman” Banteg.

This led to the attacker minting 235e36 yETH tokens which it then used to withdraw the underlying LSTs.

Banteg was keen to point out that yETH is separate to Yearn’s core vault products and “doesn’t share any code with vaults.”

One observer pointed out the efficiency of the hack transaction, which covered the entire attack flow. They claim it “deployed attack contracts, conducted the attack, tornado cashed part of the profits, and self-destructed the contracts.”

Launched in September 2023, it took over two years for someone to exploit the vulnerability in the yETH pool.

Earlier that year, a yUSDT vault lost $11 million after three years of activity. Meanwhile, back in 2021, a flash loan attack drained another $11 million from the DAI v1 vault, with the hacker profiting just $2.8 million.

Two operational mistakes have also cost the Yearn treasury.

A botched swap in December 2023 lost $1.4 million, and the treasury covered a $25,000 malfunction in the yUSND vault in September, announced last week.

Got a tip? Send us an email securely via Protos Leaks. For more informed news, follow us on X, Bluesky, and Google News, or subscribe to our YouTube channel.

Source: https://protos.com/yearn-hacker-loses-2-4m-of-9m-loot-as-tokens-burned-from-wallet/

Market Opportunity
Ambire Wallet Logo
Ambire Wallet Price(WALLET)
$0.01042
$0.01042$0.01042
+0.77%
USD
Ambire Wallet (WALLET) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Is Doge Losing Steam As Traders Choose Pepeto For The Best Crypto Investment?

Is Doge Losing Steam As Traders Choose Pepeto For The Best Crypto Investment?

The post Is Doge Losing Steam As Traders Choose Pepeto For The Best Crypto Investment? appeared on BitcoinEthereumNews.com. Crypto News 17 September 2025 | 17:39 Is dogecoin really fading? As traders hunt the best crypto to buy now and weigh 2025 picks, Dogecoin (DOGE) still owns the meme coin spotlight, yet upside looks capped, today’s Dogecoin price prediction says as much. Attention is shifting to projects that blend culture with real on-chain tools. Buyers searching “best crypto to buy now” want shipped products, audits, and transparent tokenomics. That frames the true matchup: dogecoin vs. Pepeto. Enter Pepeto (PEPETO), an Ethereum-based memecoin with working rails: PepetoSwap, a zero-fee DEX, plus Pepeto Bridge for smooth cross-chain moves. By fusing story with tools people can use now, and speaking directly to crypto presale 2025 demand, Pepeto puts utility, clarity, and distribution in front. In a market where legacy meme coin leaders risk drifting on sentiment, Pepeto’s execution gives it a real seat in the “best crypto to buy now” debate. First, a quick look at why dogecoin may be losing altitude. Dogecoin Price Prediction: Is Doge Really Fading? Remember when dogecoin made crypto feel simple? In 2013, DOGE turned a meme into money and a loose forum into a movement. A decade on, the nonstop momentum has cooled; the backdrop is different, and the market is far more selective. With DOGE circling ~$0.268, the tape reads bearish-to-neutral for the next few weeks: hold the $0.26 shelf on daily closes and expect choppy range-trading toward $0.29–$0.30 where rallies keep stalling; lose $0.26 decisively and momentum often bleeds into $0.245 with risk of a deeper probe toward $0.22–$0.21; reclaim $0.30 on a clean daily close and the downside bias is likely neutralized, opening room for a squeeze into the low-$0.30s. Source: CoinMarketcap / TradingView Beyond the dogecoin price prediction, DOGE still centers on payments and lacks native smart contracts; ZK-proof verification is proposed,…
Share
BitcoinEthereumNews2025/09/18 00:14
Fed-up Lauren Boebert throws Trump's own words back in his face

Fed-up Lauren Boebert throws Trump's own words back in his face

President Donald Trump is leaning hard on the House GOP to pass Foreign Intelligence Surveillance Act reauthorization — but far-right Rep. Lauren Boebert (R-CO)
Share
Rawstory2026/03/26 04:41
Markets await Fed’s first 2025 cut, experts bet “this bull market is not even close to over”

Markets await Fed’s first 2025 cut, experts bet “this bull market is not even close to over”

Will the Fed’s first rate cut of 2025 fuel another leg higher for Bitcoin and equities, or does September’s history point to caution? First rate cut of 2025 set against a fragile backdrop The Federal Reserve is widely expected to…
Share
Crypto.news2025/09/18 00:27