Yearn Finance Faces New Security Breach in yETH Liquidity Pool

Beginner
Quick Reads
Last Updated 2026-03-27 07:57:27
Reading Time: 1m
Yearn Finance's yETH pool was recently hit by a highly sophisticated attack. The attacker used manipulated minting events to rapidly withdraw the majority of LST assets from the pool. This resulted in millions of dollars in losses. While Yearn's primary Vault products remained unaffected, this incident highlights the ongoing security challenges DeFi protocols face in cross-contract interactions, minting mechanisms, and asset pool governance.

Major Security Risk Hits Yearn Finance yETH Pool

Yearn Finance, the decentralized yield protocol, has once again faced a security incident. The yETH liquidity pool recently experienced irregular trading activity, with a substantial volume of Liquid Staking Tokens (LSTs) withdrawn in a short span. As the primary pool aggregating leading LSTs, the yETH pool is a cornerstone of the Yearn protocol. This incident is a significant concern for the market.

Attack Method: Forged Minting and Instant Pool Drain

On-chain data shows that the attacker deployed a series of custom contracts to mint an unlimited supply of yETH tokens in a single transaction. Using these artificially generated tokens, they exchanged for all LST assets in the pool, resulting in the pool being emptied within seconds. The losses are estimated at several million US dollars.

Following the attack, approximately 1,000 ETH (about $3 million) was quickly transferred into Tornado Cash, complicating efforts to trace the funds. Multiple attack contracts self-destructed after execution, highlighting the attack’s meticulous planning and technical sophistication.

Loss Estimates Await Official Confirmation

Prior to the incident, the yETH pool held roughly $11 million in assets. However, the actual losses require confirmation from Yearn Finance and blockchain security teams, as some ETH may have been consumed or become untraceable during the exploit.

On-chain analyst Togbe was the first to detect the breach, identifying anomalies while tracking large fund movements and bringing the attack to light.

Official Response and Historical Context


(Source: yearnfi)

Yearn Finance announced on X that it is actively investigating the incident. The team emphasized that V2 and V3 Vaults remain unaffected. The protocol has previously faced several security and technical challenges:

  • 2021: yDAI Vault vulnerability resulted in losses of approximately $11 million
  • 2022: Founder Andre Cronje announced his departure from the project
  • Late 2023: A script error reduced treasury assets by 63%, though user funds were not impacted

As of now, Yearn’s team has not released further details from its investigation. The market continues to await additional updates.

To learn more about Web3, sign up here: https://www.gate.com/

Summary

This incident demonstrates that even long-standing DeFi protocols with robust communities and audit histories remain vulnerable to flaws in contract logic, cross-contract interactions, and governance design. Yearn Finance needs to focus not only on fixing vulnerabilities but also on restoring market trust. The broader DeFi ecosystem is reminded that security audits, monitoring systems, and ongoing maintenance are critical for long-term stability. While innovation drives DeFi forward, striking the right balance between speed and security will ultimately determine the sector’s longevity and success.

Author: Allen
Disclaimer
* The information is not intended to be and does not constitute financial advice or any other recommendation of any sort offered or endorsed by Gate.
* This article may not be reproduced, transmitted or copied without referencing Gate. Contravention is an infringement of Copyright Act and may be subject to legal action.

Related Articles

AI-Native Settlement Layers: How United Stables Is Building the Next Financial Rail
Beginner

AI-Native Settlement Layers: How United Stables Is Building the Next Financial Rail

Stablecoins were originally designed as dollar substitutes within exchanges, primarily used for asset pricing and trade settlement. As on-chain financial ecosystems have matured, their role has expanded beyond simple payments to include collateral assets, cross-chain liquidity mediums, and unified settlement units. In particular, as AI systems and automated agents begin to participate directly in economic activity, demand has risen sharply for programmable value units capable of instant settlement. This shift is pushing stablecoins toward the role of foundational financial infrastructure.
2026-03-25 03:16:17
DePIN Identity Network and Real World Applications: How Humanity Protocol Brings on-chain Identity Into the Physical World
Beginner

DePIN Identity Network and Real World Applications: How Humanity Protocol Brings on-chain Identity Into the Physical World

Most Web3 identity systems remain confined to on-chain environments and struggle to achieve meaningful adoption in real world settings. Through a DePIN architecture and physical verification hardware, Humanity Protocol aims to bring decentralized identity into access control systems, hospitality, public services, and offline events, allowing on-chain identity to function not just as a digital credential, but as foundational infrastructure for real world access.
2026-03-25 07:40:53
Gold Price Forecast for the Next Five Years: 2026–2030 Trend Outlook and Investment Implications, Could It Reach $6,000?
Beginner

Gold Price Forecast for the Next Five Years: 2026–2030 Trend Outlook and Investment Implications, Could It Reach $6,000?

Analyze current gold price trends alongside authoritative five-year forecasts, integrating an evaluation of market risks and opportunities. This gives investors insight into the potential trajectory of gold prices and the main drivers expected to shape the market over the next five years.
2026-03-25 18:13:30
Aster vs Hyperliquid: Which Perp DEX Will Prevail?
Beginner

Aster vs Hyperliquid: Which Perp DEX Will Prevail?

Aster and Hyperliquid are the two representative protocols of the "purpose-built L1 path" within the current decentralized perpetual exchange (Perp DEX) sector. As a pioneer in the field, Hyperliquid has built a deep liquidity moat through its highly mature order book architecture and strong community consensus. Conversely, Aster, as a rising challenger, seeks to leapfrog the competition in high-performance trading through more aggressive multi-chain aggregation logic, private transaction modules, and an underlying execution environment optimized for 2026 market demands.
2026-03-24 11:58:33
Aerodrome Tokenomics: How ve(3,3) Powers Base's Most Profitable DEX
Beginner

Aerodrome Tokenomics: How ve(3,3) Powers Base's Most Profitable DEX

AERO is the native token of Aerodrome Finance, a core decentralized exchange and liquidity protocol in the Base ecosystem. It is primarily used for liquidity incentives and ecosystem operations. veAERO is a governance NFT that users receive by locking AERO, representing both voting power and the right to share protocol revenue. Through a dual track structure of AERO as a utility token and veAERO as a governance credential, Aerodrome separates liquidity usage value from long term governance power, allowing participants to act as liquidity providers, governance decision makers, and revenue sharers within the same system.
2026-03-25 06:40:31
The ve(3,3) Flywheel Explained: How AERO Tokenomics Powers Aerodrome’s DeFi Economy
Beginner

The ve(3,3) Flywheel Explained: How AERO Tokenomics Powers Aerodrome’s DeFi Economy

In the competition for DeFi liquidity, high-inflation mining alone is no longer enough to build lasting advantages. Aerodrome applies the ve(3,3) economic model to redesign token emissions, voting mechanisms, and revenue distribution, creating a liquidity flywheel centered on governance and cash flow. This article examines AERO tokenomics, the veAERO locking mechanism, and protocol revenue models to explain how Aerodrome builds a sustainable DeFi economic system.
2026-03-25 06:41:58