Legacy Code Flaw Enables $9M DeFi Heist, Exposing Sector's Vulnerabilities

Generated by AI AgentCoin WorldReviewed byAInvest News Editorial Team
Monday, Dec 1, 2025 5:54 am ET1min read
Speaker 1
Speaker 2
AI Podcast:Your News, Now Playing
Aime RobotAime Summary

- Yearn Finance lost $9 million in 2025 after a hacker exploited a legacy yETH pool vulnerability to mint infinite tokens and drain liquidity.

- The attack used self-destructing contracts to obscure traces, stealing $3 million via Tornado Cash while $6 million remained in the attacker's wallet.

- Yearn halted the affected pool and pledged to audit pre-2023 contracts, highlighting risks from outdated smart contract logic in DeFi protocols.

- The breach occurred amid a $127 million sector-wide hacking trend in 2025, underscoring urgent needs for rigorous audits and hybrid verification systems.

Yearn Finance, a prominent decentralized finance (DeFi) platform,

on November 30, 2025, after a hacker exploited a vulnerability in its yETH token pool, minting near-infinite tokens to drain liquidity pools in a single transaction. The attack targeted a legacy yETH stableswap pool, - effectively an infinite supply - and extract real assets such as and liquid staking derivatives from and Curve pools. The stolen funds included $3 million in ETH routed through , a privacy-focused mixer, while an additional $6 million remained in the attacker's wallet. confirmed that its newer V2 and V3 vaults were unaffected, .

The exploit

in the yETH pool, which failed to properly validate token minting conditions. Attackers deployed and later self-destructed helper contracts to obscure their on-chain footprint, a tactic observed in prior DeFi breaches. Blockchain security firm PeckShield noted that in the yETH contract.
The incident follows a broader trend of DeFi exploits in 2025, in November alone, including a $116 million Balancer cross-chain attack.

Yearn Finance's response included halting the affected yETH pool and

. The platform's co-founder, Andre Cronje, , vowing to audit pre-2023 contracts and implement safeguards to prevent future incidents. Despite assurances, the breach , Yearn's governance token, which briefly rose from $4,080 to $4,160 due to liquidity imbalances and short-covering. The token's thin market and during the incident.

The attack underscores persistent challenges in DeFi security, where complex smart contracts and composability create attack vectors. Experts

, sunset clauses for legacy contracts, and hybrid on-chain/off-chain verification systems to mitigate risks. For users, the incident serves as a cautionary tale about the trade-offs between high-yield opportunities and protocol vulnerabilities. Yearn's transparency in disclosing the breach and its commitment to post-incident analysis may help rebuild trust, but the event reinforces the sector's susceptibility to sophisticated exploits.

Comments



Add a public comment...
No comments

No comments yet