Yala Hack

Reported loss $7.6M
Polygon Solana Ethereum
Deployer Key Compromised

What happened

Yala suffered unauthorized token issuance in September 2025. Halborn's analysis describes abuse of a temporary deployment key to establish a bridge connection that later accepted attacker-controlled tokens. Approximately $7.64 million in USDC was extracted.

Technical root cause

The reported weakness was deployment-key access and unauthorized bridge configuration. Returning over-minted tokens is distinct from recovering the USDC extracted through them. The precise initial key-compromise mechanism remains unestablished.

How it happened

  1. During an August deployment, access to a temporary key enabled an unauthorized cross-chain connection.
  2. In September, the attacker used a malicious Polygon OFTU contract to send tokens through Yala's bridge as YU on Solana.
  3. The attacker minted 120 million OFTU and bridged 30 million. Approximately 22.2 million over-minted tokens were returned, while the remaining portion was converted and laundered.
  4. Yala disabled conversion and bridging and blocked further minting and transfers.

Protocol details

Classification Key Compromise
Protocol Type CDP
Implementation language Rust
Protocol links Website @yalaorg

Market Context at Time of Hack

Token Price at Hack $0.1781
Market Cap at Hack $43.8M
Reported loss / token market cap 17.44%
Token Categories
DeFi Ethereum Ecosystem Polychain Capital Portfolio Governance Galaxy Digital Portfolio Hashkey Capital Portfolio BNB Chain Ecosystem Bitcoin Ecosystem

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.