Yala Hack
What happened
Yala suffered unauthorized token issuance in September 2025. Halborn's analysis describes abuse of a temporary deployment key to establish a bridge connection that later accepted attacker-controlled tokens. Approximately $7.64 million in USDC was extracted.
The reported weakness was deployment-key access and unauthorized bridge configuration. Returning over-minted tokens is distinct from recovering the USDC extracted through them. The precise initial key-compromise mechanism remains unestablished.
How it happened
- During an August deployment, access to a temporary key enabled an unauthorized cross-chain connection.
- In September, the attacker used a malicious Polygon OFTU contract to send tokens through Yala's bridge as YU on Solana.
- The attacker minted 120 million OFTU and bridged 30 million. Approximately 22.2 million over-minted tokens were returned, while the remaining portion was converted and laundered.
- Yala disabled conversion and bridging and blocked further minting and transfers.
Protocol details
Evidence
- analysis DeFiLlama defillama.com
- analysis Explained: The Yala Hack (September 2025) halborn.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.