Yearn Finance Hack
What happened
On February 4, 2021, an attacker exploited Yearn's v1 yDAI vault on Ethereum by manipulating Curve 3pool's stablecoin balance and forcing the vault's strategy to deposit at a poor exchange rate. About 11 million DAI left the vault, while Yearn estimated the attacker's own profit at 2.7 million DAI.
The strategy accepted a same-transaction, externally manipulable Curve 3pool exchange rate for a large single-sided investment. A 1% slippage tolerance was too loose, the normal 0.5% withdrawal fee had been set to zero for v2 migration, and the public `earn()` method let any caller force the vulnerable strategy investment.
Case & protocol details
Attack Timeline
The attacker obtained temporary large liquidity and deposited USDC and DAI into Curve 3pool, receiving 3CRV. They then withdrew USDT, deliberately leaving 3pool heavily skewed toward DAI and USDC. Because the v1 vault allowed a caller to invoke earn(), they repeatedly deposited DAI into yDAI, causing StrategyDAI3pool to invest the vault's DAI in the deliberately imbalanced pool at an unfavorable rate.
The attacker restored the pool with USDT, withdrew yDAI, then recreated the skew. In the final cycle, they redeemed their earlier 3CRV position and captured about 2.7 million DAI, while the broader vault loss totalled 11 million DAI. Yearn stopped further strategy deposits within minutes. Its later treasury-funded vault restoration is not represented as recovery of attacker funds.
Funds Recovery
Recovered
$1.7M
Net Loss
$9,295,000
Evidence & learning
Proof of concept
1 availableSources and on-chain records
- report Post-mortem rekt.news
- transaction Transaction etherscan.io
- transaction Transaction etherscan.io
- code Code reference github.com
- code Code reference github.com
- analysis Website reference twitter.com
- analysis Blog reference blog.defiyield.app
- analysis Inside the Yearn v1 yDAI Hack halborn.com
- analysis Yearn Finance DAI Vault Exploit coindesk.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.