Yearn Finance Hack
Incident Overview
Yearn Finance and Aave Protocol were exploited via a flash loan attack, resulting in the loss of 11,512,509 $USD worth of $ETH and $DAI.
Yearn Finance is a Yield Aggregator, and Aave Protocol is a Lending and Borrowing platform. The hacker performed an attack using two malicious smart contracts. The attack started with the exploiter taking a flash loan for 2,000,000 $USDT, 5,000,000 $USDC, and 5,000,000 $DAI from Balancer.
Borrowed assets are used to exploit Yearn Finance’s USDT pool vulnerability and mint a big amount of ycUSDT (~204 billion) and yUSDT (~33 trillion) tokens then swap them for various stablecoins worth 11,512,509 $USD. Another smaller attack took place during the exploit which affected Aave’s LendingPoolCoreV1 contract. Worth noticing that the exploiter repaid all users USDT positions in the Aave V1 protocol.
During multiple transactions stolen assets were transferred to destination wallets part of which as 1,000 $ETH was bridged through TornadoCash.
Attacker address:
https://etherscan.io/address/0x5bac20be…9cdfe0
Attacker wallets with funds:
https://etherscan.io/address/0x16af29b7…2374a5
https://etherscan.io/address/0x6f4a6262…6f6ab8
Malicious transaction examples:
https://etherscan.io/tx/0x8db0ef33…053138
https://etherscan.io/tx/0xd55e43c1…cda95d
Malicious Contracts:
https://etherscan.io/address/0x8102ae88…d0579e
https://etherscan.io/address/0x9fcc1409…a0eb0f
Incident Report
Protocol Information
Market Context at Time of Hack
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Yearn Finance, these are the critical security checks that could have prevented this incident (April 2023).
- Verify all logic paths related to Flashloan Misconfiguration Exploit / Flash Loan Attack are guarded by proper access controls and input validation - see the Flash Loans Attacks attack class for patterns
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialRelated Attack Classes
The technique used in this hack maps to these vulnerability classes in our security curriculum:
Sources & References
- 01
- 02
- 03
- 04
Learn to Prevent the Next Yearn Finance
The Yearn Finance hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.