Yearn Finance Hack

TOTAL LOST $11.5M
High Flash Loan Attacks Ethereum

What happened

On April 13, 2023, an attacker exploited the legacy iEarn yUSDT contract on Ethereum. A deployment misconfiguration let the attacker distort the vault's accounting, mint an enormous amount of yUSDT from minimal capital, and swap the unbacked shares for stablecoins from Curve pools. Yearn said the immutable iEarn contract had been deprecated in 2020; current Yearn v2 Vaults were not affected.

Technical Root Cause

A legacy yUSDT deployment was misconfigured to use Fulcrum iUSDC where it should have used Fulcrum iUSDT. The incompatible asset accounting enabled the attacker to manipulate the vault balance used in the share-mint calculation, collapse the value per share, and mint unbacked yUSDT. This is a deployment/configuration and share-accounting flaw, not an external price-oracle manipulation.

Case & protocol details

Classification Protocol Logic / Legacy Contract Misconfiguration / Yield Aggregator
Protocol Type Yield Aggregator
Affected asset / contract YFI
Smart Contract Language Solidity
Official Website yearn.finance/
Protocol Twitter/X @iearnfinance

Attack Timeline

The attacker used Balancer flash loans of 5 million DAI, 5 million USDC, and 2 million USDT. They manipulated the legacy yUSDT contract's reserve and accounting path, including minting and transferring bZx iUSDC to the yUSDT contract, causing the share value to fall to zero after rebalance. After sending 1 wei of USDT, the attacker could mint a massive amount of yUSDT, swap it through Curve for stablecoins, and repay the flash loans.

The exploit affected the deprecated pre-YFI contract, not current Yearn vaults or Aave. Published incident estimates vary with the valuation time, so the record keeps an approximate $11.54 million incident figure rather than treating it as a fixed accounting value.

Security review history

  • MixBytes 2020-12-03 No public report
  • Trail of Bits 2021-04-30 No public report
  • Quantstamp Report
  • PeckShield Report

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.