Yearn Finance Hack
What happened
On April 13, 2023, an attacker exploited the legacy iEarn yUSDT contract on Ethereum. A deployment misconfiguration let the attacker distort the vault's accounting, mint an enormous amount of yUSDT from minimal capital, and swap the unbacked shares for stablecoins from Curve pools. Yearn said the immutable iEarn contract had been deprecated in 2020; current Yearn v2 Vaults were not affected.
A legacy yUSDT deployment was misconfigured to use Fulcrum iUSDC where it should have used Fulcrum iUSDT. The incompatible asset accounting enabled the attacker to manipulate the vault balance used in the share-mint calculation, collapse the value per share, and mint unbacked yUSDT. This is a deployment/configuration and share-accounting flaw, not an external price-oracle manipulation.
Case & protocol details
Attack Timeline
The attacker used Balancer flash loans of 5 million DAI, 5 million USDC, and 2 million USDT. They manipulated the legacy yUSDT contract's reserve and accounting path, including minting and transferring bZx iUSDC to the yUSDT contract, causing the share value to fall to zero after rebalance. After sending 1 wei of USDT, the attacker could mint a massive amount of yUSDT, swap it through Curve for stablecoins, and repay the flash loans.
The exploit affected the deprecated pre-YFI contract, not current Yearn vaults or Aave. Published incident estimates vary with the valuation time, so the record keeps an approximate $11.54 million incident figure rather than treating it as a fixed accounting value.
Evidence & learning
Sources and on-chain records
- report Report twitter.com
- report OpenZeppelin Security Report: April to June 2023 openzeppelin.com
- transaction Transaction etherscan.io
- analysis Website reference theblock.co
- analysis Blog reference blog.solidityscan.com
- analysis Website reference twitter.com
- analysis Earnings Misconfigured: Yearn.finance Exploit Explained certik.com
- analysis Yearn Finance Exploit Points to Dangers of Old Smart Contracts blockworks.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.