Yearn Finance Hack
What happened
On December 17, 2025, Yearn Finance's legacy v1 iEarn TUSD vault suffered a flash loan exploit resulting in approximately $307,000 loss ($245K in TUSD and $55K in 3Crv tokens), with the attacker converting stolen funds to 103 ETH.
The attacker utilized flash loans from Aave V1/V2 and dYdX, withdrawing $203,491 worth of TUSD from Aave Protocol V1, $4,068 worth of USDC from dYdX, and a flash loan of $245,906 worth of TUSD from Aave Protocol V2. The vault's configuration flaw calculated share prices using only the sUSD balance deposited in a Fulcrum sUSD vault strategy, opening the door to "donation attacks" where an attacker transfers assets directly into a vault to distort accounting metrics. The stolen funds moved quickly across Curve and Yearn Finance, swapping four different tokens and shifting millions in stablecoins including $30 million from Morpho, $10 million from Yearn, and $11 million through Curve's DAI/USDC pool, with the attacker paying minimal fees of just $611 in Ethereum and 0.01 ETH ($29.60).
The immutable nature of the contract meant security analysts who warned about the vulnerability before the exploit could not prevent it, as the contract cannot be patched or paused once deployed.
Case & protocol details
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report x.com
- analysis Website reference x.com
- analysis Website reference x.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.