Yearn Finance Hack
Incident Overview
On November 30, 2025, Yearn Finance suffered a $9 million exploit via an infinite mint vulnerability in its yETH pool; the attacker minted 235 trillion yETH tokens, laundered $3 million through Tornado Cash, and holds $6 million in the exploiter's wallet with no funds recovered.
The exploit occurred around 21:11 UTC on November 30, 2025, when a malicious wallet executed an infinite-mint attack on the yETH LST stableswap pool. The attacker minted approximately 235 trillion yETH tokens in a single transaction, depleting the pool and withdrawing real ETH and liquid staking assets. The affected contract is a custom version of popular stableswap code, unrelated to other Yearn products - Yearn V2/V3 vaults were not impacted.
Multiple newly deployed helper contracts appeared just moments before the attack and vanished through self-destruct calls once the pool was drained.
Exploiter:
https://etherscan.io/address/0xFb63aa93…fa4779
Exploit tx:
https://etherscan.io/tx/0x53fe7ef1…331156
Incident Report
Market Context at Time of Hack
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Yearn Finance, these are the critical security checks that could have prevented this incident (November 2025).
- Verify all logic paths related to Other are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSecurity Audit History
- Audit Report 1 Report
Sources & References
Learn to Prevent the Next Yearn Finance
The Yearn Finance hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.