Yearn Finance Hack
What happened
On November 30, 2025, Yearn Finance suffered a $9 million exploit via an infinite mint vulnerability in its yETH pool; the attacker minted 235 trillion yETH tokens, laundered $3 million through Tornado Cash, and holds $6 million in the exploiter's wallet with no funds recovered.
The exploit occurred around 21:11 UTC on November 30, 2025, when a malicious wallet executed an infinite-mint attack on the yETH LST stableswap pool. The attacker minted approximately 235 trillion yETH tokens in a single transaction, depleting the pool and withdrawing real ETH and liquid staking assets. The affected contract is a custom version of popular stableswap code, unrelated to other Yearn products - Yearn V2/V3 vaults were not impacted.
Multiple newly deployed helper contracts appeared just moments before the attack and vanished through self-destruct calls once the pool was drained.
Exploiter:
https://etherscan.io/address/0xFb63aa93…fa4779
Exploit tx:
https://etherscan.io/tx/0x53fe7ef1…331156
Case & protocol details
Evidence & learning
Sources and on-chain records
- report Report x.com
- report Report forklog.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.