Yearnspace Hack
What happened
The contract deployer had permission to mint tokens as he added himself to the list of minters by invoking addMinter function:
https://etherscan.io/tx/0xb3b88155…e4583f
The owner called the mint function twice at the following transactions:
https://etherscan.io/tx/0xaa5b1712…d29eeb
https://etherscan.io/tx/0x95aac0cc…b34183
The total supply was increased by 15,000 YFS tokens. The owner obtained the YFS tokens and started exchanging them for ETH, having conducted a total of 38 transactions. The contract deployer stole 58 ETH and split this amount among some external wallets. The website is down and the Twitter account is deleted.
Case & protocol details
Evidence & learning
Sources and on-chain records
- report Report archive.ph
- analysis de.fi Analysis t.me
- analysis Web Archive web.archive.org
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.