Yearnspace Hack
Incident Overview
The contract deployer had permission to mint tokens as he added himself to the list of minters by invoking addMinter function:
https://etherscan.io/tx/0xb3b88155…e4583f
The owner called the mint function twice at the following transactions:
https://etherscan.io/tx/0xaa5b1712…d29eeb
https://etherscan.io/tx/0x95aac0cc…b34183
The total supply was increased by 15,000 YFS tokens. The owner obtained the YFS tokens and started exchanging them for ETH, having conducted a total of 38 transactions. The contract deployer stole 58 ETH and split this amount among some external wallets. The website is down and the Twitter account is deleted.
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Yearnspace, these are the critical security checks that could have prevented this incident (December 2020).
- Verify all logic paths related to Rugpull are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSources & References
-
01
Source 1 https://archive.ph/wJdWM
-
02
de.fi Analysis https://t.me/defiyield_ann/269
- 03
Learn to Prevent the Next Yearnspace
The Yearnspace hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.