YIEDL Hack

Reported loss $150K
BNB Chain
Missing Input Validation

What happened

On April 24, 2024, an attacker drained YIEDL's Y-BULL spot vault on BNB Smart Chain. Its redeem function passed a caller-supplied dataList to the 1inch router without validating it. By redeeming zero shares with crafted swap data, the attacker made the vault swap its own tokens and send the output to the attacker's address.

BlockSec Phalcon detected a series of attacks and put the loss at over $150K. Quadriga Initiative lists $157K, and SlowMist estimated about $300K. YIEDL said the lost funds were company funds, not community users' funds, and that its other vaults were not affected. It said it would publish an incident report after investigations with authorities and its partners.

How it happened

  1. The vault's redeem(sharesToRedeem, receivingAsset, minTokensToReceive, dataList, useDiscount) loops over the vault's assets. For each asset that is not the requested output, it makes an external call to the 1inch router using the matching entry in the caller-supplied dataList.
  2. The contract did not check dataList, and it did not require the caller to redeem a non-zero number of shares.
  3. The attacker (0x322696471792440499b1979e0a440491e870667a) called redeem with sharesToRedeem = 0 and crafted unoswapTo payloads whose recipient was the attacker. The swaps sold the vault's holdings, such as USDC, BTCB and ETH, from the vault's own balance.
  4. Because no shares were burned, the attacker repeated the call many times across multiple transactions (e.g. 0x49ca5e18...20c2ec) until the vault was drained.

Protocol details

Classification Input Validation
Protocol Type DeFi Protocol
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.