YieldCore Hack

Reported loss $399K
Ethereum
Improper Access Control

What happened

On April 28, 2026, the YieldCore-3rd-deal vault on Ethereum was exploited for about $398,000. The affected vault was permissionlessly listed on Trading Protocol; reporting states that Trading Protocol's core contracts were not affected.

Technical root cause

The vault lacked a caller-authorization check on a function capable of moving funds, allowing an arbitrary external caller to invoke the drain path.

How it happened

An attacker called an unrestricted funds-moving function on the YieldCore-3rd-deal vault, draining the vault's balance in a single transaction.

Protocol details

Classification Access Control
Protocol Type DeFi Protocol
Implementation language Solidity

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.