Yearn Finance suffers fourth exploit only weeks after third

Only weeks after losing $6.6 million to an infinite mint exploit, a Yearn Finance smart contract has again been exploited, allowing an attacker to make off with around 103 ETH (~$300,000). The affected contract is a legacy contract that was part of the Yearn v1 project (once known as iearn). The attacker used a flash loan to manipulate the price of tokens in the vault, allowing them to withdraw the iearn assets, which they then swapped for ETH.

This is Yearn's fourth hack, following the $6.6 million theft in November, an $11 million exploit in 2023, and an $11 million exploit in 2021. Yearn also lost around $1.4 million in 2023 in connection to the Euler Finance attack.

Yearn Finance hacked for the third time

Yearn Finance, a defi yield protocol, has suffered another hack. The exploiter took advantage of bugs in the project's smart contract to drain assets from several of its pools by minting a huge number of yETH tokens and then withdrawing the corresponding asset in the pools.

$2.4 million of the stolen assets, which were denominated in pxETH, a liquid staking token issued by Redacted Cartel, were recovered after the issuer burned the stolen tokens and reissued them to the team's wallet — essentially, removing the tokens from the hacker's wallet. However, the hacker routed the remaining funds through the Tornado Cash cryptocurrency mixer, which makes recovery substantially more challenging.

This is the third time Yearn Finance has been hacked, following an $11 million exploit in 2023 and another $11 million exploit in 2021. Yearn also suffered around $1.4 million in losses in 2023 in connection to the Euler Finance attack.

Yearn Finance accidentally swaps its entire Ip-yCRVv2 treasury, asks nicely for the money back

Periodically, Yearn Finance converts a small quantity of its treasury tokens into stablecoins to spend on operations. However, something went terribly wrong during this process when they went to perform the swap and erroneously converted the entire amount — nearly 3.8 million Ip-yCRVv2 tokens — into a stablecoin. According to one Yearn Finance employee, this pool of tokens comprised around 3% of the project's treasury.

Because there was not sufficient liquidity for such a large trade at the going price, the trade was ultimately fulfilled, but at a 63% loss. Before the trade, that quantity of tokens was priced at around $2.28 million; however, Yearn received only around $780,000 in stablecoins because of the slippage.

Yearn quickly identified the issue and embarked on a campaign to ask nicely for the counterparties in the trade to please give some of their profits back. In on-chain messages, Yearn wrote: "one of yearns multisigs made a costly mistake last night that affected a critical source of yCRVs liquidity. we identified you as having made a profit off of this and are kindly requesting that you return as much as you see reasonable to yearns main multisig: ychad.eth. sorry we have to ask this, but hope you can understand." Doesn't hurt to ask, I guess. So far, only one wallet has taken them up on the offer, returning 2 ETH (~$4,400).

Yearn Finance exploited for more than $11 million

A bug in a token issued by the Yearn Finance defi protocol resulted in a loss that has been estimated at around $11.6 million. An attacker was able to use a 10,000 USDT deposit to mint more than 1.2 quadrillion yUSDT, a wrapped version of the Tether (USDT) stablecoin. Losses were limited somewhat by the fact that only older versions of the Yearn protocol were vulnerable to the bug, and the version had been "frozen" since December 2022.

The attacker began swapping tokens out for other stablecoins shortly after the exploit, moving them into lending projects like Aave and laundering them through the Tornado Cash cryptocurrency mixer. There were early concerns that Aave itself was impacted by an exploit, but it was later clarified that Aave had simply been used to swap tokens involved in the Yearn exploit, and did not appear to itself be vulnerable.

This is not the first exploit involving Yearn Finance, which was hacked for $11 million in 2021, and which lost around $1.4 million in connection to the massive Euler Finance attack in March 2023.

Crowdfunded TitanReach MMO game project crashes and burns after developer spends investor money on a bad crypto gamble and a Tesla

A video game character stands on a beachTitanReach game screenshots (attribution)
The "Runescape-like" MMO game known as TitanReach has had a bumpy history so far, first failing to reach its Kickstarter goal in a crowdfunding project launched in 2020, but building enough community behind it to continue with crowdfunding off of Kickstarter to fund development on a month-to-month basis. The developer earned more than $200,000 via this model, but this only kept the project going until around August 2021, when they ran out of money. However, a month later, the lead developer of the project, "Unravel", reported that an anonymous investor had "fully funded this whole game out of the kindness of his heart. No strings attached. It sounds too good to be true, but it's true." Development resumed.

On February 11, Unravel announced that his studio "would be closing its doors for good. TitanReach will be laid to rest. The reasons for this are private." From there he went into a long message about the previously-unannounced crypto and NFT plans he had for the game, which unsurprisingly enraged the community who had supported the game.

YouTuber KiraTV, who had become close to the project, its developer, and the investor, revealed that the anonymous angel investor had been the cryptocurrency entrepreneur behind Yearn Finance, though Kira said that he believed the investor had not influenced Unravel to add crypto elements to the game. Kira alleged that Unravel had taken $150,000 of money sent by the investor and put it into $TIME, the token associated with the ill-fated Wonderland project. When he lost the money overnight, the investor cut funding for the project. It later came out that Unravel had allegedly used company money to make risky cryptocurrency investments besides the one incident with $150,000, and had even used the investor's money to purchase himself a new Tesla.

Yearn Finance loses $11 million to a hack

An exploit in Yearn Finance's yDAI vault resulted in an $11 million loss to the platform, though "only" $2.8 million of this went to the hacker.

No JavaScript? That's cool too! Check out the Web 1.0 version of the site to see more entries.