Yearn Finance Faces Second Hack Since December

3 Min Read Tags:

  • Yearn Finance suffered a second hack since early December 2025, losing approximately $300,000 in crypto assets.
  • The breach exploited a vulnerability within the Yearn Finance V1 contract.
  • The attacker converted stolen assets into 103 ETH and left 214,000 sUSD in the vault.
  • The vulnerability was tied to the configuration of iEarn storage and known issues with outdated contracts.

Yearn Finance Faces Second Hack Since Early December

In a significant setback for Yearn Finance, the project faced its second hack since early December 2025. The incident resulted in an estimated loss of $300,000 as reported by PeckShield experts. This breach highlights ongoing security challenges within decentralized finance (DeFi) protocols.

Exploiting Vulnerabilities in Yearn Finance V1

The recent attack targeted vulnerabilities within the Yearn Finance V1 contract. According to security analysts, including William Lee, the issue stemmed from misconfigurations in iEarn’s storage system. The attacker leveraged these vulnerabilities to manipulate asset transfers and maximize their gain.

Technical Breakdown of the Attack

The attacker initiated their plan by taking loans in TUSD and sUSD. They transferred sUSD to Fulcrum and subsequently deposited TUSD into Yearn. By transferring Fulcrum sUSD back into storage, they artificially inflated share values before executing a rebalance function that drastically reduced share prices. This enabled them to profit from selling shares through Curve Finance pools.
Notably, despite converting some assets into 103 ETH for personal gain, they left behind a substantial amount—214,000 sUSD—inaccessible within the vault.

Response from Yearn Finance

Yearn Finance addressed this incident by emphasizing that it exclusively affected iEarn storage and did not impact other components of their ecosystem. The team acknowledged that the exploited contract was outdated with long-known vulnerabilities.
The firm’s response underscores ongoing efforts to mitigate risks associated with legacy systems while reinforcing newer components’ resilience against similar threats.

Implications for DeFi Security

This latest attack on Yearn Finance underlines persistent security concerns plaguing decentralized finance platforms. It serves as both a cautionary tale for investors and an urgent call-to-action for developers across DeFi ecosystems to prioritize robust security measures and timely updates on all contracts—especially those considered obsolete or vulnerable.
As DeFi continues evolving rapidly alongside broader cryptocurrency markets globally; ensuring secure infrastructure remains paramount not only preserving user trust but also safeguarding burgeoning industry growth potential worldwide.

Canary Capital Launches First US Spot TRX ETF With Staking

Canary Capital launched the Canary Staked TRX ETF on Cboe BZX under ticker TRXS on Sept. 9, 2026, offering direct TRX exposure and staking rewards.

5 Min Read
Anthropic Models 3 US Economic Scenarios Through 2030

Anthropic published a model outlining three scenarios for the U.S. economy through 2030, with its extreme scenario suggesting annual GDP growth could reach 15% alongside historically high unemployment.

7 Min Read
Robinhood CEO Says Companies Cannot Control Tokenization of Their Shares

In September 2026, Robinhood CEO Vlad Tenev said companies cannot prevent third-party products linked to their shares, defending 1:1 share-backed Stock Tokens after AMC CEO Adam Aron challenged their legality.

5 Min Read
Germany Will Change Crypto-Asset Tax Rules in 2027, Media Reports

Germany’s draft crypto tax reforms would from Jan. 1, 2027, tax profits on covered assets acquired after Dec. 31, 2026, regardless of holding period, while platforms would begin withholding tax…

5 Min Read
Vitalik Buterin Says Recursive STARKs Could Cut Ethereum Private, Post-Quantum Transaction Costs

On Sept. 9, Ethereum co-founder Vitalik Buterin explained EIP-8288, a proposal to aggregate STARK proofs and cryptographic signatures at the mempool level, potentially reducing costs without changing the EVM.

6 Min Read