Yearn Finance hack — February 2021
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | February 4, 2021 |
| Target type | Other |
| Loss | $11,000,000Published estimates range $11,000,000 to $11,100,000Price at time of incident |
| Method | Oracle or price manipulationThe v1 yDAI vault routed deposits into Curve's 3pool through a permissionless earn() function and realised value at whatever exchange rate that pool offered at the moment of the trade. Using borrowed capital, including an Aave flash loan, the attacker pushed the 3pool far out of balance, forced the vault to deposit at the distorted rate, restored the balance, then withdrew at the corrected rate and kept the difference. Three configuration choices made it profitable: a 1% slippage tolerance, a withdrawal fee set to 0%, and an earn() function anyone could call. Halborn's analysis characterises this as slippage extraction against an imbalanced pool rather than a corrupted price-feed read. |
| Chains | Ethereum |
| Outcome | Users reimbursed |
What happened
Yearn Finance's v1 yDAI vault was drained on 4 February 2021. Yearn's own disclosure states that 11 million DAI of vault deposits were lost out of the vault's 35 million DAI, and estimates the exploiter's profit at 2.7 million DAI. Yearn developer banteg gave slightly different numbers publicly on the day, saying the vault lost 11.1 million and the attacker got away with 2.8 million. The gap between the vault's loss and the attacker's gain was absorbed as slippage by liquidity providers in the Curve pool used to carry out the attack, so the two figures measure different things and both are recorded here.
The vault deposited DAI into Curve's 3pool and took its pricing from that pool. Using borrowed capital, including an Aave flash loan, the attacker first pushed the 3pool badly out of balance. Yearn's timeline records deposits of 134 million USDC and 36 million DAI against a withdrawal of 165 million USDT. The vault was then made to deposit at the distorted rate, the pool was rebalanced, and the position withdrawn at the corrected rate. The cycle ran across a series of eleven transactions over roughly 38 minutes. Three configuration choices made it profitable: a 1% slippage tolerance, no withdrawal fee, and an earn() function anyone could call.
Yearn's security team spotted the pattern at 21:45 UTC, set the DAI vault's minimum reserve to zero by 21:56 and did the same for the USDC, USDT and TUSD vaults by 22:07, protecting about 24 million DAI. Tether said it froze $1.7 million of USDT linked to the attack. Yearn subsequently opened a Maker vault against treasury YFI to mint 9.7 million DAI and restore the vault, making depositors whole. No attacker has been publicly identified.
Sources
- Yearn Finance (yearn-security disclosures)Primary · retrieved 2026-08-01
- CoinDeskSecondary · retrieved 2026-08-01
- HalbornSecondary · retrieved 2026-08-01
- ForkLogSecondary · retrieved 2026-08-01
Official post-mortem: https://github.com/yearn/yearn-security/blob/master/disclosures/2021-02-04.md
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Yearn Finance hack — February 2021", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/yearn-financehttps://itokenly.com/hacks/yearn-financePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.