T
iTokenly

Yearn Finance (yUSDT) hack — April 2023

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedApril 13, 2023
Target typeOther
Loss$11,540,000Published estimates range $10,000,000 to $11,600,000Price at time of incident
MethodContract logic errorLegacy iEarn yUSDT vault was deployed referencing Fulcrum's iUSDC token instead of iUSDT, breaking share-price accounting; flash loans were used to inflate then collapse the share price and mint over a quadrillion yUSDT
ChainsEthereum
Audited beforehandCertiK audited a related iEarn contract; CertiK states the yUSDT misconfiguration fell outside that audit's scope as an operational deployment error
OutcomeUnresolved

What happened

On 13 April 2023 an attacker exploited yUSDT, a token from Yearn's original 2020 iEarn product, which had been misconfigured since deployment: the contract referenced Fulcrum's iUSDC token where it should have referenced iUSDT. Researchers noted the token had been broken since deploy, roughly 1,000 days earlier.

Because the vault's accounting rested on the wrong underlying asset, its share price could be manipulated. QuillAudits' analysis describes the attacker taking flash loans of 5 million DAI, 5 million USDC and 2 million USDT, depositing into the yUSDT contract, minting bZx tokens and forcing a rebalance to inflate and then collapse the share price, after which a deposit of one wei of USDT minted over a quadrillion yUSDT. PeckShield put the minted amount above 1.2 quadrillion. Those tokens were swapped out through Curve pools and Aave v1 for DAI, USDT, USDC, BUSD and TUSD.

Reported totals vary widely and no single figure is authoritative. CertiK put the loss at about $10 million; CoinDesk, working from PeckShield's early alert, reported over $11 million; QuillAudits calculated about $11.54 million; Decrypt reported $11.6 million. The losses fell on liquidity providers in the affected pools rather than on current Yearn users: Yearn v2 vaults were unaffected, and PeckShield stated the root cause was misconfigured yUSDT and not related to Aave. Aave's v1 deployment had been frozen since December 2022 and served only as a venue for swapping tokens; Aave's founder confirmed no direct impact.

CertiK, which had audited a related iEarn contract (yDAIv2.sol) in March 2020, said the misconfiguration fell outside that audit's scope because it was an operational deployment error rather than a code defect. The funds were not recovered.

Sources

  1. CoinDeskSecondary · retrieved 2026-08-01
  2. DecryptSecondary · retrieved 2026-08-01
  3. QuillAuditsSecondary · retrieved 2026-08-01
  4. CertiKSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Yearn Finance (yUSDT) hack — April 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/yearn-finance-yusdt
https://itokenly.com/hacks/yearn-finance-yusdt

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.