T
iTokenly

Yearn Finance (yETH pool) hack — November 2025

Verified — 3 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedNovember 30, 2025
Target typeOther
Loss$9,000,000Price at time of incident
Recovered$2,400,000
MethodContract logic errorImbalanced add_liquidity deposits drove the yETH weighted-stableswap pool's iterative fixed-point solver into a divergent state until an internal product term collapsed to zero, breaking the invariant. An unchecked subtraction then underflowed, allowing an effectively unlimited mint of yETH LP tokens against a deposit of 16 wei.
ChainsEthereum
Audited beforehandYes
OutcomePartially recovered

What happened

Yearn Finance's yETH pool, a weighted stableswap holding a basket of liquid staking tokens including apxETH, sfrxETH and wstETH, was exploited on 30 November 2025 at Ethereum block 23,914,086. About $9 million in liquid staking tokens and WETH left a pool that had held roughly $11 million. Yearn said its v2 and v3 vaults, with more than $410 million in deposits, were unaffected and that the damage was confined to yETH and its Curve integration.

The bug was arithmetic. According to Yearn's post-mortem, a sequence of imbalanced add_liquidity deposits pushed the pool's iterative fixed-point solver into a divergent state until an internal product term collapsed to zero. That broke the weighted-stableswap invariant, and an unchecked subtraction then underflowed, letting the attacker mint an enormous quantity of yETH LP tokens against a deposit of 16 wei spread across the pool's eight supported assets. Check Point Research describes the same outcome from a different angle: cached virtual-balance values held in packed storage were never cleared when liquidity was fully withdrawn, so a later deposit into a pool reading zero supply was priced against stale phantom balances.

The attacker swapped the minted tokens for wrapped ether, repaid flash loans and routed roughly $3 million in ETH through Tornado Cash. Yearn convened a war room with SEAL 911 and, working with the Plume and Dinero teams, clawed back 857.49 pxETH on 1 December, worth about $2.4 million, which it said would go pro rata to yETH depositors based on balances immediately before the exploit. Yearn stated that contributors are not liable for reimbursement under the product's use-at-own-risk terms. ChainSecurity assisted with root-cause analysis. No attacker has been identified.

Sources

  1. The BlockSecondary · retrieved 2026-08-01
  2. Check Point ResearchSecondary · retrieved 2026-08-01
  3. DL NewsSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Yearn Finance (yETH pool) hack — November 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/yearn-yeth
https://itokenly.com/hacks/yearn-yeth

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.