T
iTokenly

yieldcore-3rd-deal vault (Ethereum) hack — April 2026

Verified — 4 sourcesLast checked October 6, 2026

Incident facts

Date of incident
Publicly disclosedApril 29, 2026
Target typeOther
Loss$398,655Price at time of incident
MethodAccess control flawThe vault overrode the ERC-4626 withdraw function without checking that a caller withdrawing someone else's shares had an allowance, so the attacker withdrew eight depositors' balances to itself
ChainsEthereum
OutcomeUnresolved

What happened

A USDC vault on Ethereum named yieldcore-3rd-deal lost 398,655 USDC on 28 April 2026, in a transaction at 15:00:11 UTC. Its operator has not been clearly identified. An on-chain message sent to the attacker the next day, relayed by Defimon Alerts, was signed "the YieldCore team" and called it "our yieldcore-3rd-deal vault". YieldCore.App, a bond protocol on BNB Chain, has said the vault has nothing to do with it, and DefiLlama renamed the incident accordingly in September.

According to DeFiHackLabs, the vault contract, RWAVault, overrode the standard ERC-4626 withdraw function and dropped the check that a caller withdrawing someone else's shares has been given an allowance. The attacker withdrew the balances of eight depositors to an address it controlled.

This registry read the receipt: the vault paid out 398,655.47 USDC and the attacker's address received 387,764 USDC. The vault's loss is recorded, with the attacker's net as the lower end. No recovery has been reported.

Sources

  1. Defimon Alerts on TelegramSecondary · retrieved 2026-10-06
  2. DefiLlama correction request by YieldCore.AppSecondary · retrieved 2026-10-06
  3. DeFiHackLabs exploit reconstructionSecondary · retrieved 2026-10-06
  4. Ethereum transaction receipt, read by this registryOn-chain · retrieved 2026-10-06

Changes to this entry

  • Recorded on 6 October 2026 in a backfill of 2026 incidents that this registry had missed, found through DeFiHackLabs' reproduction list. The amount was checked against the transaction receipt, read by this registry from a public node.

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "yieldcore-3rd-deal vault (Ethereum) hack — April 2026", iTokenly, accessed 2026-10-06, https://itokenly.com/hacks/yieldcore-3rd-deal-vault
https://itokenly.com/hacks/yieldcore-3rd-deal-vault

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.