Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Sam Bankman-Fried had a plan to get out of prison, and he’s following it

    March 15, 2026

    ZK Grants Round Announcement | Ethereum Foundation Blog

    March 15, 2026

    Zerebro founder Jeffy Yu has allegedly killed himself again

    March 15, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram LinkedIn
    Ai Crypto TimesAi Crypto Times
    • Altcoins
      • Coinbase
      • Litecoin
      • Bitcoin
    • Ethereum
    • Crypto
    • Blockchain
    • Lithosphere News Releases
    Ai Crypto TimesAi Crypto Times
    Home » Yearn Finance hit by fourth exploit as attacker drains legacy v1 vault
    Crypto

    Yearn Finance hit by fourth exploit as attacker drains legacy v1 vault

    James WilsonBy James WilsonDecember 17, 2025No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email



    Yearn Finance suffers its fourth exploit as a flash loan attack drains a legacy v1 vault, underscoring ongoing risks from outdated DeFi contracts and price manipulation tactics.​

    Summary

    • PeckShield reports an attacker used flash loans to manipulate prices in a deprecated Yearn v1 (iearn) vault, withdraw assets and convert them into another token.​
    • The hit follows a separate $9 million yETH exploit earlier this month and prior hacks in 2023 and 2021, despite multiple audits on the protocol’s contracts.​
    • Yearn says it is reviewing active contracts, boosting security checks and warning users to be cautious with older v1 vaults as flash loan attacks keep targeting legacy DeFi code.

    Yearn Finance, a decentralized finance protocol, has experienced its fourth security exploit in recent weeks, according to blockchain security firm PeckShield.

    The latest attack targeted a legacy Yearn v1 smart contract, formerly known as iearn, resulting in reported losses, the company stated. The incident follows a previous exploit reported in November.

    Yearn finance unveils attacker flash loan strategy

    The attacker utilized a flash loan to manipulate token prices within the affected vault, according to PeckShield’s analysis. The perpetrator withdrew iearn assets and converted them into another cryptocurrency, the security firm reported. The compromised contract is part of Yearn v1 and has not received updates for several years, according to protocol documentation.

    Flash loans enable borrowers to obtain large amounts of cryptocurrency without collateral, allowing attackers to manipulate prices and withdraw assets rapidly, according to blockchain security experts.

    Yearn Finance has experienced four security breaches in recent years. In November, the protocol suffered an infinite mint exploit, according to reports. In 2023, Yearn experienced another hack and a separate incident connected to Euler Finance, industry sources stated. In 2021, a similar exploit resulted in significant losses, according to protocol records.

    Each attack has employed complex methods including flash loans and price manipulation, according to security analyses. Security audits have been performed on the protocol, though legacy contracts remain exposed to potential vulnerabilities, according to blockchain security firms.

    Yearn Finance is reviewing all active contracts for weaknesses, the protocol announced. PeckShield and other blockchain monitoring services tracked the exploit immediately and urged users to verify balances and secure potentially vulnerable funds.

    The protocol team has not provided public details regarding recovery plans. Yearn Finance continues examining remaining v1 contracts for vulnerabilities and has recommended caution when interacting with older vaults, according to a protocol statement.

    Security audits and checks are being increased to prevent further losses, the company stated. Flash loan attacks continue to present risks for legacy decentralized finance protocols, according to industry security assessments.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    James Wilson

    Related Posts

    Bittensor (TAO) Just Surged 31% in 7 Days — Is the AI Crypto Supercycle Actually Here?

    March 15, 2026

    How to Run a Bitcoin Lightning Node in 5 Minutes?

    March 15, 2026

    Token2049 delay, Ethereum Foundation mandate

    March 15, 2026
    Leave A Reply Cancel Reply

    Our Picks
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Don't Miss

    Sam Bankman-Fried had a plan to get out of prison, and he’s following it

    Coinbase March 15, 2026

    Sam Bankman-Fried was brainstorming about media stunts that might get him out of prison. He’s…

    ZK Grants Round Announcement | Ethereum Foundation Blog

    March 15, 2026

    Zerebro founder Jeffy Yu has allegedly killed himself again

    March 15, 2026

    blog.ethereum.org mailing list incident | Ethereum Foundation Blog

    March 15, 2026

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    X (Twitter) Instagram YouTube LinkedIn
    Our Picks

    Everdawn labs’ Omnichain stablecoin USDT0 tops $50b in transfers

    November 28, 2025

    Introducing the Devcon Archive (and an event update)

    November 20, 2025

    Tether’s Q3 attestations prove that it can’t quit secured loans

    November 26, 2025
    Recent Posts

    Sam Bankman-Fried had a plan to get out of prison, and he’s following it

    March 15, 2026

    ZK Grants Round Announcement | Ethereum Foundation Blog

    March 15, 2026

    Zerebro founder Jeffy Yu has allegedly killed himself again

    March 15, 2026

    Type above and press Enter to search. Press Esc to cancel.