Find notable cyber news and cases, enriched with sources, timelines, and signals.

Yearn Finance's yETH pool hit by cyberattack

Incident
First reported
Last updated
Happening score
H score 27
1 unique sources, 1 articles

Summary

Hide ▲

Yearn Finance's yETH pool on Ethereum suffered an asset-drain exploit that removed about $9m from the pool. The attacker abused a flaw in the pool's internal accounting to mint 235 septillion yETH from only 16 wei. Repeated flash-loan-assisted deposit and withdrawal cycles desynchronized cached balances and set up the final mint. The stolen assets were then swapped through DEXs and partly routed through Tornado Cash, complicating tracing and recovery.

Related Happenings

Uranium Finance smart contract flaws actively exploited security flaw

Vulnerability
First: 31.03.2026 18:30 Last: 31.03.2026 18:30 Sources 1

About this happening: In **April 2021**, **Uranium Finance** smart contract flaws were **actively exploited** to drain funds from liquidity pools, including a **rewards calculation** weakness and a **t...

Uranium Finance hit by network compromise

Incident
First: 31.03.2026 12:15 Last: 31.03.2026 12:15 Sources 1

About this happening: **Uranium Finance** suffered a **two-stage smart-contract hack** in **April 2021** that drained about **$53.3 million** and forced the exchange to shut down. The attacks exploited...

Jonathan Spalletta Cthulhon Jspalletta indicted in Jonathan Spalletta / Uranium Finance hack and laundering case

Law Enforcement
First: 31.03.2026 12:15 Last: 31.03.2026 12:15 Sources 1

About this happening: **U.S. prosecutors** charged **Jonathan Spalletta** in a **federal cybercrime** case tied to the **Uranium Finance** hack, alleging more than **$53 million** in stolen crypto was...

Timeline

  1. 03.12.2025 17:30 2 articles · 5mo ago

    Yearn Finance yETH pool exploit disclosed

    Initial Disclosure

    Check Point Research disclosed that a vulnerability in Yearn Finance's yETH pool on Ethereum let an attacker drain about $9m, mint 235 septillion yETH tokens from 16 wei, swap the stolen LSD assets through DEXs, and route part of the proceeds through Tornado Cash.

    Show sources