Yearn Finance's yETH pool hit by cyberattack
Incident
Summary
Hide ▲
Show ▼
Yearn Finance's yETH pool on Ethereum suffered an asset-drain exploit that removed about $9m from the pool. The attacker abused a flaw in the pool's internal accounting to mint 235 septillion yETH from only 16 wei. Repeated flash-loan-assisted deposit and withdrawal cycles desynchronized cached balances and set up the final mint. The stolen assets were then swapped through DEXs and partly routed through Tornado Cash, complicating tracing and recovery.
Related Happenings
Uranium Finance smart contract flaws actively exploited security flaw
Vulnerability
First: 31.03.2026 18:30
Last: 31.03.2026 18:30
Sources 1
About this happening:
In **April 2021**, **Uranium Finance** smart contract flaws were **actively exploited** to drain funds from liquidity pools, including a **rewards calculation** weakness and a **t...
Uranium Finance smart contract flaws actively exploited security flaw
VulnerabilityAbout this happening: In **April 2021**, **Uranium Finance** smart contract flaws were **actively exploited** to drain funds from liquidity pools, including a **rewards calculation** weakness and a **t...
Uranium Finance hit by network compromise
Incident
First: 31.03.2026 12:15
Last: 31.03.2026 12:15
Sources 1
About this happening:
**Uranium Finance** suffered a **two-stage smart-contract hack** in **April 2021** that drained about **$53.3 million** and forced the exchange to shut down. The attacks exploited...
Uranium Finance hit by network compromise
IncidentAbout this happening: **Uranium Finance** suffered a **two-stage smart-contract hack** in **April 2021** that drained about **$53.3 million** and forced the exchange to shut down. The attacks exploited...
Jonathan Spalletta Cthulhon Jspalletta indicted in Jonathan Spalletta / Uranium Finance hack and laundering case
Law Enforcement
First: 31.03.2026 12:15
Last: 31.03.2026 12:15
Sources 1
About this happening:
**U.S. prosecutors** charged **Jonathan Spalletta** in a **federal cybercrime** case tied to the **Uranium Finance** hack, alleging more than **$53 million** in stolen crypto was...
Jonathan Spalletta Cthulhon Jspalletta indicted in Jonathan Spalletta / Uranium Finance hack and laundering case
Law EnforcementAbout this happening: **U.S. prosecutors** charged **Jonathan Spalletta** in a **federal cybercrime** case tied to the **Uranium Finance** hack, alleging more than **$53 million** in stolen crypto was...
Timeline
-
03.12.2025 17:30 2 articles · 5mo ago
Yearn Finance yETH pool exploit disclosed
Initial DisclosureCheck Point Research disclosed that a vulnerability in Yearn Finance's yETH pool on Ethereum let an attacker drain about $9m, mint 235 septillion yETH tokens from 16 wei, swap the stolen LSD assets through DEXs, and route part of the proceeds through Tornado Cash.
Show sources
- Yearn Finance yETH Pool Hit by $9M Exploit — www.infosecurity-magazine.com — 03.12.2025 17:30
- Yearn Finance yETH Pool Hit by $9M Exploit — www.infosecurity-magazine.com — 03.12.2025 17:30