A legacy version of the decentralized finance protocol Yearn has suffered an exploit, reviving concerns about misconfigured and immutable smart contracts that haveA legacy version of the decentralized finance protocol Yearn has suffered an exploit, reviving concerns about misconfigured and immutable smart contracts that have

YearnFinanceV1 suffers $300,000 exploit to legacy TUSD vault

A legacy version of the decentralized finance protocol Yearn has suffered an exploit, reviving concerns about misconfigured and immutable smart contracts that have held funds on the network years after being deprecated.

In an X post on Wednesday, Security firm PeckShield reported YearnFinanceV1’s hack resulted in losses of about $300,000. The stolen funds were swapped into 103 Ether and now sit at address 0x0F21…4066, according to Etherscan images shared by the firm.

The hackers took advantage of an outdated Yearn vault tied to TrueUSD, known as the “iearn TUSD vault,” which is still deployed on Ether despite being superseded by newer versions. A configuration flaw helped the attackers manipulate share prices through several transactions.

Yearn Finance misconfigured vault triggered price manipulation 

According to an analysis from pseudonymous crypto researcher and University of Science and Technology of China alumnus Weilin Li, the vault configured one of its strategies as a Fulcrum sUSD vault and calculated its share price using only the sUSD balance deposited.

This opened the door to so-called “donation attacks,” in which an attacker transfers assets directly into a vault to distort accounting metrics. After sending Fulcrum sUSD tokens into the Yearn TUSD vault, the perpetrators were able to artificially inflate the vault’s reported share price.

The issue was compounded by a rebalance function that withdraws all underlying assets in sUSD, an asset not included in the vault’s share price calculations. When the rebalance started, the vault’s share price tanked steeply and created a “price shock.”

Per PeckShield Alert’s Etherscan snapshot, the attacker executed sequenced flash loans by firstly borrowing large amounts of TUSD and sUSD without an upfront collateral. They then deposited sUSD to mint Fulcrum sUSD tokens before depositing TUSD into the Yearn TUSD vault. 

At that stage, all underlying assets of the TUSD vault consisted of Fulcrum sUSD tokens. The exploiter withdrew from the Yearn TUSD vault and called the rebalance function, forcing Fulcrum to redeem everything into sUSD. Because sUSD was excluded from share price calculations, the vault’s accounting collapsed, effectively driving the share price toward zero.

The attacker then transferred a small amount of TUSD back into the vault, pushing the share price to extremely low levels, and minted an outsized number of Yearn TUSD tokens at minimal cost. He ultimately counted gains by selling the cheaply acquired Yearn TUSD tokens on Curve pools, extracting value from liquidity providers before repaying the flash loans.

Yearn Finance recaps 2023 vulnerability, researcher recounts

Researcher Li found that the exploit was similar to an attack carried out in 2023, leading to losses exceeding $10 million. The immutable yUSDT contract targeted in that earlier incident was deployed more than three years ago, during the early days of iearn when the late Andre Cronje led the protocol.

Pessimistic security analysts had issued a warning about the vulnerability on social media before the exploit, but since immutable smart contracts cannot be patched or paused once deployed, it was inevitable.

 “iearn finance, Smoothswap, be careful. This address 0x5bac20…ed8e9cdfe0 got 10 ETH from Tornado and deploys contracts with flashloans using your addresses,” PS’ Nikiti Kirillov wrote.

A Yearn team member known as storming0x admitted the attack happened and reassured users that its current contracts were safe. Yet, Rekt News observers revealed it took 1,156 days for the DeFi protocol to spot a multimillion-dollar vulnerability.

Yearn yUSDT token contract generated yield from a basket of yield-bearing positions, including USDT deposits on Aave, Compound, dYdX and BzX’s Fulcrum. Since launch, however, yUSDT contained a copy-and-paste error which referenced the Fulcrum USDC address instead of the Fulcrum USDT contract. 

Using just 10,000 USDT, hackers were able to mint approximately 1.2 quadrillion yUSDT, draining value from the system before cashing out.

The Yearn incident comes less than a week after Cryptopolitan featured a $2.7 million drainage from an old contract belonging to Ribbon Finance, the rebranded version of Aevo. That attack involved repeated interactions with a proxy admin contract at address 0x9D7b…8ae6B76. The attacker invoked functions such as transferOwnership and setImplementation to manipulate price-feed proxies through delegate calls.

Get seen where it counts. Advertise in Cryptopolitan Research and reach crypto’s sharpest investors and builders.

Market Opportunity
TrueUSD Logo
TrueUSD Price(TUSD)
$0,9996
$0,9996$0,9996
-0,01%
USD
TrueUSD (TUSD) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

VIRTUAL Weekly Analysis Jan 21

VIRTUAL Weekly Analysis Jan 21

The post VIRTUAL Weekly Analysis Jan 21 appeared on BitcoinEthereumNews.com. VIRTUAL closed the week up 3.57% at $0.84, but the long-term downtrend maintains its
Share
BitcoinEthereumNews2026/01/22 06:54
MetaMask Token: Exciting Launch Could Be Sooner Than Expected

MetaMask Token: Exciting Launch Could Be Sooner Than Expected

BitcoinWorld MetaMask Token: Exciting Launch Could Be Sooner Than Expected The cryptocurrency community is buzzing with exciting news: a native MetaMask token might arrive sooner than many anticipated. This development could reshape how users interact with the popular Web3 wallet and the broader decentralized ecosystem. It signals a significant step forward for one of the most widely used tools in the blockchain space. What’s Fueling the MetaMask Token Buzz? Joseph Lubin, the CEO of ConsenSys, the company behind MetaMask, recently shared insights that ignited this excitement. According to reports from The Block, Lubin indicated that a MetaMask token could launch ahead of previous expectations. This isn’t the first time the idea has surfaced; Dan Finlay, one of MetaMask’s founders, had previously mentioned the possibility of issuing such a token. ConsenSys has been a pivotal player in the Ethereum ecosystem, developing essential infrastructure and applications. MetaMask, their flagship wallet, serves millions of users, providing a gateway to decentralized applications (dApps), NFTs, and various blockchain networks. Therefore, any move to introduce a native token is a major event for the entire Web3 community. Why is a MetaMask Token So Anticipated? The prospect of a MetaMask token generates immense interest because it could introduce new layers of utility and community governance. Users often speculate about the benefits such a token could offer. Here are some key reasons for the high anticipation: Governance Rights: A token could empower users to participate in the future direction and development of MetaMask. This means voting on new features, upgrades, or even changes to the platform’s policies. Ecosystem Rewards: Tokens might be distributed as rewards for active participation, using certain features, or contributing to the MetaMask community. This incentivizes engagement and loyalty. Enhanced Utility: The token could unlock premium features, reduce transaction fees, or provide exclusive access to services within the MetaMask ecosystem or partnered dApps. Decentralization: Introducing a token often aligns with the broader Web3 ethos of decentralization, distributing control and ownership among its users rather than centralizing it within ConsenSys. Consequently, a token launch is seen as a way to deepen user involvement and foster a more robust, community-driven ecosystem around the wallet. Exploring the Potential Impact of a MetaMask Token The introduction of a MetaMask token could have far-reaching implications for the decentralized finance (DeFi) and Web3 landscape. Firstly, it could set a new standard for how popular infrastructure tools engage with their user base. By providing a tangible stake, MetaMask might strengthen its position as a community-governed platform. Moreover, a token could significantly boost the wallet’s visibility and adoption, attracting new users eager to participate in its governance or benefit from its utility. This could also lead to innovative integrations with other blockchain projects, creating a more interconnected and efficient Web3 experience. Ultimately, the success of such a token will depend on its design, utility, and how effectively it engages the global MetaMask community. What Challenges Could a MetaMask Token Face? While the excitement is palpable, launching a MetaMask token also presents several challenges that ConsenSys must navigate carefully. One primary concern is regulatory scrutiny. The classification of cryptocurrency tokens varies across jurisdictions, and ensuring compliance is crucial for long-term success. Furthermore, designing a fair and equitable distribution model is paramount. Ensuring that the token provides genuine utility beyond mere speculation will be another hurdle. A token must integrate seamlessly into the MetaMask experience and offer clear value to its holders. Additionally, managing community expectations and preventing market manipulation will require robust strategies. Addressing these challenges effectively will be key to the token’s sustainable growth and positive reception. What’s Next for the MetaMask Ecosystem? The prospect of a MetaMask token signals an evolving strategy for ConsenSys and the future of Web3 wallets. It reflects a growing trend where foundational tools seek to empower their communities through tokenization. Users are keenly watching for official announcements regarding the token’s mechanics, distribution, and launch timeline. This development could solidify MetaMask’s role not just as a wallet, but as a central pillar of decentralized identity and interaction. The potential for a sooner-than-expected launch adds an element of urgency and excitement, encouraging users to stay informed about every new detail. It represents a significant milestone for a platform that has become synonymous with accessing the decentralized web. Conclusion The hints from ConsenSys CEO Joseph Lubin regarding an earlier launch for the MetaMask token have undoubtedly captured the attention of the entire crypto world. This potential development promises to bring enhanced governance, utility, and community engagement to millions of MetaMask users. While challenges exist, the underlying potential for a more decentralized and user-driven ecosystem is immense. The coming months will likely reveal more about this highly anticipated token, marking a new chapter for one of Web3’s most vital tools. Frequently Asked Questions (FAQs) Q1: What is a MetaMask token? A MetaMask token would be a native cryptocurrency issued by ConsenSys, the company behind the MetaMask wallet. It is expected to offer various utilities, including governance rights, rewards, and access to special features within the MetaMask ecosystem. Q2: Why is ConsenSys considering launching a MetaMask token? ConsenSys is likely exploring a token launch to further decentralize the MetaMask platform, empower its user community with governance rights, incentivize active participation, and potentially unlock new forms of utility and growth for the ecosystem. Q3: What benefits could users gain from a MetaMask token? Users could gain several benefits, such as the ability to vote on MetaMask’s future developments, earn rewards for using the wallet, access exclusive features, or potentially reduce transaction fees. It also provides a direct stake in the platform’s success. Q4: When is the MetaMask token expected to launch? While no official launch date has been confirmed, ConsenSys CEO Joseph Lubin has indicated that the launch could happen sooner than previously expected. The exact timeline remains subject to official announcements from ConsenSys. Q5: How would a MetaMask token impact the broader Web3 ecosystem? A MetaMask token could significantly impact Web3 by setting a precedent for user-owned and governed infrastructure tools. It could drive further decentralization, foster innovation, and strengthen the connection between users and the platforms they rely on, ultimately contributing to a more robust and participatory decentralized internet. To learn more about the latest crypto market trends, explore our article on key developments shaping Ethereum institutional adoption. This post MetaMask Token: Exciting Launch Could Be Sooner Than Expected first appeared on BitcoinWorld.
Share
Coinstats2025/09/19 15:40
Former Pantera partner launches $300 million SOL vault Solmate in UAE

Former Pantera partner launches $300 million SOL vault Solmate in UAE

PANews reported on September 18 that according to AggrNews, a former Pantera partner leads Solmate in the UAE and manages the $300 million Solana digital asset treasury (DAT).
Share
PANews2025/09/18 21:22