CryptoReal
CASE FILE — Apr 13, 2023

A Three-Year-Old Copy-Paste Error Drains $10M+ From Yearn's Legacy yUSDT Vault

More than two years after its first appearance on the leaderboard, Yearn Finance is back in the headlines, this time after losing more than $10 million.

Yearn has long been regarded as one of the more dependable, battle-tested names in DeFi, having built its reputation on offering some of the sector's most straightforward yield-farming products. That reputation took a hit when attackers found a way into the protocol's original yUSDT contract — a piece of code that had been sitting untouched on Ethereum since it was deployed more than three years earlier, back when Yearn still operated under Andre Cronje's original branding, iearn finance.

Although Yearn's strategies have since moved on to newer contract versions, the old yUSDT contract still held meaningful funds. Yearn has since confirmed that its current, actively used vault contracts were not affected by the exploit.

Notably, a warning about the vulnerability surfaced on Twitter shortly before the attack — but because the contract in question is immutable, there was no way to patch it in time. Yearn team member storming0x confirmed the attack was underway, after which the project's official account reassured users that the rest of the protocol remained secure.

In total, the flaw sat undetected for 1,156 days inside one of DeFi's oldest and most established protocols before anyone caught it — raising obvious questions about how a bug of this scale could go unnoticed for so long.

Analysis of the exploit was credited to Samczsun, OtterSec, and SlowMist.

At the root of the incident was a misconfiguration inside the original iearn yUSDT token contract. The token was designed to generate yield from a basket of underlying yield-bearing positions, spanning USDT deposits across Aave, Compound, dYdX, and Fulcrum (bZx). The problem: since the contract's launch, it had pointed to the wrong address — the Fulcrum USDC contract instead of the intended Fulcrum USDT contract, apparently the result of a copy-paste mistake.

By exploiting that mismatch, the attacker was able to dramatically distort yUSDT's internal share-price calculation, allowing them to mint roughly 1.2 quadrillion yUSDT using only 10,000 USDT as input. A detailed, step-by-step breakdown of the mechanics was published by Theori researcher junomon.eth on Twitter.

Three addresses have been tied to the exploit:

Sums referenced in this case file

Two attack transactions have been identified:

The fraudulently minted yUSDT was subsequently converted into other stablecoins, with total proceeds reaching $11.4 million, according to a breakdown published by BlockSec.

The attacker's initial funding for the operation was traced to Tornado Cash via this transaction, and 1,000 ETH was later sent back through the mixer as part of the laundering process. As of the time the incident was documented, the first two exploiter addresses each held roughly $1.5 million in assets, while the third address held 7.4 million DAI.

It's also worth noting that Certik had performed an audit of iearn finance back in February 2020 — but that review appears to have covered only the yDAI contract, not the yUSDT contract that was ultimately exploited.

Cronje's well-known "test in production" philosophy has generated no shortage of security incidents over the years, many of which supplied early material for rekt.news coverage. Typically, though, issues with new protocols or features surfaced within hours or days of launch — not years later, as happened here.

Each of those earlier incidents contributed to what's been described as a growing decentralised monopoly around the Cronje ecosystem, which has racked up enough hacks over time to warrant its own running tally — a pattern also seen when CREAM Finance was hacked for a second time in October 2021.

Even with a loss north of $10 million, the damage was contained to a deprecated, legacy strategy, leaving the roughly $450 million in TVL held across Yearn's current strategies untouched.

As noted after Yearn's first appearance on this list: no protocol is too big to fail. First it was Sushi; now it's Yearn's turn again — making for a rough week for two of DeFi's most established names.

Yearn
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.