Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Hackers Exploit Critical Yearn Finance’s yETH Pool Vulnerability to Steal $9 Million in Ethereum

On November 30, 2025, Yearn Finance's yETH pool experienced a significant security breach, resulting in the unauthorized extraction of approximately $9 million.

On November 30, 2025, Yearn Finance's yETH pool experienced a significant security breach, resulting in the unauthorized extraction of approximately $9 million.

The attacker executed a sophisticated exploit that involved minting an enormous quantity of 235 septillion yETH tokens by depositing just 16 wei. This action underscores vulnerabilities in complex smart contract systems, particularly in relation to mathematical invariants and gas optimization strategies.

The core issue was identified within the protocol's internal accounting mechanism, specifically through the use of cached storage variables known as packed_vbs . These variables, intended to reduce transaction costs by storing virtual balance information, failed to reset properly when the pool's liquidity supply dropped to zero.

While the main supply counter reset, the cached values mistakenly retained balances from previous transactions, leading to a critical discrepancy between the actual and recorded state of the pool.

Check Point security analysts identified the flaw as a logic error in state management, rather than a simple coding mistake. By manipulating the interaction between deposit and withdrawal functions, the attacker misled the system into recognizing a substantial pool value, even though it was effectively empty.

The attacker executed a sophisticated exploit that involved minting an enormous quantity of 235 septillion yETH tokens by depositing just 16 wei.
Natalie Rhodes · Thehackingpost

The attack, noted for its capital efficiency, required minimal upfront investment to extract millions in Ethereum-based assets.

The attack was executed through a process of state poisoning, exploiting the protocol's failure to clear its cache. The perpetrator conducted multiple cycles of deposits and withdrawals using flash-loaned funds, leaving small residual values in the packed_vbs storage slots.

This repetitive action poisoned the storage with accumulated data that persisted even after the attacker withdrew all legitimate liquidity, reducing the pool's total supply to zero.

Critically, the protocol’s add_liquidity function contained a flawed assumption: a zero supply was presumed to indicate a pristine, empty pool. Consequently, when the attacker deposited their final 16 wei, the system read the stale, non-zero values from the poisoned cache instead of recalculating based on the new deposit.

Advertisement

This misjudgment triggered the minting of septillions of LP tokens, granting the attacker control over the pool's assets, which were then exchanged for WETH and laundered via Tornado Cash.

This incident highlights the necessity for explicit state management in complex DeFi systems to prevent similar high-value exploits.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories