Tricky Profit
  • Stock
  • Economy
  • Politics
  • Editor’s Pick
Editor's Pick

Yearn Finance losses $300K in a TUSD vault exploit

by December 18, 2025
by December 18, 2025 0 comment

Yearn Finance, one of the leading decentralised finance (DeFi) protocols, has suffered a significant setback as its legacy TUSD vault fell victim to a sophisticated exploit.

According to security firm PeckShield, attackers managed to extract approximately $300,000, converting the stolen assets into 103 Ether now held at the address 0x0F21…4066.

PeckShieldAlert

@PeckShieldAlert

·Follow

#PeckShieldAlert YearnFinanceV1 @yearnfi has suffered an exploit, resulting in a total loss of ~$300K.
The exploiter has swapped the stolen funds for 103
$ETH, which now sit in the address: 0x0F21…4066.

3:00 am · 17 Dec 2025

216

Reply

Read 22 replies

Notably, the incident has reignited concerns about the vulnerabilities of outdated and immutable smart contracts that remain active on Ethereum years after their deployment.

Misconfigured TUSD vault

According to analysis by William Li, the breach targeted a legacy Yearn TUSD vault, known as the “iearn TUSD vault,” which had long been superseded by newer iterations.

Researchers identified a misconfiguration in the vault’s strategy setup, which used a Fulcrum sUSD vault for calculations while considering only sUSD balances deposited into the vault.

This flawed design created a pathway for a so-called “donation attack,” allowing the perpetrators to artificially manipulate the vault’s share price.

The attackers leveraged this weakness with a series of flash loans, borrowing significant amounts of TUSD and sUSD without any upfront collateral.

They deposited sUSD to mint Fulcrum sUSD tokens before placing TUSD into the vault.

Because the vault’s share price ignored sUSD assets, the subsequent rebalance function, which withdrew all underlying sUSD, caused the vault’s accounting metrics to collapse.

This artificial “price shock” allowed the attackers to mint vast quantities of Yearn TUSD tokens at minimal cost and ultimately sell them on Curve pools, extracting value from liquidity providers before repaying the flash loans.

A pattern of legacy vulnerabilities

Security analysts have noted that this exploit mirrors a similar attack in 2023, when a misconfigured yUSDT contract resulted in losses exceeding $10 million.

That incident stemmed from a copy-and-paste error referencing the wrong Fulcrum contract, allowing hackers to mint unprecedented amounts of yUSDT from small initial deposits.

Despite warnings from pessimistic observers on social media, the immutable nature of smart contracts rendered such vulnerabilities unavoidable once deployed.

The Yearn TUSD vault exploit adds to a growing list of attacks targeting old, unmaintained DeFi contracts.

A comparable incident recently hit Ribbon Finance, formerly known as Aevo, where an outdated deployment allowed attackers to manipulate proxy admin contracts and drain $2.7 million.

Both events highlight the ongoing risks associated with legacy protocols that continue to hold significant funds on-chain long after they have been deprecated.

Yearn Finance’s response

In response to the incident, a Yearn team member under the handle storming0x confirmed that the current contracts remain secure.

The team reassured users that only the outdated V1 TUSD vault was affected and emphasised that newer deployments incorporate lessons learned from past vulnerabilities.

Nevertheless, the attack underscores the importance of actively auditing and deprecating legacy contracts to prevent the exploitation of similar flaws in the future.

The post Yearn Finance losses $300K in a TUSD vault exploit appeared first on Invezz

0 comment
0
FacebookTwitterPinterestEmail

previous post
Bitcoin price stuck near $88K ahead of BoJ rate call, NIGHT leads altcoin gains
next post
Indonesia’s green power shift needs $92B, faces funding hurdles, coal addiction

You may also like

Litecoin price plunges toward $50 as Bitcoin falls...

February 6, 2026

Bitcoin under $65K: what this sell-off says about...

February 6, 2026

Strategy (MSTR) and corporate crypto treasuries strained as...

February 6, 2026

Morning Brief: Asian markets slide, Bitcoin tumbles amid...

February 6, 2026

Bitwise files spot Uniswap ETF with SEC as...

February 6, 2026

Tether invests $150m in Gold.com to expand tokenised...

February 6, 2026

Metaplanet to keep accumulating Bitcoin as top holders...

February 6, 2026

Bitcoin eyes $72k after correcting to $60k: Check...

February 6, 2026

The anatomy of Bitcoin’s crash: macro, money and...

February 6, 2026

Solana reclaims $80 after retesting the $68 low,...

February 6, 2026

    Join our mailing list to get access to special deals, promotions, and insider information. Your exclusive benefits await! Enjoy personalized recommendations, first dibs on sales, and members-only content that makes you feel like a true VIP. Sign up now and start saving!


    By opting in you agree to receive emails from us and our affiliates. Your information is secure and your privacy is protected.

    Recent Posts

    • ECB holds rates steady as global risks overshadow easing inflation

      February 6, 2026
    • US jobless claims climb amid storms, but labour market holds steady

      February 6, 2026
    • US stocks open lower as Nasdaq falls 0.6% and tech selloff deepens

      February 6, 2026
    • Commodity wrap: silver plummets 13%, gold below $4,900; oil dips on Iran talks

      February 6, 2026
    • Europe bulletin: BoE holds rates, Syngenta eyes IPO, Slovenia’s social media ban

      February 6, 2026

    Disclaimer: TrickyProfit.com, its managers, its employees, and assigns (collectively "The Company") do not make any guarantee or warranty about what is advertised above. Information provided by this website is for research purposes only and should not be considered as personalized financial advice.
    The Company is not affiliated with, nor does it receive compensation from, any specific security. The Company is not registered or licensed by any governing body in any jurisdiction to give investing advice or provide investment recommendation. Any investments recommended here should be taken into consideration only after consulting with your investment advisor and after reviewing the prospectus or financial statements of the company.

    • About us
    • Contacts
    • Privacy Policy
    • Terms and Conditions
    • Email Whitelisting

    Copyright © 2025 TrickyProfit.com All Rights Reserved.

    Tricky Profit
    • Stock
    • Economy
    • Politics
    • Editor’s Pick