ETH
by BSCN
April 13, 2023
Aave said the exploit did not impact any version of its protocol, while Yearn Finance said current protocols were safe.
A hacker exploited a vulnerability in an “outdated” iearn stablecoin to drain $10 million in liquidity from Yearn Finance and Aave Protocol. Following the attack, both Yearn and Aave assured users that current versions of their protocols were not impacted by the exploit.
"We're looking into an issue with iearn, an outdated contract from before Vaults v1 and v2. This problem seems exclusive to iearn and does not impact current Yearn contracts or protocols," Yearn tweeted.
Yearn said the exploited contract was deprecated in 2020.
AaveAave said the vulnerability to did not impact any version of its protocol.
The Security Department of Web3 Super App and Antivirus De.Fi broke down the attack in a Twitter thread.
According to De.Fi, the iearn yUSDT token was misconfigured to use Fulcrum $iUSDC instead of Fulcrum $iUSDT. The attacker used the vulnerability to mint 1.2 quadrillion $yUSDT from just $10,000, then cashed out the $yUSDT for other stablecoins.
De.Fi posted screenshots of the attacker’s two wallets, showing about $10 million in assets spread across $ETH, $aTUSD, $DAI and $USDC.
Latest News
4h : 32m ago
Weekly Article Recap: 9/30-10/04
October 4, 2024
Coinbase to Delist Non-Compliant Stablecoins in EU by December
October 4, 2024
CryptoPunk 1563 “Sells” for $56M: Real Deal or Flash Loan Stunt?
October 4, 2024
Is Satoshi Nakamoto About to Be Exposed? HBO Documentary Claims to Reveal Bitcoin Creator’s Identity
October 3, 2024
Visa Introduces Tokenized Asset Platform for Fiat-Backed Tokens
October 3, 2024
Lamborghini to Unveil Web3 Platform "Fast ForWorld" With Animoca Brands
October 3, 2024
Crypto Losses in 2024 Soar to $2.11 Billion, Surpassing 2023’s Annual Total: Report
October 3, 2024
Aptos Blockchain Welcomes Franklin Templeton's Tokenized U.S. Government Fund