What happened: the sequence of the attack

On the evening of November 30, 2025 (around 21:11 UTC), blockchain data flagged a suspicious transaction: a malicious wallet minted an astronomical number of yETH tokens in a single move. According to analyses, the attacker managed to create roughly 235 trillion yETH tokens in that transaction alone.

With those fraudulent tokens, the attacker drained liquidity from pools on Balancer, extracting real assets such as ETH and liquid-staking tokens (LSTs). Roughly $2.8-3 million in ETH was transferred through a mixing service in an apparent money-laundering move.

In a public statement, Yearn clarified that the exploit affected only the legacy yETH contract. Their V2 and V3 vaults remain unaffected and intact.

The vulnerability: unlimited minting in the smart-contract code

According to security firms and blockchain analysts, the root of the exploit was a flaw in the yETH token contract that allowed “infinite minting.” In effect, the contract failed to enforce limits or prerequisites on mint operations, so a malicious actor could create vast quantities of yETH tokens out of thin air.

This exploit did not target Yearn’s vault logic or lending mechanics, but rather the “index token” wrapper for liquid staking assets. Because yETH represents a basket of underlying staking tokens, minting unlimited yETH lets an attacker redeem or swap those fake tokens for real assets, then drain the backing pools.

Impact: financial loss and broader implications for DeFi

The immediate loss appears to center around $2.8-3 million in ETH and associated liquid-staking tokens. Despite the modest sum relative to some recent mega-hacks, the incident underlines critical systemic risks: even mature, audited DeFi platforms can be undermined by subtle mistakes in token contract design.

The exploit also triggered a price shock in the governance token YFI, which briefly spiked as panic selling triggered by the exploit was met by rapid repositioning from traders.

For users of Yearn and other DeFi protocols, the takeaway is stark: “vaults” or “liquidity pools” are only as safe as the smart contracts that underlie them. This yETH exploit serves as a reminder that complexity in DeFi, especially when wrapping or aggregating other protocols (e.g., liquid staking tokens), substantially increases attack surface and risk.

What’s next: investigation, remediation, and lessons learned

Yearn has pledged a full post-mortem analysis in cooperation with security auditors. So far, they assert that the vulnerability was isolated to the legacy yETH contract, meaning users in newer vaults are safe for now.

Nevertheless, the incident may well trigger audits across DeFi: projects that offer index tokens, liquid staking wrappers, or complex token-pool abstractions will likely revisit their mint logic, supply caps, and redemption mechanisms, as well as conduct deeper security reviews.

This episode underscores a hard truth: in decentralized finance, the louder the yield promise, the more silent the risk, and the consequences of a single flawed smart contract can ripple across millions.

#Ethereum#exploit#hack#infinite mint#Mixer#Smart Contract#Yearn Finance

Sarah Thompson is not a person. No notebook, no deadlines, no face behind the name — just a byline this newsroom publishes under. Here is the production line underneath it, because a name beside a portrait reads like a journalist, and this one is not one.

The models. Writing: gpt-5.6-luna. Out on the live web: gpt-5.6-luna and gpt-5.6-terra. Pictures: gpt-image-1. Swap one in the newsroom and this line swaps with it — it is read off the machines, not typed here.

How a story is made

  • Research. The searching model reads around the story, pointed at primary sources — the filing, the post, the repository — rather than at somebody else's write-up of them.
  • Writing. The writing model drafts it against what was found, at Sarah Thompson's usual length and in Sarah Thompson's usual register.
  • The loop. A reviewer reads the draft and sends it back with notes. Then reads it again. A piece can go round several times before it leaves the building.
  • Enrichment. A quotation has to appear word for word on the page it is taken from. A chart may only use figures that appear in the source it cites. Whatever fails is dropped, and the reason is kept.
  • Fact check. A last pass hunts for claims the article makes and its sources do not.
  • A human stop. Sensitive subjects are held for a person to read before publication, and a person can kill any of it at any point.

If that sounds less like a newsroom and more like a factory: quite. It is called Press Factory.

This article was generated using AI and published automatically without human pre-publication review.

Without human check

How this article was made

The article was produced by the Grandmonts Media News Engine using automated research, drafting and verification workflows. No human editor reviewed the article before publication. Grandmonts Media remains responsible for the published content. Errors can be reported at office@grandmonts.cz.