Yearn yETH Exploit Drains $9M; Attacker Launders 1,000 ETH via Tornado Cash
Yearn Finance’s legacy yETH vault was exploited in a single transaction that minted excessive yETH tokens, draining roughly $9 million from stableswap liquidity. Security monitor PeckShield first flagged the breach and traced on-chain flows. Yearn confirmed about $0.9M lost from the yETH–WETH Curve stableswap and ~ $8M from a custom stETH/rETH pool. The attacker moved roughly 1,000 ETH (≈ $3M) into Tornado Cash in 100 ETH increments and retains about $6M in an exploiter-controlled wallet. Arkham analytics show holdings split across staked-ETH derivatives and wrapped/staking xETH tokens (Rocket Pool, Lido, pXETH, fXETH, cbETH, tETH). The root cause was an unchecked mint function in the yETH contract that allowed unlimited minting without adequate collateral. Yearn has opened a war room with SEAL911 and Chain Security and is conducting a full postmortem. The exploit coincided with an intraday ~5% drop in ETH, higher trading volume and bearish technical signals (ETH below the 50-day EMA; 14-day RSI near 34). Traders should watch staked-ETH derivative pools and legacy vault contracts for fragility; consider liquidity risk, on-chain address monitoring, and potential heightened audit scrutiny. Primary keywords: Yearn yETH exploit, Tornado Cash, yETH mint vulnerability, stETH, rETH, DeFi security.
Bearish
The exploit directly affects ETH-linked liquidity by targeting staked-ETH derivative pools and a stable-swap vault, increasing perceived systemic risk for staked-ETH products. Short-term, the event coincided with a ~5% intraday ETH price drop, higher volume and bearish technical indicators (ETH below 50‑day EMA; RSI ~34), which indicates immediate selling pressure and reduced confidence among traders. The laundered 1,000 ETH through Tornado Cash adds downward pressure by removing liquidity and increasing anonymity-driven risk. Medium-term impact may remain negative for staked-ETH derivatives and legacy vaults as funds are reallocated, audits intensify and counterparties price in higher smart-contract risk premiums. However, broader ETH network fundamentals are unchanged; once vulnerabilities are patched and audits completed, price effect could moderate. Overall, expect short-term bearish pressure on ETH and on tokens tied to staked-ETH pools, with recovery contingent on remediation, reimbursements and market sentiment.