
Cos(余弦)😶🌫️|Dec 01, 2025 05:32
Yearn's on-chain announcement is fake, just like the last time Balancer got hacked. It's the same phishing group behind it...
This attacker prepared gas 28 days ago through the Railgun privacy protocol, with a very small amount of gas (0.0006384 ETH):
0xFb63aa935Cf0a003335dCE9Cca03c4F9c0fa4779
0x011C654467a2f84068325Be2C856c1D07d27f9B7
Then they initiated a single exploit:
https://(((etherscan.io)))/tx/0x53fe7ef190c34d810c50fb66f0fc65a1ceedc10309cf4b4013d64042a0331156
At first glance, it looks pretty complex. This exploit ultimately funneled 1000 ETH into Tornado Cash. Originally, it was 1100 ETH, but 100 ETH was withdrawn to continue further exploits:
https://(((etherscan.io)))/address/0x3e8e7533dcf69c698cf806c3db22f7f10b9b0b97 internaltx
The rest of the stolen funds are parked here:
https://(((etherscan.io)))/address/0xa80d3f2022f6bfd0b260bf16d72cad025440c822 tokentxns
The attacker’s total profit is around $9M. I feel like this attacker might be a bit of a perfectionist.
Timeline