SlowMist|Dec 05, 2025 02:38
🚨On Dec 1, @yearnfi was exploited, resulting in ~$9M in losses.
🛠️The SlowMist security team analyzed the incident and identified the root cause:👇
The vulnerability stems from the logic inside the _calc_supply function used to calculate supply in Yearn’s yETH Weighted Stableswap Pool contract. Due to unsafe mathematical operations, the function allows overflow and rounding during calculation. This flaw leads to a significant deviation when computing the product of the new supply and virtual balance, enabling attackers to manipulate liquidity to specific values and mint an excessive supply of LP tokens, thereby profiting illicitly.
🔍We recommend strengthened edge-case testing and the use of secure, validated arithmetic operations to prevent severe vulnerabilities like overflow in similar protocols.
Full analysis👉 https://medium.com/@slowmist/9-million-stolen-analysis-of-the-yearn-yeth-pool-vulnerability-557237092054(SlowMist)
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink