지금 프로젝트를 보호하세요
최대 규모의 웹3 보안 제공업체로 프로젝트를 강화하세요.
CertiK 보안 전문가가 귀하의 요청을 검토 후 곧 연락드리겠습니다.

Earnings Misconfigured: Yearn.finance Exploit Explained

보고서 ·사고 분석 ·
Earnings Misconfigured: Yearn.finance Exploit Explained

Project name: Yearn.finance

Project type: Aggregator

Date of exploit: April 13, 2023

Asset loss: Approximately $10M

Vulnerability: Misconfiguration

Date of audit report publishing: March 5, 2020

Conclusion: Out of Scope

Details of the Exploit

Background

Yearn Finance is a DeFi aggregator protocol. The yVault Tokens represent a user's share of the yVault that they are participating in, for example, deposit USDT to mint yUSDT.

Nature of the Vulnerability

The issue arises from an incorrect configuration where the Fulcrum iUSDC token was used in place of the Fulcrum iUSDT token. As a result, the yUSDT token, designed to generate yield based on USDT, was mistakenly based on a different token, iUSDC. This mismatch leads to unforeseen financial outcomes (either losses or gains) for holders of yUSDT, contingent on the fluctuating exchange rates between USDT and USDC. Screenshot 2024-01-08 at 6.13.52 AM

CertiK Audit Overview

Screenshot 2024-01-08 at 6.14.26 AM

Conclusion

On April 13, 2023, yearn.finance was attacked due to a misconfiguration of the yUSDT contract, leading to a loss of approximately $10M.

The vulnerability is due to a misconfiguration of the yUSDT contract that uses the fulcrum iUSDC address, which is different from the yDAIv2.sol’s configuration and should be out of scope.

References

관련 블로그

Makina Incident Analysis

Makina Incident Analysis

On 20 January 2026, DeFi protocol MakinaFi suffered an exploit resulting in the theft of 1,299 ETH, valued at approximately $4.13 million.

CertiK Ventures Announces Investment in Zoo Finance

CertiK Ventures Announces Investment in Zoo Finance

CertiK Ventures is proud to announce our investment in Zoo Finance – a DeFi protocol pioneering the next evolution of blockchain fundraising via its Liquid Node Token (LNT) architecture.

Polter Finance Incident Analysis

Polter Finance Incident Analysis

On 16 November 2024, Polter Finance was exploited for ~$8.7 million, due to a price manipulation exploit. Polter Finance paused their platform shortly after to investigate.