Yearn project favicon

Yearn

Multi-Chain
Last audited on 2023/11/03
No active critical issues

Last Issues (14)

Low
Medium
High
Critical
Total
Not fixed
----0
Fixed
851-14
Total851014

Reported rekts

yearn.finance was reported as rekt on 2021/02/04
Click to show description
Quick Summary

An attacker exploited dYdX, Aave v2, Compound, and Curve in a complex flash loan attack, resulting in a significant manipulation
of funds.




Details of the Exploit

The attacker initiated the exploit by flash loaning 116k ETH from dYdX and 99k ETH from Aave v2. They then borrowed 134M USDC and
129M DAI using the loaned ETH as collateral on Compound. The attacker added these funds to the 3crv Curve pool and withdrew 165M
USDT. 




This process was repeated five times, each time depositing less DAI to the yDAI vault and withdrawing less DAI from it. In the
final iteration, the attacker withdrew 39M DAI and 134M USDC instead of USDT. The attacker then repaid the debts on Compound and
the flash loans on dYdX and Aave v2.




Block Data Reference

The attacker's transactions:

https://etherscan.io/tx/0x59faab5a1911618064f1ffa1e4649d85c99cfd9f0d64dcebbc1af7d7630da98b

https://etherscan.io/tx/0xf6022012b73770e7e2177129e648980a82aab555f9ac88b8a9cda3ec44b30779

Audits (10)

#NameAuditorDateChainsIssues
1yETH GovernanceChainSecurity2023/11/03
Off-Chain (Private)
No active critical issues
2ERC4626 RouterChainSecurity2023/08/29
Off-Chain (Private)
No active critical issues
3yETH PeripheryChainSecurity2023/08/29
Off-Chain (Private)
No active critical issues
4yETHChainSecurity2023/06/26
Off-Chain (Private)
No active critical issues
5yBALChainSecurity2023/06/13
Off-Chain (Private)
No active critical issues
6Yearn Tokenized StrategyChainSecurity2023/05/04
Off-Chain (Private)
No active critical issues
7Yearn V3 VaultsChainSecurity2023/05/04
Off-Chain (Private)
No active critical issues
8oYfiChainSecurity2023/03/07
Off-Chain (Private)
No active critical issues
9yCRV and ZapYCRVChainSecurity2022/09/06
Off-Chain (Private)
No active critical issues
10Partner TrackerChainSecurity2022/01/18
Off-Chain (Private)
No active critical issues