• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer
CoinLaw LogoCoinLaw

Bringing Crypto and Finance Closer to You

  • Latest News
  • Statistics
  • About
  • Contact
Subscribe
CoinLaw Logo
  • Latest News
  • Statistics
  • About
  • Contact
Subscribe
Home Β» Cryptocurrency

$3M Laundered Through Tornado Cash After Major Yearn Finance Exploit

Published on: December 1, 2025
Kelvin Scott
Written By
Kelvin Scott
Kelvin Scott
Finance News Analyst • 460 Articles
Kelvin Scott, with over 8 years of experience, covers the latest trends in digital assets, financial markets, and regulatory developments. W... See full bio
LATEST POSTS:
Capital B Eyes High Yield Bitcoin Credit Product in Europe
Pyra to Shut Down After Drift Exploit Leaves No Path to Recovery
Zimbabwe Opens Crypto Sector With New Licensing Framework
Yearn Finance Faces Exploit With 3m Tokens Laundered
As Featured In
Bloomberg LogoForbes LogoFortune LogoCoinDesk LogoCoinMarketCap Logo
Share on LinkedIn ChatGPT Perplexity Share on X Share on Facebook

One of DeFi’s oldest protocols, Yearn Finance, is facing scrutiny after an attacker exploited a legacy yETH token contract, minting trillions of fake tokens and draining millions in real assets from Balancer liquidity pools.

Key Takeaways

  • An attacker exploited Yearn Finance’s legacy yETH token, minting 235 trillion tokens in one transaction.
  • Roughly $9 million in total losses were confirmed by Yearn, with $3 million worth of ETH laundered through Tornado Cash.
  • Yearn’s V2 and V3 Vaults were not affected by the exploit, and the issue remains isolated to an older yETH implementation.
  • The protocol is working with SEAL 911 and ChainSecurity on a full post-mortem.

What Happened?

Yearn Finance confirmed on Sunday that its legacy yETH product was targeted in a sophisticated exploit. The attacker used a vulnerability in the token’s minting logic to create a nearly unlimited supply of yETH, then swapped the fake tokens for real assets from Balancer liquidity pools. Blockchain data shows the attacker minted around 235 trillion yETH tokens in a single transaction, draining millions in a matter of minutes.

We are investigating an incident involving the yETH LST stableswap pool.

Yearn Vaults (both V2 and V3) are not affected.

β€” yearn (@yearnfi) November 30, 2025

Yearn’s Legacy Token Exploited

The vulnerability was tied to an outdated version of the yETH token contract, not the newer vault infrastructure that Yearn currently promotes. By leveraging a flaw in this contract, the attacker was able to mint an infinite amount of yETH, which was then used to siphon off real ETH and popular liquid staking tokens (LSTs) from the associated Balancer pools.

  • Blockchain analysis estimates the attacker made off with roughly $9 million, including $8 million from the yETH stableswap pool and $0.9 million from the yETH-WETH pool on Curve.
  • Yearn confirmed that no other Yearn products, including V2 and V3 Vaults, were affected.
  • Protocols like Katana, which rely on Yearn V3, also reported no exposure to the exploit.

According to Yearn, β€œInitial analysis indicated this hack has a similar high complexity level to the recent Balancer hack,” and investigations are underway with assistance from SEAL 911 and ChainSecurity.

Tornado Cash Used to Obscure Funds

Shortly after the exploit, the attacker moved quickly to obfuscate their trail. Around 1,000 ETH, worth approximately $3 million, was funneled through privacy protocol Tornado Cash in several batches, including multiple 100 ETH transactions. This pattern was flagged by blockchain observers such as Togbe and confirmed by Nansen alerts.

Several helper smart contracts were deployed moments before the exploit to facilitate the attack. These contracts self-destructed afterward, erasing on-chain evidence and complicating forensic analysis.

Newsletter Img
Don't chase the news. Let us curate it.

You get one weekly briefing with only the stories that matter. If the market is quiet, we skip it.

βœ… Join readers from Visa, Vanguard, and the FDIC.

Not the First Time for Yearn

Yearn has dealt with security issues before. In 2021, the protocol lost $11 million from its yDAI vault, and in late 2023, a faulty script caused the loss of 63 percent of a treasury position, although no user funds were affected in that case.

Despite the incident, Yearn’s Total Value Locked (TVL) remains above $600 million, suggesting its core systems are still trusted by many DeFi users. However, its governance token YFI saw a temporary drop of 4 percent, trading near $4,002 shortly after the exploit and currently trading at $3,898.

Yfi Token Price 1st Dec
Image Credit – CoinGecko.com

CoinLaw’s Takeaway

I’ve seen many DeFi exploits over the years, but this one stands out for how cleanly it separated old code from current infrastructure. What this tells me is that legacy risks never really go away, especially in protocols with long histories and evolving codebases. The fact that Yearn isolated the issue quickly and maintained trust in its newer vaults is a positive sign, but it’s also a wake-up call for every DeFi protocol to retire or harden old contracts. In my experience, it’s not always the flashy new code that gets exploited. Sometimes, it’s the forgotten bits that come back to bite.

Definition of Blockchain. Link to full glossary entry follows the description.Blockchain

A distributed digital ledger that records transactions across a network, with each block cryptographically linked to the previous one for security.

Read more

Definition of Staking. Link to full glossary entry follows the description.Staking

Staking is the process of locking cryptocurrency in a proof-of-stake network to help validate transactions and earn rewards, replacing energy-intensive mining.

Read more

Definition of DeFi. Link to full glossary entry follows the description.DeFi

Decentralized finance leverages blockchain protocols and smart contracts to enable lending, trading, and borrowing without banks or traditional intermediaries.

Read more

CoinLaw follows strict Publishing Principles and a documented Fact-Check Policy to ensure accuracy, transparency, and editorial independence across all content.

Add CoinLaw as a Preferred Source on Google for instant updates! Follow on Google News
Share ChatGPT Perplexity
Kelvin Scott

Kelvin Scott

Finance News Analyst


Kelvin Scott, with over 8 years of experience, covers the latest trends in digital assets, financial markets, and regulatory developments. With a strong focus on accuracy and clarity, he delivers timely updates to help readers navigate the fast-changing world of crypto and finance. An avid football fan, he never misses a chance to watch a good match, whether it’s Premier League drama or a local game.

Related Posts

Exploiter Behind $65M DeFi Hacks Resurfaces with $2M Token Selloff
Cryptocurrency

Exploiter Behind $65M DeFi Hacks Resurfaces with $2M Token Selloff

Tessera DAO Hit by Exploit as TSR Drops 99%
Cryptocurrency

Tessera DAO Hit by Exploit as TSR Drops 99%

Stake DAO Hit by 5.4 Trillion vsdCRV Mint Exploit
Cryptocurrency

Stake DAO Hit by 5.4 Trillion vsdCRV Mint Exploit

Disclaimer:Β The content published on CoinLaw is intended solely for informational and educational purposes. It does not constitute financial, legal, or investment advice, nor does it reflect the views or recommendations of CoinLaw regarding the buying, selling, or holding of any assets. All investments carry risk, and you should conduct your own research or consult with a qualified advisor before making any financial decisions. You use the information on this website entirely at your own risk.

Reader Interactions

Leave a Comment Cancel reply

Primary Sidebar

Connect With Us

facebook x linkedin google-news telegram pinterest whatsapp email
google-preferred-source-badge Add as a preferred source on Google

You Should Also Read

Hacker Launders $19M in ETH After $27M Multisig Wallet Heist
Mixin Network Hacker Sends 2,005 ETH to Tornado Cash
THORChain Exploit Drains Over $10 Million as RUNE Price Sinks

Table of Contents

  • Key Takeaways
  • What Happened?
  • Yearn’s Legacy Token Exploited
  • Tornado Cash Used to Obscure Funds
  • Not the First Time for Yearn
  • CoinLaw’s Takeaway
Connect on Telegram

Footer

CoinLaw Logo

Bringing Finance Closer to You.

Connect With Us

Follow Us on Google News

Editorial & Trust

  • About
  • Publishing Principles
  • Fact-Check Policy
  • Corrections Policy
  • Ethics Policy
  • Disclaimer
  • Cookie Policy

Worth Checking

  • Best Cloud Mining Platforms
  • Millennial vs. Gen Z Banking
  • Ethereum Gas Fees Statistics
  • Binance vs. Coinbase Statistics
  • Zelle vs. Venmo Statistics
  • Traditional Banks vs. Neobanks
  • Crypto Exchange Hack Statistics
Contact Us
13570 Grove Dr #189,
Maple Grove, MN 55311,
United States
10β€―a.m. – 6β€―p.m. | Every day

Copyright Β© 2024–2026 CoinLaw. All Rights Reserved. Powered by the HODL Force ❀️

  • Privacy Policy
  • Terms
Manage your privacy

To provide the best experiences, we and our partners use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us and our partners to process personal data such as browsing behavior or unique IDs on this site and show (non-) personalized ads. Not consenting or withdrawing consent, may adversely affect certain features and functions.

Click below to consent to the above or make granular choices. Your choices will be applied to this site only. You can change your settings at any time, including withdrawing your consent, by using the toggles on the Cookie Policy, or by clicking on the manage consent button at the bottom of the screen.

Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Statistics

Marketing

Features
Always active

Always active
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
Manage options
  • {title}
  • {title}
  • {title}
Manage your privacy
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Statistics

Marketing

Features
Always active

Always active
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
Manage options
  • {title}
  • {title}
  • {title}
Company
  • About Us
  • Our Team
  • Our Mission
  • Core Values
Discover
  • glossary icon
    Glossary
  • Stats
    Stats Research Process
  • Brand Guide Icon
    Brand Assets
Categories
  • Cryptocurrency
  • Payments
  • Finance
  • Banking
  • Insurance
Cryptocurrency
Coinbase vs Kraken Statistics 2026: Volume, Fees, Licenses
Coinbase vs Kraken Statistics 2026: Volume, Fees, Licenses
Solana vs Ethereum Statistics 2026: TVL, Fees, Validators, ETFs
Solana vs Ethereum Statistics 2026: TVL, Fees, Validators, ETFs
Uniswap vs PancakeSwap Statistics 2026: Head-to-Head DEX Data
Uniswap vs PancakeSwap Statistics 2026: Head-to-Head DEX Data
Cryptojacking Statistics 2026: 80+ Cloud, Cost & Threat Numbers
Cryptojacking Statistics 2026: 80+ Cloud, Cost & Threat Numbers
MetaMask vs Phantom Wallet Statistics 2026: Big Growth Data
MetaMask vs Phantom Wallet Statistics 2026: Big Growth Data
Crypto Wallet Ecosystem Statistics 2026: Addresses, Security, Adoption
Crypto Wallet Ecosystem Statistics 2026: Addresses, Security, Adoption
Payments
Toast Statistics 2026: ARR, GPV & Revenue Data
Toast Statistics 2026: ARR, GPV & Revenue Data
Rapyd Statistics 2026: TPV, Valuation & Licences
Rapyd Statistics 2026: TPV, Valuation & Licences
Marqeta Statistics 2026: TPV, Revenue and Customer Mix
Marqeta Statistics 2026: TPV, Revenue and Customer Mix
Digital Payments Statistics 2026: Market Size, Users, and Growth
Digital Payments Statistics 2026: Market Size, Users, and Growth
Cash App vs Venmo vs Zelle Statistics 2026: What You Must Know Now
Cash App vs Venmo vs Zelle Statistics 2026: What You Must Know Now
Worldpay Statistics 2026: Massive Payment Growth
Worldpay Statistics 2026: Massive Payment Growth
Finance
Emergency Fund Statistics 2026: How Much Americans Have Saved (and How Much They Should)
Emergency Fund Statistics 2026: How Much Americans Have Saved (and How Much They Should)
Financial Advisor Statistics 2026: Headcount, AUM, and Demographics
Financial Advisor Statistics 2026: Headcount, AUM, and Demographics
Wealth Inequality Statistics 2026: Hidden Wealth Divide
Wealth Inequality Statistics 2026: Hidden Wealth Divide
Blockchain in Supply Chain Finance Statistics 2026: Trade Breakthrough
Blockchain in Supply Chain Finance Statistics 2026: Trade Breakthrough
Blockchain in Healthcare Finance Statistics 2026: Cost Breakthrough
Blockchain in Healthcare Finance Statistics 2026: Cost Breakthrough
AI-Powered Robo Trading Statistics 2026: Big Insights
AI-Powered Robo Trading Statistics 2026: Big Insights
Banking
N26 Statistics 2026: Customers, Deposits, Revenue and the BaFin Growth Cap
N26 Statistics 2026: Customers, Deposits, Revenue and the BaFin Growth Cap
Revolut vs Monzo Statistics 2026: Customers & Profit
Revolut vs Monzo Statistics 2026: Customers & Profit
Islamic Banking Statistics 2026: Assets, Growth, and Top Markets
Islamic Banking Statistics 2026: Assets, Growth, and Top Markets
Credit Union Statistics 2026: Assets, Members, Loans
Credit Union Statistics 2026: Assets, Members, Loans
Banking API Statistics 2026: Market Size, Adoption, and Growth
Banking API Statistics 2026: Market Size, Adoption, and Growth
Citigroup Statistics 2026: Growth Secrets Inside
Citigroup Statistics 2026: Growth Secrets Inside
Insurance
Lemonade Insurance Statistics 2026: Customers, In-Force Premium, Loss Ratio, Pet & Auto Segments
Lemonade Insurance Statistics 2026: Customers, In-Force Premium, Loss Ratio, Pet & Auto Segments
Chubb Statistics 2026: Powerful Data Insights
Chubb Statistics 2026: Powerful Data Insights
Virtual Reality In Insurance Statistics 2026: Innovations, Risks, and Opportunities
Virtual Reality In Insurance Statistics 2026: Innovations, Risks, and Opportunities
US Life Insurance Industry Statistics 2026: Growth Facts
US Life Insurance Industry Statistics 2026: Growth Facts
US Auto Insurance Industry Statistics 2026: What You Must Know Now
US Auto Insurance Industry Statistics 2026: What You Must Know Now
UK Insurance Industry Statistics 2026: Growth Data
UK Insurance Industry Statistics 2026: Growth Data
Categories
  • Cryptocurrency
  • Investments
  • Compliance
  • Fintech
  • Finance
Cryptocurrency
Singapore Flags Bybit in Major Crypto Warning to Investors
Singapore Flags Bybit in Major Crypto Warning to Investors
Inveniam, Docugami Reveal Powerful RWA Data Verification Model
Inveniam, Docugami Reveal Powerful RWA Data Verification Model
Kraken Rolls Out Regulated Crypto Perps Across the US
Kraken Rolls Out Regulated Crypto Perps Across the US
MARA Buys 1,000 Bitcoin After Massive $1.5B BTC Selloff
MARA Buys 1,000 Bitcoin After Massive $1.5B BTC Selloff
India’s ED Files Case in $20M Coinbase Crypto Heist
India’s ED Files Case in $20M Coinbase Crypto Heist
Capital B Eyes High Yield Bitcoin Credit Product in Europe
Capital B Eyes High Yield Bitcoin Credit Product in Europe
Investments
Nvidia Unveils Huge $20B Bond Raise to Power AI Growth
Nvidia Unveils Huge $20B Bond Raise to Power AI Growth
Binance SpaceX IPO Offer Attracts Massive $557M Demand
Binance SpaceX IPO Offer Attracts Massive $557M Demand
Metaplanet Acquires Siiibo in Major Bitcoin Expansion Move
Metaplanet Acquires Siiibo in Major Bitcoin Expansion Move
Morpho Raises $175M at $2B Value as MORPHO Token Jumps
Morpho Raises $175M at $2B Value as MORPHO Token Jumps
Pyth Launches Groundbreaking 24/7 Stock and Commodity Indices
Pyth Launches Groundbreaking 24/7 Stock and Commodity Indices
Nvidia Secures SK Hynix AI Memory Supply Deal
Nvidia Secures SK Hynix AI Memory Supply Deal
Compliance
Binance Could Lose EU Access After Reported MiCA Rejection
Binance Could Lose EU Access After Reported MiCA Rejection
New York Moves to Align Stablecoin Rules With GENIUS Act
New York Moves to Align Stablecoin Rules With GENIUS Act
Polymarket Faces Major Blow as South Korea Probes Users
Polymarket Faces Major Blow as South Korea Probes Users
FCA Flags Crypto Sponsorship Risks for Premier League Clubs
FCA Flags Crypto Sponsorship Risks for Premier League Clubs
Polymarket May Enforce KYC as Regulators Tighten Oversight
Polymarket May Enforce KYC as Regulators Tighten Oversight
CFTC and Gemini Ask Court to Undo $5M Settlement
CFTC and Gemini Ask Court to Undo $5M Settlement
Fintech
Bybit Unveils Powerful Broker API With Ultra Low Latency Access
Bybit Unveils Powerful Broker API With Ultra Low Latency Access
Bitget and xStocks Bring SpaceX IPO Access Onchain
Bitget and xStocks Bring SpaceX IPO Access Onchain
Bybit Launches IPO Express With Tokenized SpaceX Access
Bybit Launches IPO Express With Tokenized SpaceX Access
Pred Launches Sports Prediction Markets for FIFA World Cup
Pred Launches Sports Prediction Markets for FIFA World Cup
JPMorgan, Citi, BofA to Build Blockchain Deposit Network
JPMorgan, Citi, BofA to Build Blockchain Deposit Network
Moomoo Debuts Kalshi Powered Event Contracts for Retail Traders
Moomoo Debuts Kalshi Powered Event Contracts for Retail Traders
Finance
Coinbase Sparks New Race With 1:1 Backed Tokenized Stocks
Coinbase Sparks New Race With 1:1 Backed Tokenized Stocks
Bitmine Launches $300M Preferred Stock to Buy More ETH
Bitmine Launches $300M Preferred Stock to Buy More ETH
Coinbase Lists SpaceX Pre IPO Perpetual Futures
Coinbase Lists SpaceX Pre IPO Perpetual Futures
Binance Expands Into US Stocks With New bStocks Service
Binance Expands Into US Stocks With New bStocks Service
SEC Clears Paxos to Settle U.S. Stocks on Blockchain
SEC Clears Paxos to Settle U.S. Stocks on Blockchain
Mastercard Expands Stablecoin Strategy With NY BitLicense
Mastercard Expands Stablecoin Strategy With NY BitLicense
Newsletter Img

Too much noise in crypto?

We respect your time. You get one high-impact briefing a week. If the market is quiet, so are we.

βœ… Join readers from Visa, Vanguard, and the FDIC.
Newsletter Img

The Weekly Briefing

We track the market 24/7. You get a 5-minute summary. If it’s quiet, we skip it.

βœ… Read by pros at Visa, Vanguard, and the FDIC.