Yearn Finance has disclosed a security breach in a legacy stableswap liquidity pool that resulted in the theft of approximately $9 million. The attack, which occurred on November 30, 2025, was facilitated by a numerical error that allowed attackers to mint unlimited LP tokens.
Attack Details
The exploit targeted an older version of Yearn's stablecoin AMM pool. The vulnerability allowed the attacker to drain around $9 million in crypto assets. Yearn Finance confirmed that its v2 and v3 vaults were not impacted by the exploit, as they rely on more robust contract logic.
Recovery and User Compensation
In response, Yearn Finance has successfully recovered 857.49 pxETH (a liquid staking derivative) and intends to return these assets to affected savers. The recovery was achieved through on-chain negotiations with the exploiter. The team stated that it will prioritize returning the funds to users as soon as possible.
Security Enhancements
To prevent future incidents, Yearn Finance plans to implement domain checks as part of its security enhancements. This measure will validate inputs more strictly to prevent numerical miscalculations. The protocol also urged users to stay updated on security advisories.
The incident underscores the persistent risks of legacy DeFi contracts. While Yearn has patched the issue in newer versions, lingering old pools remain vulnerable. The community calls for proactive code audits and migration strategies to reduce technical debt.

