Nine Flash Loans and a Disabled Withdrawal Fee Cost Yearn's DAI Vault $11M
Yearn's DAI v1 vault lost $11 million on February 5, 2021 in an arbitrage attack built around nine flash loans — a reminder that scale and track record don't make any protocol immune to this kind of exploit.
Of the $11 million drained, $2.7 million went to the attacker, $3.5 million went to Curve liquidity providers, another $3.5 million went to Curve stakers, and $1.4 million was consumed in Aave v2 fees. The root cause: a withdrawal fee that had been switched off to support a vault migration, which opened a profit window the attacker was able to exploit.

01How the exploit unfolded
Yearn's team published its own post-mortem without referencing flash loans directly. A more granular breakdown came from Igor Igamberdiev, who laid out the attacker's transaction sequence on Twitter. By his account, the attacker's take amounted to 513k DAI, 1.7M USDT, and a remaining 506k 3CRV (~$1).
The attack itself spanned 11 transactions:
- Flash-loan 116k ETH from dYdX.
- Flash-loan 99k ETH from Aave v2.
- Use the borrowed ETH as collateral on Compound to borrow 134M USDC and 129M DAI.
- Deposit 134M USDC and 36M DAI into the 3crv Curve pool.
- Withdraw 165M USDT from the 3crv Curve pool.
- Repeat the following loop five times, with each round's amounts slightly smaller than the last: deposit 93M DAI into the yDAI vault, add 165M USDT to the 3crv pool, withdraw 92M DAI from the yDAI vault, then withdraw 165M USDT from the 3crv pool again.
- On the final pass through that loop, withdraw 39M DAI and 134M USDC instead of USDT.
- Repay the Compound debts.
- Repay the flash loans.
Each cycle through step six left the attacker holding a larger 3crv balance, which was eventually converted into stablecoins for the final payout described above.
The funds moved through the attacker's contract, visible on Etherscan, before being routed through Tornado Cash across four separate transactions:
02Reading the motive
Given that Yearn's developers are widely regarded as highly capable, the incident looked less like a fundamental design flaw and more like an opportunist capitalizing on a temporary condition — the disabled withdrawal fee — introduced specifically for the vault migration.
Speculation briefly circulated that the attack was retaliation connected to an earlier dispute in which Andre Cronje accused Julien Bouteloup, a contributor to Stake DAO, of hypocrisy. That theory didn't hold up: on-chain records show the attacker's account was funded and the exploit contract was written hours before Cronje's remarks were even made, ruling out any direct causal link between the two events.

03The Tether question
Separately, Tether froze the 1.7M USDT taken in the hack. The company has a history of reimbursing users who accidentally send tokens to the wrong contract address, and it appears to have extended similar treatment here. That raises a governance question for a supposedly decentralized ecosystem: if Tether ultimately burns the frozen tokens and mints an equivalent amount to make Yearn whole, the intervention functions no differently than action by a central bank. Notably, Yearn developer @fubuloubu, who has previously criticized reliance on Tether, appeared to soften that stance following this instance of Tether stepping in.
04Takeaway
The episode marked the first visible crack in what had been viewed as one of DeFi's most battle-tested platforms. It underscores how deeply interconnected DeFi protocols have become, and how even experienced teams operating mature, widely used systems remain exposed to overlooked edge cases — in this case, a fee toggled off for a routine migration, and nine flash loans were all it took to turn that gap into an $11 million loss. As with earlier pieces on centralized finance and the broader stablecoin landscape, the incident is best read as a lesson in systemic risk rather than a verdict on any single team's competence.
Get new scam files the moment we publish them — usually 2–3 emails a week.