Five-Year-Old iEarn Contract Bled for $293k in Yearn's Fourth Exploit
DeFi's habit of repeating itself isn't limited to patterns of behavior — sometimes it's the exact same bug, replayed against a different balance sheet. Yearn Finance has now been hit a fourth time, this time through a 2020-era contract undone by a configuration flaw nearly identical to the one that cost the protocol $10 million in 2023.
The dollar figure this time was comparatively small — about $293,000 — but the incident points to a pattern worth watching across the industry.

It's the latest entry in what's becoming a season defined by attacks on old code. Abracadabra's "deprecated" cauldrons lost $1.8 million in October; Balancer's rounding-error exploit drained $128 million just last month; and Yearn's own yETH pool lost $9 million only two weeks prior to a math bug in a product the team had effectively abandoned. None of these were current, actively guarded systems — all were dormant, overlooked contracts still sitting live on-chain.
As easier, present-day targets grow scarcer, attackers appear to be treating a protocol's immutable history less as an archive and more as an inventory to raid.
Credit: William Li, Peckshield, Yearn, Banteg (GitHub)
01Timeline of discovery
The first warning came late on December 16, when William Li publicly flagged the activity: "Another Yearn V1 vault attack is underway! The root cause appears to be another configuration problem." PeckShield confirmed the exploit shortly afterward, by which point the attacker had already converted the stolen funds into 103 ETH.
Yearn's team responded quickly by separating the incident from its current infrastructure. Rather than mobilizing a formal incident-response effort, the team's statement functioned more as a historical footnote, noting that the affected contract had been deployed more than 2,100 days earlier and had no bearing on Yearn's active vaults.
02What was actually exploited
Per Yearn's own account, this was not a breach of the protocol's present-day security setup — it was an old, dormant contract being reactivated by an attacker, and the underlying cause turned out to be strikingly familiar.
The root cause mirrored the 2023 exploit almost exactly — a configuration error that closely resembled the $10 million incident that hit the iearn USDT vault in April 2023. This time, the TUSD vault carried the flawed setup.
Banteg's technical writeup laid out the mechanics: the vault's strategy was configured to track Fulcrum's iSUSD token (backed by sUSD), even though the vault's actual underlying asset was TUSD — a mismatch between what the vault held and what it thought it was pricing.
Using a large flash loan from Morpho, the attacker exploited this mismatch to set off a chain reaction. The first move corrupted the vault's share accounting: by depositing assets the vault's logic couldn't account for, the attacker pushed the accounting system into treating its own balance as effectively zero. With the denominator collapsed near zero, the share-price calculation broke down entirely, producing extreme inflation in the supply of yTUSD shares — an enormous quantity minted for what amounted to a rounding-error's worth of cost.
Minting the shares was only the setup. To realize any value, the attacker needed a venue willing to accept them, which turned out to be the Curve yPool. Using heavy leverage, the newly minted yTUSD was dumped into that pool, swapped out for genuine yDAI and yUSDC.
The sell-off didn't just strip the pool's liquidity — it crashed the price of the yPool LP token itself, with consequences beyond the vault. STABLEx, which priced its collateral off the Curve yPool, was left exposed: once the pool's value collapsed, its positions were theoretically pushed toward instant insolvency. The protocol wasn't destroyed outright by the attacker — it was left drained of confidence, still standing but hollowed out.
The attacker's net take was roughly $293,000 — but a strange byproduct was left behind: about 214,000 sUSD remains stuck inside the compromised vault. Because the legacy contract's code doesn't recognize sUSD as a valid asset, those funds are stranded permanently — visible on-chain, but not something the contract logic can ever release. The vault is effectively frozen, holding assets it has no way to process.
03Following the money
The attack itself required no exotic tooling — just a contract with the right access. The attacker's externally owned account deployed a purpose-built contract to handle the minting, the pool draining, and the subsequent swaps.
- Attacker EOA: 0xcaca279dff5110efa61091becf577911a2fa4cc3
- Attacker contract: 0x67e0c4cfc88b98b9ed718b49b8d2f812df738e42
Leverage came from a 30,000,000 USDC flash loan sourced from Morpho.
- Flash loan transaction (see the highlighted event log): 0x78921ce8d0361193b0d34bc76800ef4754ba9151a1837492f17c559f23771c43
- Victim contract — iearn TUSD (legacy V1): 0x73a052500105205d34daf004eab301916da8190f
- Exploit transaction: 0x78921ce8d0361193b0d34bc76800ef4754ba9151a1837492f17c559f23771c43
Once complete, the stolen stablecoins were converted into roughly 103 ETH. Unlike the $9 million yETH exploit from November, where funds moved through laundering channels almost immediately, this time the trail simply stops.
- Holding address where the funds currently sit idle: 0x0F214a04c70cf421ae92279afb3cf5668f554066

No Tornado Cash deposits, no bridge transfers — just a static balance, unmoved since the exploit.
04Yearn's response and the bigger pattern
Rather than standing up a formal incident response, Yearn largely pointed to the contract's age. The team confirmed the breach was contained to "iEarn's immutable TUSD contract," deployed more than 2,100 days earlier — predating the existence of YFI itself — and stated it had no bearing on current contracts or vaults.
That framing holds up technically: an immutable contract cannot be patched by design. But the same immutability that makes the contract technically unimpeachable also makes it permanently exploitable once a flaw is found.
The broader implication reinforces a concern already circulating in the security community: this isn't opportunistic hacking anymore, but something closer to systematic excavation of old deployments. Attackers appear to be working through years-old bytecode, hunting for logic errors that were easy to miss in 2020 but are far easier to spot with today's tooling, including AI-assisted analysis. Under that lens, dormant liquidity sitting in old contracts looks less like a forgotten balance and more like an open bounty.
The recurrence of this exact configuration error — now responsible for two separate losses — suggests that even as protocols evolve, the mistakes baked into their earlier code do not go away on their own. Whether this marks a genuine wave of attackers specializing in old contracts remains to be seen, but the underlying tension is clear: immutability was meant to guarantee that rules can't be changed, and that same guarantee is exactly what lets a known flaw stay exploitable indefinitely, with no statute of limitations in sight.
Get new scam files the moment we publish them — usually 2–3 emails a week.