{"id":47790,"date":"2023-04-13T08:07:17","date_gmt":"2023-04-13T12:07:17","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=47790"},"modified":"2023-07-08T03:35:23","modified_gmt":"2023-07-08T07:35:23","slug":"exploiter-mints-1-quadrillion-yearn-tether-yusdt","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/exploiter-mints-1-quadrillion-yearn-tether-yusdt\/","title":{"rendered":"Exploiter mints 1 quadrillion Yearn Tether (yUSDT)"},"content":{"rendered":"\n<p>In the most recent decentralized finance (DeFi) breach, <a href=\"https:\/\/coinscreed.com\/staging\/in-light-of-a-recent-air-force-contract-the-u-s-air-force-prioritizes-blockchain-security.html\">Blockchain security<\/a> firm PeckShield detected a hack that allowed the exploiter to mint over 1 quadrillion Yearn Tether (yUSDT).<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img fetchpriority=\"high\" decoding=\"async\" width=\"800\" height=\"459\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/04\/image-26.png\" alt=\"Exploiter mints 1 quadrillion Yearn Tether (yUSDT)\" class=\"wp-image-47801\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/04\/image-26.png 800w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/04\/image-26-300x172.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/04\/image-26-768x441.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/04\/image-26-750x430.png 750w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><figcaption class=\"wp-element-caption\">Exploiter mints 1 quadrillion Yearn Tether (yUSDT)<\/figcaption><\/figure>\n\n\n\n<p>According to the security firm, the intruder then exchanged yUSDT for other stablecoins, allowing them to obtain stablecoins worth $11.6 million. This consists of 61,000 Pax Dollars (USDP), 1.5 million TrueUSD (TUSD), 1.79 million Binance Dollars (USD), 1.2 million Tether (USDT), 2.58 million USD Coin, and 3 million DAI.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"662\" height=\"364\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/04\/image-25.png\" alt=\"\" class=\"wp-image-47800\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/04\/image-25.png 662w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/04\/image-25-300x165.png 300w\" sizes=\"(max-width: 662px) 100vw, 662px\" \/><figcaption class=\"wp-element-caption\">PeckShield illustrates the flow of funds from the attack. Source: PeckShield<\/figcaption><\/figure>\n\n\n\n<p>According to PeckShield, the intruder has already transferred 1,000 Ether, worth approximately $2 million, to the authorized <a href=\"https:\/\/coinscreed.com\/staging\/cryptocurrency-mixer-tornado-cash-open-sources-ui-code.html\" target=\"_blank\" rel=\"noreferrer noopener\">cryptocurrency mixer<\/a> Tornado Cash. The blockchain security company also flagged the Aave and Yearn Finance DeFi protocols to inform them of the situation.<\/p>\n\n\n\n<p>After preliminary investigations, the lending platform Yearn Finance announced that the problem was limited to iearn, an obsolete contract before Vaults V1 and V2. Current Yearn Finance contracts and protocols are not affected by the exploit, according to the DeFi protocol.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">We&#39;re looking into an issue with iearn, an outdated contract from before Vaults v1 and v2.<br><br>This problem seems exclusive to iearn and does not impact current Yearn contracts or protocols.<br><br>iearn is an immutable contract predating YFI, it was deprecated in 2020.<br><br>Vaults v1, with\u2026<\/p>&mdash; yearn (@yearnfi) <a href=\"https:\/\/twitter.com\/yearnfi\/status\/1646436798086672385?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">April 13, 2023<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>In the meantime, Aave stated that they are also aware of the transaction. Recently, the liquidity protocol affirmed that the hack had no effect on Aave V1, V2, or V3.<\/p>\n\n\n\n<p>While hacks continue to plague the DeFi industry in 2023, the quantity of money lost due to hacks has decreased compared to prior years. More than $320 million were lost to breaches in the first quarter of 2023, according to the quarterly report of blockchain security firm CertiK.<\/p>\n\n\n\n<p>The losses were significantly less than in the first quarter of 2022, when $1.3 billion was lost, and in the fourth quarter when $950 million was lost to breaches.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In the most recent decentralized finance (DeFi) breach, Blockchain security firm PeckShield detected a hack that allowed the exploiter to mint over 1 quadrillion Yearn Tether (yUSDT). According to the security firm, the intruder then exchanged yUSDT for other stablecoins, allowing them to obtain stablecoins worth $11.6 million. This consists of 61,000 Pax Dollars (USDP), [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":47801,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[11476],"tags":[2156,4650,14161,14162],"class_list":["post-47790","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hacks-and-scams","tag-exploit","tag-yearn-finance","tag-yearn-tether","tag-yusdt"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/04\/image-26.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/47790","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=47790"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/47790\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/47801"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=47790"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=47790"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=47790"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}