{"id":47812,"date":"2023-04-13T11:57:50","date_gmt":"2023-04-13T15:57:50","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=47812"},"modified":"2023-04-13T11:57:52","modified_gmt":"2023-04-13T15:57:52","slug":"over-5-million-exploited-in-recent-defi-hacks-on-aave-and-yearn-finance","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/over-5-million-exploited-in-recent-defi-hacks-on-aave-and-yearn-finance\/","title":{"rendered":"Over $5 million exploited in recent DeFi hacks on Aave and Yearn Finance"},"content":{"rendered":"\n<p>As DeFi hacks continue to plague the cryptocurrency industry, PeckShield, blockchain security firm reports that Aave and Yearn Finance are the latest protocols to be targeted by exploiters. <\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full is-resized\"><img fetchpriority=\"high\" decoding=\"async\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/04\/Hacks.jpg\" alt=\"Over $5 million exploited in recent DeFi hacks on Aave and Yearn Finance\" class=\"wp-image-47815\" width=\"788\" height=\"481\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/04\/Hacks.jpg 900w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/04\/Hacks-300x183.jpg 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/04\/Hacks-768x469.jpg 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/04\/Hacks-750x458.jpg 750w\" sizes=\"(max-width: 788px) 100vw, 788px\" \/><\/figure>\n\n\n\n<p><a href=\"https:\/\/coinscreed.com\/staging\/aave-pro-to-be-launched-this-july-promises-to-support-only-btc-eth-aave-and-usdc.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Aave\u2019s version 1 <\/a>was impacted, while versions 2 and 3 remained unaffected. The oldest version has been frozen since December 2022, and the team behind the lending protocol said it is monitoring the situation. <a href=\"https:\/\/coinscreed.com\/staging\/yearn-finance-creator-andre-cronje-launches-artion-nft-marketplace.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Yearn Finance<\/a> has not provided any details regarding the extent of the exploit.<\/p>\n\n\n\n<p>PeckShield clarified that the root cause is due to <a href=\"https:\/\/twitter.com\/peckshield\/status\/1646411259125063686\" target=\"_blank\" rel=\"noreferrer noopener\">misc<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a><a href=\"https:\/\/twitter.com\/peckshield\/status\/1646411259125063686\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">o<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><a href=\"https:\/\/twitter.com\/peckshield\/status\/1646411259125063686\" target=\"_blank\" rel=\"noreferrer noopener\">nfigured yUSDT<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a>, not related to Aave. \u2018It appears the root cause is due to the misconfigured yUSDT, which is exploited to mint huge yUSDT (1,252,660,242,212,927.5) from a small $10K USDT. The huge yUSDT is then cashed out by swapping to other stablecoins,\u2019 PeckShield said.<\/p>\n\n\n\n<p>\u201cThe exploiter may have made over $10 million in stablecoins DAI, USDC, BUSD, USDT, and TUSD&#8221; according to Lookonchain\u2019s <a href=\"https:\/\/twitter.com\/lookonchain\/status\/1646404007051800576?t=xDrpM4MWQADWc9pcui0k1g&s=35\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">data<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a>.<\/p>\n\n\n\n<p>\u201cAave Chan creator Marc Zeller said the issue is unlikely but not impossible. V1\u2019s current size is $18 million while the Aave safety module stands at $382.50 million.\u201d<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">Aave V1 has been frozen since Dec 2022, so no user can deposit or increase borrow size making issue unlikely but not impossible.<br><br>We&#39;re aware of the situation and research is ongoing. More info when we have more clarity.<\/p>&mdash; Marc \u201d\u4e03\u5341 Billy\u201d Zeller \ud83d\udc7b \ud83e\udd87\ud83d\udd0a (@lemiscate) <a href=\"https:\/\/twitter.com\/lemiscate\/status\/1646401044295892992?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">April 13, 2023<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>This year has seen a surge in stories of hacks and exploits in <a href=\"https:\/\/coinscreed.com\/staging\/defi-protocols-stablecoins-to-be-affected-by-merger.html\">DeFi protocols<\/a>. In March alone, cybercriminals stole $211.5 million worth of cryptocurrencies via 26 attacks. Earlier this week, $3.3 million in ETH was drained from SushiSwap\u2019s approval contract.&#8221;<\/p>\n\n\n\n<p><em>Disclaimer: This is a developing story and will be updated.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>As DeFi hacks continue to plague the cryptocurrency industry, PeckShield, blockchain security firm reports that Aave and Yearn Finance are the latest protocols to be targeted by exploiters. Aave\u2019s version 1 was impacted, while versions 2 and 3 remained unaffected. The oldest version has been frozen since December 2022, and the team behind the lending [&hellip;]<\/p>\n","protected":false},"author":44,"featured_media":47815,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21,73,11476],"tags":[1323,132,197,1496],"class_list":["post-47812","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","category-defi-news","category-hacks-and-scams","tag-blockchain-technology","tag-crypto","tag-defi","tag-hack"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/04\/Hacks.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/47812","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/44"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=47812"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/47812\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/47815"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=47812"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=47812"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=47812"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}