A bug in a token issued by decentralized finance (DeFi) protocol Yearn Finance was impacted in an exploit this morning, security firm PeckShield tweeted, leading to millions of dollars in losses.
Losses could total over $11 million and occurred on Aave version 1, the data suggested. These were spread over U.S. dollar-pegged stablecoins dai (DAI), tether (USDT), USD Coin (USDC), binance USD (BUSD) and tru USD (TUSD).
Aave V1 was previously thought to be affected by the exploit. However, Aave developers said the protocol was unaffected and merely used to swap tokens to conduct the exploit, which mainly involved Yearn Finance’s yUSD stablecoin.
«We need to clarify that the root cause is due to misconfigured yUSDT, not related to Aave,» PeckShield said in a follow-up tweet following the initial flag.
PeckShield said exploiters were able to mint over 1.2 quadrillion yUSDT in early Asian hours using a $10,000 initial deposit, which was then used to trick the Yearn Finance protocol to eventually cash out millions in stablecoins.
Elsewhere Aave integrations lead Marc Zeller said in a tweet that the impact to the protocol was limited as version 1 was «frozen since Dec 2022.»
«The current size of V1 is $18M, and the current size of the Aave safety module is $382.50M,» Zeller said, adding in a separate tweet that version 2 and version 3 of Aave were not impacted at writing time.