--

[SlowMist: Yearn attacked due to mathematical calculation vulnerability in yETH stablecoin pool contract] The SlowMist security team monitored and analyzed the decentralized finance protocol Yearn being attacked by hackers on December 1, resulting in a loss of approximately $9 million. The root cause lies in the unsafe mathematical operations within the _calc_supply function logic of the Yearn yETH weighted stablecoin swap pool contract, leading to overflow and rounding errors during supply calculations. The attacker exploited this flaw to manipulate liquidity to specific values and excessively mint liquidity pool (LP) tokens for illegal profits. SlowMist recommends strengthening boundary scenario testing and adopting securely verified arithmetic mechanisms to prevent similar vulnerabilities.

7 x 24 快訊

更多 >
今天 2025-12-05
03:30

Caldera启动链上扩展计划,ERA代币上线Arbitrum One

03:25

美国9月核心PCE物价指数年率将于今晚23:00公布

03:04

「瞬时飙升」BOB 成交量飙升5倍

02:53

Bitwise CIO:MStrategy 无需出售其比特币持仓

02:53

慢雾:Yearn 遭攻击因 yETH 稳定币池合约数学运算漏洞