On April 13, 2023, an attacker exploited a bug in the legacy iEarn USDT token contract, disrupting several Curve stablecoin pools. Yearn’s official incident update attributed the root cause to the old yUSDT contract and said the defect had persisted across several versions. The episode mattered less as a breach of Yearn’s then-current vault code than as a warning that deprecated, immutable contracts could remain economically connected to active decentralized-finance positions.
PeckShield estimated the damage at $11.6 million in an assessment reported and updated during the morning of April 13. That was a security firm’s contemporaneous estimate, not a final audited loss. The available event-day records did not settle how much belonged to each affected liquidity provider, how much would be recovered or whether every token transfer represented an irrecoverable loss.
What the attacker exploited
The affected yUSDT contract belonged to iEarn, the system that preceded Yearn’s Vaults v1 and v2. Yearn said iEarn predated the YFI governance token, had been deprecated in 2020 and was immutable. Its initial update said the problem appeared exclusive to iEarn and did not affect current Yearn contracts or protocols.
Contemporaneous technical analysis described a configuration error: the yUSDT contract referenced Fulcrum’s iUSDC token where it should have referenced iUSDT. PeckShield and independent researcher samczsun traced the exploit to that mismatch. According to PeckShield’s event-day analysis, the attacker used a $10,000 USDT deposit to mint approximately 1.2 quadrillion yUSDT, then exchanged the inflated balance through liquidity pools for other stablecoins.
Those quantities describe token accounting during the exploit, not the creation of 1.2 quadrillion genuine dollars. The yUSDT units were claims generated by the faulty contract; their extraction value depended on the real assets available in connected pools.
The blast radius crossed protocol labels
Yearn’s later April 13 update said the bug contributed to the draining of Curve’s y, BUSD and PAX pools. It also added an important qualification: although current Yearn v2 Vault contracts were not themselves exploited, users of v2 and legacy v1 vaults that packaged affected pool tokens could still suffer losses. “Current code unaffected” therefore did not mean “no current user exposure.”
Aave appeared in early descriptions because the transaction sequence used Aave V1. Aave said that version was not impacted, and PeckShield clarified that the root cause was the misconfigured yUSDT contract rather than Aave. The distinction is material: composable DeFi transactions can pass through several protocols without every protocol in the path containing the vulnerability.
Why April 13 changed the security record
The exploit demonstrated the long tail of immutable infrastructure. Deprecation can end development and user promotion, but it cannot delete autonomous code or automatically unwind every liquidity position built around it. A legacy contract can remain callable, and pool tokens representing its assets can remain embedded in newer products.
That made dependency mapping as important as version labels. A narrow bug in an old token adapter propagated into multiple pools and downstream vault positions because those systems accepted one another’s assets. The verified record supports the occurrence, affected legacy contract and basic mechanism. The $11.6 million figure should remain labeled an initial estimate until a complete address-level reconciliation or formal postmortem establishes a final loss.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

