Yearn Finance disclosed on February 4, 2021 that its version-one yDAI vault had been exploited and that the attack had been mitigated. A Yearn developer’s event-day estimate put the vault’s loss at approximately 11 million DAI and the attacker’s proceeds at approximately $2.8 million.

The incident mattered because the attacker did not simply find an isolated withdrawal bug. The transaction sequence manipulated conditions in Curve’s 3pool, an external pool containing DAI, USDC and USDT, and then induced Yearn’s strategy to move depositor assets through that distorted market. The episode exposed how risks could propagate across the interconnected protocols that supported decentralized-finance yields.

Those first figures were preliminary. Yearn’s detailed disclosure, published on February 5, refined the estimates to 11 million DAI lost from 35 million DAI of vault deposits, 24 million DAI preserved and an estimated 2.7 million DAI profit for the exploiter.

How the vault was made to accept bad prices

According to Yearn’s reconstruction, the attacker first created an imbalance between the stablecoins in Curve’s 3pool. The attacker then caused the yDAI vault to deposit DAI into that pool while the exchange rate was unfavorable, partially reversed the imbalance and withdrew through the vault under different pool conditions.

Yearn said that pattern was repeated in 11 transactions over 38 minutes. Its representative example described the attacker depositing 134 million USDC and 36 million DAI into 3pool, withdrawing 165 million USDT and repeatedly forcing the vault to move DAI through the imbalanced pool. In one illustrated cycle, 92.3 million DAI returned from a 93 million DAI vault deposit, leaving 0.7 million DAI behind in 3pool.

These large transaction amounts were temporary components of a multi-protocol strategy, not the attacker’s net proceeds. Yearn estimated the attacker’s final profit at 2.7 million DAI. The distinction matters because gross flash-loan and liquidity movements can greatly exceed the economic loss retained after debts and transaction costs are settled.

Yearn identified three contributing conditions: the vault’s slippage protection was set at 1%; its normal 0.5% withdrawal fee had been reduced to zero to facilitate migration to version two; and the version-one vault allowed an external caller to invoke `earn()`, pushing deposits into the strategy.

An emergency control limited the damage

Yearn’s timeline says its security team noticed an unusual transaction pattern at 21:45 UTC on February 4. At 21:48 UTC, the team concluded that the DAI version-one vault was under active attack. Multi-signature wallet participants applied `setMin(0)` to the DAI vault at 21:56 UTC, effectively preventing additional deposits into its strategy.

The same precaution was completed for the version-one USDC, USDT and TUSD vaults at 22:07 UTC. Yearn publicly acknowledged the incident at 22:09 UTC. The team therefore mitigated the identified yDAI path approximately 11 minutes after detecting the suspicious pattern, although Yearn’s later reconstruction found that the attacker’s broader transaction sequence had run for 38 minutes.

What February 4 established

The defensible event-day conclusion was that a legacy Yearn vault had suffered a material loss and that strategy deposits had been disabled while the protocol investigated. The initial announcement did not establish a final depositor reimbursement, insurance recovery or complete technical explanation.

No token-price claim is made here. Contemporaneous reports described movement in YFI after disclosure, but continuous trading across venues and the absence of a specified instrument, venue and measurement window prevent a reliable causal market calculation.

Later context

Yearn’s February 5 postmortem supplied the detailed mechanism and revised DAI-denominated estimates used above. It is later context by one day, not information presented as fully known when Yearn first announced the exploit on February 4.

Primary sourceYearn Security — vulnerability disclosure and incident timeline

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.