Hackers Drain $15 Million From ‘Unreleased’ Yearn Finance Project
A smart contract vulnerability allowed hackers to mint unlimited tokens and sell those for millions of dollars—before returning half the funds to Yearn founder Andre Cronje.
Experimental DeFiDeFi platform Yearn Finance cultists were hit with losses this morning after an unidentified hacker exploited a smart contractsmart contract vulnerability in Eminence, an upcoming gaming project built by Yearn founder Andre Cronje.
The exploit allowed them to mint unlimited new tokens and steal over $15 million in the process. And yet, strangely, they would later return half the stolen crypto.
Known for his “I test in prod” approach—a meme reference to testing in production on the Ethereum mainnet instead of the testnet (as developers usually do)—Cronje teased the project’s logo last night over Twitter.
What followed later was a hallmark crypto move: The lack of information around the project did not stop speculators from rushing in; they purchased over $15 million worth of Eminence’s EMN tokens in under three hours, given its association to Cronje and his reputation as a trusted builder in the crypto space.
Yam Finance, a yield farmers paradise which aggregated $600M in TVL in less than 48 hours, will direct 1% of its future treasury to Gitcoin Grants’s public goods funding upon its forthcoming V3 migration.
Inspired by a community tweet, Gitcoin CEO Kevin Owocki took to the governance forum to propose that Yam’s bountiful treasury, which had previously aggregated $500k in V1 before being lost to a bug, “pass it along” to the Tech Grants category.
It wasn’t obvious that the community would decide...
But then someone who actually read Eminence’s contracts discovered a flaw—a rogue function that would allow the hacker to mint unlimited EMN tokens, burn an equal amount of EMN tokens against another cryptocurrency, and sell that to those rushing in to buy EMN.
Needless to say, the hacker went ahead with the plan.
4/x 7. The exploit itself was a very simple one, mint a lot of EMN at the tight curve, burn the EMN for one of the other currencies, sell the currency for EMN.
But what happened after that wasn’t a hallmark of crypto. The hacker then returned over $8 million of the stolen funds to Cronje’s own deployer contracts, which the developer promptly said would be returned to all those who rushed into buying EMN.
It didn't, however, stop the threats that Cronje allegedly received for the losses suffered by the speculators.
“As I am receiving a fair amount of threats, I have asked to yearn treasury to assist with refunding the 8m the hacker sent. The multisig is safer and as such, I feel more comfortable with them having the funds. Funds will be returned to holders pre-hack snapshot,” said Cronje.
Cryptocurrency was supposed to be anonymous; a way to transfer money without banks and governments. It’s the currency of choice for whistleblowers and privacy advocates. But the promise of secrecy has also enticed countless crypto scammers, thieves and fraudsters, who try to profit at other people’s expense.
And because blockchain is anonymous, their crimes can’t come back to haunt them, they thought. They were dead wrong. An industry of private crypto forensic investigators has sprung up, ofte...
At press time, Cronje said he would continue to develop Eminence in the coming weeks; with a disclaimer this time, “Let me be clear, do not use random contracts I deploy unless I reference it in a Medium article.”
Given some of the responses, let me be clear, do not use random contracts I deploy unless I reference it in a medium article.
The contracts I deployed yesterday were purely for myself to engage with, both GIL and EMN are staging and will not be used.
Digital assets may be firmly in the mainstream, with institutional involvement and a crypto-friendly president in the White House.
But hackers and fraudsters are having a field day so far this year.
Crypto users have lost over $1.7 billion to these groups—already 14% more than 2024’s total losses of $1.49 billion, according to blockchain security firm Immunefi.
In the same period last year, losses totaled $420 million, the firm said.
The report comes amid ongoing concerns about the vulnerabil...
Libre, a regulated real-world asset platform, and the TON Foundation have launched a $500 million tokenized fund on The Open Network, aiming to bring Telegram’s $2.4 billion in corporate debt onto the blockchain for the first time.
Dubbed the Telegram Bond Fund, the product allows institutional and accredited investors to gain exposure to Telegram’s outstanding bonds directly through the TON blockchain, according to a statement shared with Decrypt.
The fund will also participate in future Telegr...
Solana decentralized exchange Raydium has deployed its native token launchpad, which is designed to rival the popular Pump.fun. This comes almost a month after Pump.fun deployed its own decentralized exchange, cutting ties with Raydium in the process.
LaunchLab by Raydium offers a more sophisticated token creation process, compared to Pump.fun’s simplistic approach. The new launchpad allows for deployers to toy with the token supply, how many tokens will be sold on the bonding curve, and how muc...