YearnFinance V1 TUSD Vault Exploited, ~$300K Lost
A legacy version of YearnFinance was exploited on Wednesday when a TUSD vault in the V1 deployment was drained for roughly $300,000, according to a post by security firm PeckShield. The affected contract is part of a deprecated V1 codebase that still holds user funds despite being superseded by newer releases.
The breach has renewed concerns over immutable smart contracts and the challenges of retiring legacy code; once deployed, misconfigured contracts can remain vulnerable long after teams move on. The incident underscores the importance of careful migration, ongoing monitoring, and explicit decommissioning strategies for old deployments to prevent future losses and protect users.