Moderate risk — pioneered yield vaults and holds $560M, but repeated legacy code exploits and admin key risk undermine confidence
Risk Breakdown
Top Risks
1
Four separate exploits confirmed: $11M DAI vault (Feb 2021), $9M yETH (Dec 2025), $300K TUSD (2025), and a March 2026 legacy v1 vault drain of ~$290K — establishing a persistent pattern of legacy code exploitation on Yearn infrastructure
2
Controller/strategist key can connect vaults to arbitrary strategies, enabling fund drainage with no user warning period
3
Multi-strategy vault composition increases attack surface — each additional strategy adds a potential exploit vector
Frequently Asked Questions
Is Yearn Finance safe to use?
Yearn Finance receives a C+ risk grade (38/100) from Hindenrank, where lower scores indicate lower risk. Moderate risk — pioneered yield vaults and holds $560M, but repeated legacy code exploits and admin key risk undermine confidence The original DeFi yield aggregator that automatically invests your deposits across lending and trading protocols to maximize returns. It manages $560M in deposits. Its C grade reflects four separate hacks across its history -- including two in 2025 targeting old vault code -- and the risk that a compromised admin key could redirect all vault funds instantly.
What are the main risks of using Yearn Finance?
The key risks identified for Yearn Finance are: (1) Four separate hacks have hit Yearn vaults, including a $9M exploit in December 2025 and a $11M exploit in 2021 -- old code keeps getting attacked (2) An admin key holder can attach a new strategy to any vault at any time with no delay -- if that key gets stolen, vault funds can be drained instantly (3) Your deposits are spread across other DeFi protocols like Aave and Curve -- if any of those get hacked, your Yearn vault takes the loss
What is Yearn Finance's risk score breakdown?
Yearn Finance scores 38/100 across eight risk dimensions: Mechanism Novelty: 2/15, Interaction Severity: 8/20, Oracle Surface: 0/10, Documentation Gaps: 3/10, Track Record: 13/15, Scale Exposure: 5/10, Regulatory Risk: 2/10, Vitality Risk: 5/10. The highest risk area is Track Record at 13/15.
How does Yearn Finance compare to other Yield protocols?
Among 116 rated Yield protocols on Hindenrank, Yearn Finance ranks #68 by safety (lowest risk score = safest). Its 38/100 risk score and C+ grade place it in the middle tier of Yield protocols.
Has Yearn Finance ever been hacked or exploited?
Yearn Finance scores 13/15 on the Track Record risk dimension, indicating some history of security incidents or exploits. Higher scores reflect more severe or frequent incidents. Review the full risk report for details.
Incident History
6incidents|$43Mtotal losses
Last scanned 2026-03-21
Get risk alerts before it's too late
Weekly grade changes, downgrade alerts, and new protocol risk findings. Free.