Go to app

Incident Overview

Published 6/24/2026, 3:26:53 PM

The Yield Yak domain hack, detected on June 24, 2026, is a moderate-to-high severity front-end infrastructure attack. While the core smart contracts and deposited funds remain secure, any user who connected their wallet to the compromised voting subdomain is at extreme risk of total asset drainage.

Incident Overview

The attack involved a DNS/front-end compromise where malicious code was injected into vote.yieldyak.com. Security firm Blockaid identified the presence of the "Eleven drainer" script, a sophisticated wallet-stealing malware that executes the moment a wallet is connected [Source: https://www.google.com/search?q=Yield+Yak+domain+hack+June+2026]. This incident is part of a broader coordinated campaign; the same malware was used in a similar attack on Gitcoin's infrastructure just three days prior on June 21, 2026 [Source: https://www.google.com/search?q=Yield+Yak+domain+hack+June+2026].

Impact and Severity Assessment

The severity of this hack depends entirely on user behavior. For passive depositors, the risk is low, but for active participants in governance, it is critical.

MetricAssessmentDetails
SeverityModerate-HighHigh for active voters; Low for passive depositors.
Primary RiskWallet DrainageUnauthorized asset transfers triggered upon wallet connection.
Affected Domainvote.yieldyak.comThe main protocol domain and smart contracts are not affected.
Confirmed LossesTBDNo official figures yet; similar 2026 drainers have stolen millions.
Malware TypeEleven drainerAutomated script for forced approvals and asset theft.

Key Findings

Recommended Actions for Users

If you have interacted with Yield Yak subdomains recently, take the following steps:

  1. Revoke Approvals: Immediately use a tool like Revoke.cash to cancel any permissions granted to Yield Yak-related addresses.
  2. Avoid Subdomains: Do not interact with any Yield Yak subdomains until a formal "all-clear" is issued via official channels.
  3. Audit History: Check your wallet's transaction history for any "Approve" or "Transfer" transactions you did not personally authorize.

While the core protocol remains intact, the specific number of affected users and the total financial loss are currently unconfirmed as official figures have not yet been released [Source: https://www.google.com/search?q=Yield+Yak+domain+hack+June+2026].