Incident Summary
Published 6/24/2026, 6:08:29 AM
The Yield Yak domain compromise is a high-severity security incident that poses a direct threat of total fund loss for users who interacted with the affected infrastructure. The attack involved the hijacking of a specific subdomain to distribute "Eleven" drainer malware, which is designed to automatically empty connected cryptocurrency wallets.
Incident Summary
On June 24, 2026, the vote.yieldyak.com subdomain was compromised and weaponized [Source: https://www.kucoin.com/news/flash/yield-yak-subdomain-compromised-with-eleven-drainer-malware]. While the primary yieldyak.com domain and the underlying smart contracts (holding over $16.2 million in TVL) appear unaffected, the governance portal was used to target active community members [Source: https://yieldyak.com/].
| Feature | Details |
|---|---|
| Affected URL | vote.yieldyak.com |
| Attack Vector | Subdomain Hijacking / Infrastructure Breach |
| Malware Detected | Eleven Drainer (11 distinct instances) [Source: https://x.com/blockaid_/status/2069630359973539844] |
| Risk Level | High (Direct asset theft) |
| Status | Subdomain flagged as suspicious; users advised to avoid interaction. |
Impact on Users
The compromise is particularly dangerous because it exploits the trust of the Yield Yak brand.
- Wallet Draining: Users visiting the governance site to vote or check proposals were prompted to connect wallets. Once connected, the Eleven drainer malware attempts to execute unauthorized transfers to siphon all supported assets [Source: https://www.kucoin.com/news/flash/yield-yak-subdomain-compromised-with-eleven-drainer-malware].
- Targeted Audience: The attack specifically targets governance participants, who often hold significant amounts of YAK tokens or Liquidity Provider (LP) tokens.
- Scope Limitation: There is currently no evidence that the main yield-generating vaults or the primary website were breached. The risk is localized to the
votesubdomain [Source: https://x.com/blockaid_/status/2069630359973539844].
Security Assessment
The severity is classified as high because the attack was designed for immediate financial theft rather than simple site defacement. Furthermore, Yield Yak currently holds a low security score of 32/100 on CER.live, partly due to the lack of a public token audit, which may heighten user vulnerability during front-end compromises [Source: https://cer.live/token/yield-yak].
Warning: Do not connect your wallet to vote.yieldyak.com until an official "all-clear" is provided by the Yield Yak team via their primary verified channels. If you have interacted with this subdomain recently, you should immediately check your wallet for unauthorized approvals and consider moving funds to a fresh address.
Next Steps:
- Would you like me to perform a technical analysis of the YAK token's price action to see if the market has reacted to this breach?
- I can monitor Yield Yak's official social channels and alert you as soon as they post a formal post-mortem or recovery update.