Yield Yak vote subdomain hit by drainer code, Blockaid says

Yield Yak vote subdomain hit by drainer code, Blockaid says

Blockaid linked the compromise at vote.yieldyak.com to a recent Gitcoin subdomain attack, underscoring a broader rise in front-end hacks aimed at crypto users' wallet approvals.

AVAX

Fact Check
The primary source — Blockaid's own alert — directly confirms a front-end attack on yieldyak.com with vote.yieldyak.com hosting Eleven Drainer code, explicitly linking it to a similar Gitcoin subdomain incident the previous day. This matches the claim precisely. Independent outlets (Cryptopolitan, KuCoin, Binance Square, PANews) corroborate the same details, including the link to the Gitcoin attack and the broader trend of front-end hacks targeting wallet approvals.
Summary

Yield Yak's website frontend was compromised through its vote.yieldyak.com subdomain, where Blockaid said it detected code tied to the Eleven drainer toolkit. The security firm said the incident resembled a similar subdomain compromise at Gitcoin days earlier, with both attacks targeting secondary web infrastructure rather than the core application interface. Such drainer scripts are designed to trick users into approving wallet transactions that can transfer assets to attackers, making front-end compromises dangerous even when underlying smart contracts are unchanged. Yield Yak's main product, an auto-compounding yield farming protocol on Avalanche, runs on its primary domain, but users who connected wallets through the affected voting site may have been exposed. No confirmed loss figures had been provided by Blockaid or Yield Yak at the time of publication, and Blockaid urged users not to interact with the affected websites while the issue was investigated and remediated.

Terms & Concepts
  • front-end hacks: Attacks that compromise a project's website or user interface to trick visitors, without necessarily altering the underlying smart contracts.
  • wallet approvals: Permissions users grant to a crypto application or contract, which attackers can abuse if a site is compromised.
  • drainer toolkit: A set of malicious scripts used to induce wallet connections or signatures that let attackers steal digital assets.