Blockaid detected a front-end attack on vote.yieldyak.com serving Eleven drainer code to users.
Security & Exploits ·
Security firm Blockaid detected malicious code injected into the voting subdomain of Yield Yak's website. The compromised vote.yieldyak.com domain was serving Eleven drainer code to visitors, representing a front-end attack against the platform's infrastructure.
The incident mirrors a similar breach reported the previous day affecting another platform. Drainers are designed to trick users into authorizing unauthorized transactions on their blockchain wallets. Yield Yak's team responded by removing the associated DNS record to mitigate further exposure.
It remains unclear how long the malicious code remained active, the number of users potentially affected, or whether any funds were successfully extracted. The scope of the attack and its relation to the Gitcoin incident referenced in the alert have not been fully detailed.