YieldCore exploited for $382,864 USDC via redeem() vulnerability on April 29; team offers 50% white-hat bounty for return within 72 hours.
Security & Exploits ·
A vulnerability in YieldCore's redeem() function was exploited on April 29, resulting in the loss of 382,864 USDC across seven user accounts. The YieldCore team publicly identified the incident via an onchain message addressed to the exploiter, offering a white-hat bounty equal to 50% of the stolen amount if the remaining funds are returned within 72 hours.
The team set a May 1, 2026 deadline for the return and specified a recovery address for the transfer. The offer represents an attempt to resolve the matter without legal action, though the message indicates that YieldCore is simultaneously engaging blockchain analytics firms and preparing to involve law enforcement. The team noted that the funds had not yet been mixed at the time of the message.
The identity of the exploiter and whether the recovery window will be met remain unknown. No public disclosure of the redeem() vulnerability's technical details has been provided, leaving unclear the precise mechanism by which the theft occurred or whether other YieldCore vaults face similar exposure.