YieldCore vault exploited for 382,864 USDC via redeem() vulnerability; team offering 20% white-hat bounty for return within 48 hours.
Security & Exploits ·
YieldCore's team posted an on-chain message on April 29 announcing that its yieldcore-3rd-deal vault had been exploited via a redeem() function vulnerability, resulting in the drainage of 382,864 USDC across seven user accounts. The team offered a 20% white-hat bounty—approximately 76,500 USDC equivalent—to the attacker in exchange for returning the remaining 80% within 48 hours to a specified address.
The exploit appears to have affected a discrete set of users and left the stolen funds unmixed at the time of the message. The team's response involved both financial incentive and stated escalation measures: they indicated they were already working with blockchain analytics firms and preparing to involve law enforcement, framing the bounty as a simpler resolution path than further investigation.
The deadline for the bounty offer was set for April 30, 2026 at 24:00 UTC. It remains unclear whether the attacker engaged with the offer, whether the funds were recovered, or what subsequent steps the team took if the bounty window passed without response.