Yield Yak Hit by Same Drainer Script Used Against Gitcoin
Blockaid linked a front-end compromise on Yield Yak’s voting subdomain to the same “Eleven drainer” wallet-stealing script used against Gitcoin days earlier. The attacks highlight how subdomain targeting has become DeFi’s most exploited vulnerability, with drainer operators now operating at industrial scale.
