A fraudulent on-chain message targeting Yearn Finance has been identified as part of a phishing scam by the same group responsible for a previous attack on Balancer. The attacker prepared for the exploit 28 days in advance using the Railgun privacy protocol, setting aside a minimal amount of gas (0.0006384 ETH) from addresses 0xFb63aa935Cf0a003335dCE9Cca03c4F9c0fa4779 and 0x011C654467a2f84068325Be2C856c1D07d27f9B7. The attack culminated in the transfer of 1,000 ETH into Tornado Cash, with an initial amount of 1,100 ETH, of which 100 ETH was withdrawn for further exploitation. The total profit from the attack is estimated at approximately $9 million, with remaining funds parked in various addresses. This incident highlights the ongoing threat of sophisticated phishing schemes in the DeFi space, emphasizing the need for heightened vigilance among users and platforms.