Breaking: Curve Finance pools exploited in over $24M due to reentrancy vulnerability

Share This Post

Several stable pools on Curve Finance using Vyper were exploited on July 30.

Several stable pools on Curve Finance using Vyper were exploited on July 30, with losses reaching $24 million at the time of writing. According to Vyper, its 0.2.15, 0.2.16 and 0.3.0 versions are vulnerable to malfunctioning reentrancy locks. 

“The investigation is ongoing but any project relying on these versions should immediately reach out to us,” Vyper wrote on X.

According to initial investigation, some versions of the Vyper compiler do not correctly implement the reentrancy guard, which prevents multiple functions from being executed at the same time by locking a contract. Reentrancy attacks can potentially drain all funds from a contract.

A number of decentralized finance projects were affected by the attack. Decentralized exchange Ellipsis reported that a small number of stable pools with BNB were exploited using an old Vyper compiler. Alchemix’s alETH-ETH also witnessed $13.6 million outflow, along with $11.4 million exploited on JPEGd’s pETH-ETH pool, and $1.6 million in Metronome’s sETH-ETH pool.

The exploit sparked panic across the DeFi ecosystem, prompting a wave of transactions across pools and a rescue operation from white hats. Data from CoinMarketCap shows Curve Finance’s utility token Curve DAO (CRV) declining over 5% in reaction to the news. CRV’s liquidity has declined significantly in recent months, making it vulnerable to violent price swings, Cointelegraph reported. According to Curve Finance, crvUSD contracts and any pools with it were not affected by the attack.

Curve DAO token prince on July 30, 2023. Source: CoinMarketCap.

Curve Finance is a DeFi protocol that enables the decentralized exchange (DEX) of stablecoins within Ethereum. The protocol has been targeted by a series of incidents within its ecosystem. Just a few days ago, its omnipool platform Conic Finance was exploited for $3.26 million in Ether (ETH), with nearly the entire amount stolen sent to a new Ethereum address in just one transaction.

Magazine: Should crypto projects ever negotiate with hackers? Probably

Read Entire Article
spot_img

Related Posts

World Bank to Issue CHF Digital Bond Settled Using Swiss Franc Central Bank Digital Currency

The World Bank has announced that it will issue its first CHF digital bond on June 11 This 7-year, CHF 200 million ($219 million) bond is the largest CHF issuance by the World Bank since 2009 It

X To Unleash The Dogecoin Flood? Payments Promise Stirs Community

The Dogecoin army is barking with excitement after an insider hinted at the long-awaited integration of Dogecoin (DOGE) into X Payments, Elon Musk’s social media platform However, a closer look

US Authorities Arrest Chinese Nationals Allegedly Behind Crypto Scam Network

An indictment unsealed in the Central District of California charges two Chinese nationals, Daren Li and Yicheng Zhang, with leading a scheme to launder at least $73 million tied to an international

Shiba Inu Metrics Turn Bullish: Here’s How Many Wallets Stand Between Current Price And $0.000139

Shiba Inu is exhibiting interesting price action as it looks to break above a downward-sloping upper trendline under which it has been trading since the first week of March Currently, SHIB is up by

Russia and Iran Collaborating on Single BRICS Currency, Iranian Ambassador Says

Russia and Iran are collaborating on creating a single BRICS currency, the Iranian ambassador to Russia has claimed He noted that over 60% of the two nations’ bilateral trade is conducted in

Are New Altcoins Listing On Exchanges Like Binance Profitable? This Crypto Researcher Has The Answer

A crypto and macro researcher identified as “Flow” on X (formerly Twitter) has provided a detailed review of the profitability of new altcoins listed on Centralized Exchanges (CEX) such as
- Advertisement -spot_img