CEX price feed prevents Curve price from collapsing amid $100M vulnerability

Share This Post

A vulnerability in the Vyper programming language widely used by DeFi protocols like Curve Finance led to the exploit of multiple Curve liquidity pools on Sunday, July 30.

Several Curve Finance liquidity pools were attacked on July 30 due to a vulnerability found in the Vyper programming language. Vyper is a contract programming language created for the Ethereum Virtual Machine (EVM).

Curve Finance is one of the key decentralized finance (DeFi) protocols due to its key liquidity services, and the code vulnerability has put nearly $100 million worth of digital assets at risk.

The vulnerability was found in the version 0.2.15, 0.2.16 and 0.3.0, leading to a malfunctioning reentrancy lock. As a result, millions were drained from four Curve pools, namely aETH/ETH, msETH/ETH, pETH/ETH and CRV/ETH. The flaw in three of its variants may have an effect on a number of other protocols.

The price of the native token of Curve Finance (CRV) collapsed on the DeFi market due to the significant draining of several pools; however, it was eventually saved by the centralized exchange price feed. The CRV price hit $0.086 on decentralized exchanges but traded at $0.60 on centralized exchanges (CEXs), preventing the token’s price from collapsing to zero.

Related: Pro-XRP lawyer claims SEC prioritizes corporate capitalism over investors

Curve pools use Chainlink’s oracle system that incorporates several price feeds, including centralized exchanges. If not for the CEX price feed, Curve Finance would have collapsed. This ironic incident drew the attention of Binance CEO Changpeng Zhao, who chuckled at the fact that, in the end, it was a CEX price feed that saved the DeFi protocol.

Zhao noted that the Vyper vulnerability did not impact Binance, as the crypto exchange has updated the code to the latest version. He also reminded everyone of the importance of code library upgrades.

The bug in the earlier versions of the Vyper code is believed to be at least 1.5 years old, and the exploiter is believed to have dug deep in the release history to find an exploitable issue for a large protocol with millions of dollars at stake. A Vyper program contributor on X (Twitter) suggested the amount of time and resources put into the exploit indicates it might be a state-sponsored attack.

Collect this article as an NFT to preserve this moment in history and show your support for independent journalism in the crypto space.

Magazine: Should crypto projects ever negotiate with hackers? Probably

Read Entire Article
spot_img

Related Posts

Mastercard Welcomes 5 Startups to Blockchain and Digital Asset Program

Mastercard’s Start Path Blockchain and Digital Asset program has expanded to include five new startups, aiming to explore innovative uses of blockchain technology “Digital assets are

Financial Nonprofit Better Markets: Approving a Spot Ether ETF Would Threaten ‘the Broader Financial System’

Better Markets, a financial nonprofit organization, has lashed out against approving a spot ether ETF product, stating that it would endanger the broader financial system In a supplemental comment

Mining Rig Producer Canaan’s Q1 Unrealized Gains Narrow Net Loss to $39.4 Million

In the first quarter of 2024, Canaan Inc generated $351 in revenues versus the $724 million in costs incurred in the same period which resulted in the company recording a gross loss of $373 million

Binance Aids Taiwan in Busting $6M Crypto Money Laundering Ring

Binance’s Financial Crimes Compliance Department recently collaborated with Taiwan’s Ministry of Justice Investigation Bureau and the Taipei District Prosecutors Office on a significant

Optimism Network Activity Metrics Approach Record Levels, Propelling OP 9% Higher

Layer 2 (L2) scaling solution Optimism reported a series of strong network metrics in the first quarter (Q1) 2024, with its native OP token surging 9% on the back of this bullish momentum Optimism

Digital Yuan Goes Cross-Border: Hong Kong Unveils e-CNY Wallets For Local Users

In a significant move towards enhancing digital currency use, Hong Kong residents can now set up personal digital yuan or e-CNY wallets, as announced by the Hong Kong Monetary Authority (HKMA) This
- Advertisement -spot_img