Curve DAO Tokens Suffer Millions In Hack Ahead Of White Hat Rescue Bid

Share This Post

Curve DAO faced a significant setback as millions of CRV tokens were pilfered just moments before a white hat rescue operation aimed at securing the funds, as revealed by blockchain data and Curve contributor Banteg.

According to a report, approximately 7 million CRV tokens and $14 million worth of wrapped ether (WETH) were lost during the exploit. The breach occurred within the CRV/ETH pool on Curve Finance, a prominent decentralized exchange (DEX) renowned for its streamlined stablecoin trading capabilities. 

The platform features a diverse array of pools that facilitate trading between various tokens, primarily focusing on stablecoins while accommodating other digital assets.

Curve DAO Faces Vulnerability Impacting Multiple Pools

Curve DAO has been struck by a critical vulnerability that has repercussions across various pools, stemming from a bug found in earlier versions of the Vyper programming language. 

“crv/eth pool drained minutes before a white hack operation,” Banteg wrote on Twitter, shedding light on the unfortunate incident.

The Curve DAO situation has drawn security analysts’ attention, with BlockSec revealing that the renowned cryptocurrency exchange, Binance, funded the wallet employed in the attack. This revelation has raised concerns about the potential risks lurking in the DeFi ecosystem.

Vyper, in response to the issue, has identified the specific versions prone to the malfunctioning reentrancy locks—0.2.15, 0.2.16, and 0.3.0. Projects relying on these vulnerable versions have been urged to contact Vyper for further assistance urgently.

Curve DAO Breach: Unveiling The Flaw

As security firm Ancilia probes deeper into the situation, the full scope of the vulnerability comes to light. According to their analysis, many contracts were exposed to potential risks.

Specifically, 136 contracts relied on Vyper 0.2.15 with reentrant protection, 98 contracts were built using Vyper 0.2.16, and 226 contracts employed Vyper 0.3.0.

As the investigation progresses, the root cause of the vulnerability has been unveiled, shedding light on the extent of the risk. Specific versions of the Vyper compiler were found to need proper implementation of the reentrancy guard. 

This critical oversight allows for the simultaneous execution of multiple functions, bypassing the intended locking mechanism in affected contracts. As a result, malicious actors could unleash reentrancy attacks capable of draining all funds from vulnerable contracts.

Meanwhile, Curve DAO (CRV) price is in red in all timeframes, losing nearly 13% in the last 24 hours. In the last week, the token has shed 14% of its value, figures from crypto market tracker Coingecko shows.

Featured image from Bill Hinton/Getty Images

Read Entire Article
spot_img

Related Posts

Paypal Partnership Allows US-Based Moonpay Users to Buy Crypto With Their Paypal Accounts

The digital asset trading platform, Moonpay, announced on May 2 that it had formed a partnership with Paypal This partnership will allow US users to purchase cryptocurrency using their Paypal

Record-Breaking Q1 For Polkadot: Daily Active Addresses Hit 514,000 As DOT Price Surges 7%

According to a Messari report, the Polkadot (DOT) blockchain protocol made significant progress in the first quarter (Q1) of the year in terms of market capitalization, revenue, and Cross-Consensus

Buenos Aires Targets Worldcoin With Eye Scanning Biometric Bill

A bill that seeks to regulate the activities of companies that scan the eyes of their users, like Worldcoin, has been recently introduced in Buenos Aires The law aims to protect the app users’

Shiba Inu Stands Strong: Over 650K Wallet Addresses Still Profitable Amid Recent Price Drop

Shiba Inu (SHIB) has demonstrated resilience despite recent market downturns Data reveals that roughly over 700 trillion SHIB tokens held by more than 650,000 wallet addresses remain profitable,

Memecoins Resurgence? POPCAT And MEW Lead The Way With 20% Surge

As the crypto market settles in on this new phase of the crypto cycle, some memecoins have shown remarkable performance over the last couple of days Cat-theme tokens have significantly grown in

DOJ charges three Cred execs over $783 million in customer fund losses

On May 3, the US DOJ announced charges against former executives of Cred, a bankrupt crypto lending and investing firm Authorities alleged that the three accused individuals — Cred co-owner and
- Advertisement -spot_img