Refreshed 5h ago· updates every 6h

Curve Finance (2023) — Crypto Hack

Partially Recovered
Jul 30, 2023·
Ethereum
Amount Stolen
$61.0M
~33M in various tokens including alETH, msETH, pETH
Recovered
$22.0M
36% of stolen funds

A reentrancy vulnerability in Vyper compiler versions 0.2.15-0.3.0 allowed attackers to drain multiple Curve liquidity pools.

Summary

A reentrancy vulnerability in Vyper compiler versions 0.2.15-0.3.0 allowed attackers to drain multiple Curve liquidity pools.

How It Was Compromised — DeFi via Smart Contract Exploit

DeFiSmart Contract Exploit

Multiple Curve Finance pools built with Vyper versions 0.2.15 through 0.3.0 were found to have a malfunctioning reentrancy lock due to a compiler bug. Attackers exploited this in alETH/ETH, msETH/ETH, and pETH/ETH pools. The Curve team and white-hat hackers worked to front-run remaining vulnerable pools, recovering a significant portion.

Fund Flow & Laundering Analysis

Proceeds split — some attackers cooperated with Curve team and returned funds for a 10% bounty. Remaining stolen ETH moved through Tornado Cash. The Curve DAO treasury was used to partially compensate affected LPs. c0ffeebabe.eth (white-hat) front-ran and returned a substantial amount.

Related Incidents

For educational and transparency purposes only. Not financial advice. Data compiled from public sources and may contain approximations.