Daily Mail PH

Tuesday, August 1, 2023

[New post] Curve Finance Exploit: $100M Worth of Crypto at Risk, $CRV Drops by 17%

Site logo image Nicholas Say posted: "Curve DAO token lost 17% of its value under a massive attack. A series of exploits targeting DeFi projects in Curve Finance, leaving the platform in a vulnerable position with $100 million worth of cryptocurrency at risk. Curve, one of the most popular" Blockonomi

Curve Finance Exploit: $100M Worth of Crypto at Risk, $CRV Drops by 17%

Nicholas Say

Aug 1

Curve DAO token lost 17% of its value under a massive attack. A series of exploits targeting DeFi projects in Curve Finance, leaving the platform in a vulnerable position with $100 million worth of cryptocurrency at risk.

Curve, one of the most popular decentralized finance (DeFi) protocol, announced a series of CRV pools got exploited due to a smart contract vulnerability called "reentrancy."

The attack targeted factory pool, a model that allows projects or individuals to launch their own liquidity pool through Curve's infrastructure.

"A number of stablepools (alETH/msETH/pETH) using Vyper 0.2.15 have been exploited as a result of a malfunctioning reentrancy lock. We are dealing with the situation and will update the community as things develop," according to Curve Finance's announcement.

Curve's DeFi Projects Exploited

The incident was initiated on Sunday evening with a Curve's liquidity pool (pETH-ETH) reportedly under attack. Up to $11 worth of cryptocurrency was drained from the NFT lending protocol JPEG'd. Shortly after the news broke out, the issue resurfaced on the sETH-ETH pool.

  • Other DeFi projects such as lchemix, Debridge, and Elippsis, reportedly suffered the same exploit. The exploits affected several stablecoin pools (alETH/msETH/pETH) using the Vyper 0.2.15 programming language.
  • According to blockchain security service provider BlockSec, the loss is estimated at approximately $42 million at the writing time and the potential damage potentially makes up to $100 million given the use of Vyper in other projects.
  • However, Vyper says only versions 0.2.15, 0.2.16, and 0.3.0 are at risk when reentrancy prevention is unavailable.
  • BlockSec stated that that reentrancy attack was linked to the use of 'use_eth' and potentially put the WETH-related pools at risk. To mitigate the impact, Mimaklas, a member of the project team, said all affected groups had been liquidated by security experts.
  • A reentrancy issue refers to a vulnerability in smart contracts that can be exploited by malicious actors to drain the contract's funds. Reentrancy occurs when a smart contract function makes an external call to another contract, and the second contract then calls back to the first contract before the first contract has had a chance to update its state.
  • This malicious approach allows the attacker to call the withdraw function repeatedly, even though the contract's balance has already been updated. As a result, the attacker can withdraw the same funds multiple times, effectively draining the contract's balance.

Common Attack

Reentrancy attacks are a common vulnerability in decentralized autonomous organizations (DAOs). These attacks exploit a flaw in the way that DAOs manage their state, allowing an attacker to withdraw funds from the DAO without actually providing any value in return.

There are a number of ways to prevent reentrancy attacks, such as using a mutex to lock the contract's state during an external call or using a refund mechanism to return any funds that were sent to the contract before the state was updated.

The first and most known reentrancy attack was allegedly carried out in 2016 against The DAO, a popular DAO that was hacked for over $50 million worth of Ether.

Since then, there have been a number of other reentrancy attacks, including the one that targeted the Populous smart contract in 2017 and the one that occurred on CREAM Finance in 2021.

Curve DAO token ($CRV) lost more than 17% of its value following the incident. Other altcoins experienced small losses, except Optimisim ($OP). The cryptocurrency has increased 6% in the last 24 hours.

The flagship cryptocurrency Bitcoin had dropped below $29,300 before moving back above $29,400, according to data from CoinMarketCap. While hacks are common, this one looks like it could cost users a lot of money.

While cryptos do offer many advantages, the security side of the market is still being refined. Hacks like this demonstrate that there is still more work to be done.


Unsubscribe to no longer receive posts from Blockonomi.
Change your email settings at manage subscriptions.

Trouble clicking? Copy and paste this URL into your browser:
https://blockonomi.com/curve-finance-exploit-100m-worth-of-crypto-at-risk-crv-drops-by-17/

WordPress.com and Jetpack Logos

Get the Jetpack app to use Reader anywhere, anytime

Follow your favorite sites, save posts to read later, and get real-time notifications for likes and comments.

Download Jetpack on Google Play Download Jetpack from the App Store
WordPress.com on Twitter WordPress.com on Facebook WordPress.com on Instagram WordPress.com on YouTube
WordPress.com Logo and Wordmark title=

Automattic, Inc. - 60 29th St. #343, San Francisco, CA 94110  

at August 01, 2023
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest

No comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments (Atom)

CG BOSS Posts from Gargoyles Reboot thanks to creator kept it alive | CG BOSS Games for 04/26/2026

CG BOSS Blog Post Updates ...

  • [New post] 5 Key Technologies Streamlining the Crypto User Experience
    ...
  • Why is Ninoy Aquino Day important to you? Join Rappler’s chat on August 21!
    Hi daily! Who is Ninoy Aquino to you? What lessons from his life still spea...
  • What do you think about BBM’s 3rd year in office? Join the convos!
    Hi, daily! With the State of the Nation Address (SONA) coming up on July 28...

Search This Blog

  • Home

About Me

Daily Newsletters PH
View my complete profile

Report Abuse

Labels

  • Last Minute Online News

Blog Archive

  • April 2026 (1)
  • February 2026 (1)
  • January 2026 (7)
  • December 2025 (8)
  • November 2025 (4)
  • October 2025 (2)
  • September 2025 (1)
  • August 2025 (2)
  • July 2025 (5)
  • June 2025 (3)
  • May 2025 (2)
  • April 2025 (2)
  • February 2025 (2)
  • December 2024 (1)
  • October 2024 (2)
  • September 2024 (1459)
  • August 2024 (1360)
  • July 2024 (1614)
  • June 2024 (1394)
  • May 2024 (1376)
  • April 2024 (1440)
  • March 2024 (1688)
  • February 2024 (2833)
  • January 2024 (3130)
  • December 2023 (3057)
  • November 2023 (2826)
  • October 2023 (2228)
  • September 2023 (2118)
  • August 2023 (2611)
  • July 2023 (2736)
  • June 2023 (2844)
  • May 2023 (2749)
  • April 2023 (2407)
  • March 2023 (2810)
  • February 2023 (2508)
  • January 2023 (3052)
  • December 2022 (2844)
  • November 2022 (2673)
  • October 2022 (2196)
  • September 2022 (1973)
  • August 2022 (2306)
  • July 2022 (2294)
  • June 2022 (2363)
  • May 2022 (2299)
  • April 2022 (2233)
  • March 2022 (1993)
  • February 2022 (1358)
  • January 2022 (1323)
  • December 2021 (2064)
  • November 2021 (3141)
  • October 2021 (3240)
  • September 2021 (3135)
  • August 2021 (1782)
  • May 2021 (136)
  • April 2021 (294)
Simple theme. Powered by Blogger.