Multiple Stable Pools on Curve Finance Exploited: Losses Reach $24 Million

A recent incident on July 30 has led to the exploitation of several stable pools on Curve Finance, resulting in losses totaling $24 million. The vulnerability has been identified in versions 0.2.15, 0.2.16, and 0.3.0 of the Vyper programming language, used by Curve Finance.

The reentrancy locks in these Vyper versions have been found to be susceptible to malfunctioning, allowing for unauthorized access and potential draining of funds from contracts. Vyper has urged projects relying on these versions to contact them immediately for assistance.

A security firm, Ancilia, has analyzed the affected contracts and revealed that 136 contracts used Vyper 0.2.15 with reentrant protection, 98 contracts used Vyper 0.2.16, and 226 contracts used Vyper 0.3.0.

The impact of this exploit has been significant, affecting several decentralized finance projects. For example, Ellipsis, a decentralized exchange, reported the exploitation of stable pools with BNB using an old Vyper compiler. Alchemix’s alETH-ETH pool witnessed an outflow of $13.6 million, while JPEGd’s pETH-ETH pool lost $11.4 million. Metronome’s sETH-ETH pool also experienced a loss of $1.6 million.

DeFi Ecosystem Panics as Exploits Continue: Curve Finance Under Attack

The recent exploit on Curve Finance’s stable pools has sparked panic in the decentralized finance (DeFi) ecosystem. White hat hackers have initiated a rescue operation, but the incident has triggered a wave of transactions across pools.

The exploit has had a negative impact on Curve Finance’s utility token, Curve DAO (CRV). CoinMarketCap data shows a decline of over 5% in CRV’s value as a reaction to the news. The liquidity of CRV has already been dwindling, exposing it to volatile price swings.

However, it’s worth noting that crvUSD contracts and any pools associated with them were not affected by the attack, according to Curve Finance. This provides some assurance to users and investors holding crvUSD.

Increasing Vulnerabilities in DeFi: The Need for Robust Security Measures

The exploit on Curve Finance is not an isolated incident but part of a growing trend of attacks on DeFi protocols. The De.Fi report indicates that over $204 million was swindled through DeFi hacks and scams in the second quarter of 2023 alone.

