Markets
BTC— —
ETH— —
SOL— —
XRP— —
BNB— —
ADA— —
DOGE— —
MCap— —
BTC— —
ETH— —
SOL— —
XRP— —
BNB— —
ADA— —
DOGE— —
MCap— —
Markets

Curve Finance Exploit Triggers Liquidation Cascade as Vyper Vulnerability Drains $70M

A Vyper compiler bug allows attackers to drain $70M from Curve pools, sending CRV plummeting 30% and triggering margin calls on Curve founder Michael Egorov's positions.

By Oliver Bradford··2 min read
Curve Finance Exploit Triggers Liquidation Cascade as Vyper Vulnerability Drains $70M

Key Points

  • A Vyper compiler bug allows attackers to drain $70M from Curve pools, sending CRV plummeting 30% and triggering margin calls on Curve founder Michael Egorov's positions.

Attackers exploited a zero-day vulnerability in the Vyper programming language on Sunday, draining roughly $70 million from Curve Finance's liquidity pools in a single coordinated assault. The CRV token plunged 29% in hours, falling to $0.48 as liquidation fears gripped the market. Multiple stablecoins holding CRV as collateral faced cascading margin calls across DeFi protocols.

The vulnerability lay in Vyper versions 0.2.15, 0.2.16, and 0.3.0, which contained faulty reentrancy guards. The `@nonreentrant` decorator — meant to prevent recursive calls to the same function — used a single shared storage offset for all protected functions instead of individual keys. Attackers repeatedly called the same function within a single transaction, bypassing the guard's assumptions about transaction linearity. The CRV/ETH pool alone was hit twice for over $18.5 million.

Curve's core team responded within hours, pausing deposits across affected pools and triggering emergency circuit breakers. Some of the fund recovery involved whitehat hackers who grabbed assets before attackers could, meaning the actual user losses are probably closer to $50 million rather than $70 million. Still, the damage rippled instantly through DeFi. Fraxlend, Aave, and Abracadabra all held material CRV positions as collateral, and the sudden price move exposed founder Michael Egorov's overleveraged position to liquidation risk.

Advertisement

728×90

Egorov had borrowed over $100 million against roughly 460 million CRV tokens — approximately 47% of the circulating supply. At $0.48, his debt was catastrophically underwater. The liquidation would trigger additional CRV selling pressure, worsening the cascade. By August 3, Egorov was frantically raising capital through over-the-counter sales, moving 25 million tokens to Wintermute Trading for $10 million across two separate transactions in a race against forced liquidation.

Other CRV holders with collateralized loans faced similar pressure. Lending protocols began marking CRV as a higher-risk collateral, automatically trimming the amount borrowers could lend against it. These "haircuts" came in real-time as oracle prices updated. Across DeFi, roughly $100 million in liquidations cascaded through Frax, Abracadabra, and Aave within 48 hours.

The incident exposed a methodological failure in Vyper's compiler team. The vulnerability existed since version 0.2.15 in May 2023 — nearly three months before discovery. Any project relying on those versions faced retroactive exposure. Vyper issued an urgent advisory urging developers to recompile and redeploy. The message carried an implicit warning: you didn't know which of your contracts were compromised until you looked.

Curve's response prevented the contagion from metastasizing into a full protocol cascade. Other exchanges and lending platforms with Vyper dependencies rushed to audit their code and patch vulnerable contracts. By late 2023, the incident became a case study in why single points of failure in developer tooling — a compiler bug affects the entire ecosystem simultaneously — pose systemic risk that no amount of protocol-level safeguards can fully absorb.

---

**Word count: 445**

MiningPool content is intended for information and educational purposes only and does not constitute financial, investment, or legal advice.

Advertisement

728×90

Related Stories

Drift's Recovery Pool Pays About a Cent on Every Dollar Lost
Markets

The Drift Foundation issued one DFX token for each verified dollar taken in April's exploit, and the pool behind those 299.5 million tokens holds about $3.11 million. Tether and other partners have pledged up to $147.5 million more, none of which has arrived.

·MiningPool Staff
NEAR Intents Says an Omni Bridge Bug Cost It About $3.8 Million
Markets

The protocol halted services, patched the contract-side flaw and promised to compensate users in full, naming eleven networks whose deposits and withdrawals would stay down for another 12 hours. Investigators who traced the outflows do not agree on where the money went.

·MiningPool Staff
Aave Opened a USDC Market Backed by Seven Coinbase Stock Tokens
Markets

The Equities Hub on Base takes tokenized Apple, Microsoft, Nvidia and four other stocks as collateral at 65 to 79 percent, capped at about $29 million, and lends only USDC against them. The market runs continuously while the Chainlink feed pricing that collateral stops publishing from Friday evening until Sunday evening Eastern.

·MiningPool Staff
Robinhood Chain Fees Fell 95% From Their Peak as Deposits Rose
Markets

Network fees on Robinhood's layer-2 fell from $6.04 million on September 4 to $234,819 twelve days later, according to DeFiLlama. Over the same stretch the value held in applications on the chain rose about 15% to a high for the series, and fees have edged back up since the low.

·MiningPool Staff

Stay informed

Verifiable crypto journalism, delivered to your inbox.

Weekday mornings. No hype. No financial advice. Just what happened and why it matters.

No spam. Unsubscribe anytime. Read our privacy policy.