Markets
BTC— —
ETH— —
SOL— —
XRP— —
BNB— —
ADA— —
DOGE— —
MCap— —
BTC— —
ETH— —
SOL— —
XRP— —
BNB— —
ADA— —
DOGE— —
MCap— —
Markets

Curve Finance Exploit Drains $70 Million as Vyper Reentrancy Bug Threatens Liquidation Cascade

A reentrancy vulnerability in the Vyper compiler drained approximately $70 million from multiple Curve Finance pools on July 30, 2023.

By MiningPool Staff··2 min read
Curve Finance Exploit Drains $70 Million as Vyper Reentrancy Bug Threatens Liquidation Cascade

Key Points

  • A reentrancy vulnerability in the Vyper compiler drained approximately $70 million from multiple Curve Finance pools on July 30, 2023.

A reentrancy vulnerability in the Vyper compiler exploited on July 30, 2023, drained approximately $70 million across multiple Curve Finance pools, exposing both technical fragility in DeFi infrastructure and systemic risks posed by concentrated positions in governance tokens.

The attack targeted stablecoin pools on Curve's platform that relied on vulnerable Vyper versions 0.2.15, 0.2.16, and 0.3.0. The reentrancy bug allowed attackers to execute repeated function calls within a single transaction before state variables updated, draining liquidity pools. Alchemix, JPEG'd, MetronomeDAO, and other protocols had deployed pools using the affected compiler versions. The exploit cascaded across pools throughout the day as attackers refined their attack vectors.

Advertisement

728×90

Curve's CRV token fell more than 20 percent in the immediate aftermath. Broader DeFi markets contracted as risk appetite deteriorated and investors withdrew capital. Curve remained the largest decentralized exchange by total value locked despite the exploit. The attack highlighted a structural vulnerability affecting not just Curve but any protocol using vulnerable Vyper versions.

Curve founder Michael Egorov held a $168 million position in CRV collateralized across Aave, Fraxlend, and other lending protocols. The token's decline pushed his loans toward liquidation thresholds. Aave faced potential cascading liquidations if Egorov's position unwound involuntarily. The concentration of governance tokens in founder hands created counterparty risk that extended beyond Curve itself into the broader DeFi lending market.

Egorov conducted over-the-counter sales of CRV tokens to reduce liquidation risk. He negotiated directly with large holders and DeFi participants, offering discounts on massive blocks of tokens. The OTC market absorbed hundreds of millions of dollars of supply that might otherwise have flooded public markets. The sales succeeded in raising collateral value and reducing liquidation pressure, but left the founder with diminished voting control over Curve's governance.

Whitehat hackers and ethical actors returned portions of stolen funds to affected pools. The recovery rate varied across exploited contracts, with some achieving near-total restoration and others sustaining permanent losses. Curve offered bounties for returned funds and engaged in negotiations with attackers to minimize damage. The incident underscored how DeFi's pseudonymous structure enabled both attack and recovery mechanisms unavailable in traditional finance.

Vyper developers released patched compiler versions addressing the reentrancy vulnerability. The speed of the fix demonstrated mature security response protocols within the Ethereum development community. Protocols began mandatory upgrades to safe Vyper versions. Curve deprecated affected pools and migrated liquidity to patched versions.

The incident revealed tensions between governance decentralization and systemic stability. Egorov's voting control over Curve governance created a moral hazard, as his personal liquidation risk could influence protocol decisions. The exploit demonstrated that concentrated founder positions in governance tokens posed tail risks to broader DeFi lending markets. Later governance discussions included proposals for founder token lockups and voting limits to prevent future concentration scenarios.

MiningPool content is intended for information and educational purposes only and does not constitute financial, investment, or legal advice.

Advertisement

728×90

Related Stories

Buterin Expects Hegotá to Be Ethereum's Last Normal Fork
Tech

Buterin's post puts Ethereum's 2030 target at four to eight second slots and finality in eight to 32 seconds, against 12-second slots and about 13 minutes today. It also has nodes checking a proof instead of re-executing every block.

·MiningPool Staff
Aave Opened a USDC Market Backed by Seven Coinbase Stock Tokens
Markets

The Equities Hub on Base takes tokenized Apple, Microsoft, Nvidia and four other stocks as collateral at 65 to 79 percent, capped at about $29 million, and lends only USDC against them. The market runs continuously while the Chainlink feed pricing that collateral stops publishing from Friday evening until Sunday evening Eastern.

·MiningPool Staff
Bitget Says Its Own Approval Process Released $351.6 Million
Tech

The exchange's security notice declined to name an attack vector, and hours later its chief executive said the attacker spoofed transaction data through a compromised backend system, ruling out private key theft. Withdrawals remain suspended, and the loss is close to 76 percent of the User Protection Fund Bitget says covers it.

·MiningPool Staff
Only Agave Can Run Alpenglow as Solana Starts the Testnet Phase
Tech

Anza is targeting about 150 milliseconds to finality, down from the roughly 12.8 seconds it attributes to TowerBFT, but Firedancer and Frankendancer cannot run the code yet. No mainnet date has been announced, and September 28 is a feature-gate processing date rather than a confirmed Alpenglow launch.

·MiningPool Staff
Robinhood Chain Fees Fell 95% From Their Peak as Deposits Rose
Markets

Network fees on Robinhood's layer-2 fell from $6.04 million on September 4 to $234,819 twelve days later, according to DeFiLlama. Over the same stretch the value held in applications on the chain rose about 15% to a high for the series, and fees have edged back up since the low.

·MiningPool Staff
Solana's Slots Are 250ms Now and Still Run About 16ms Long
Tech

Network-reported block times put the new slots at about 267 milliseconds on average, the same roughly 16-millisecond overhead that sat on top of the 400, 350 and 300 millisecond targets before it. Block limits fell in proportion, so throughput stays at 150 million compute units a second.

·MiningPool Staff

Stay informed

Verifiable crypto journalism, delivered to your inbox.

Weekday mornings. No hype. No financial advice. Just what happened and why it matters.

No spam. Unsubscribe anytime. Read our privacy policy.