• Market Cap: $2,418,160,157,835.35
  • 24h Vol: $108,433,118,919.67
  • BTC Dominance: 56.67%
XBT.Market
Advertisement
  • Home
  • Coins MarketCap
  • Crypto Exchanges
  • Crypto Calculator
  • Top Gainers and Loser
  • News
  • Contact Us
No Result
View All Result
XBT.Market
No Result
View All Result
Home Bitcoin

Curve-Vyper exploit: The whole story so far

Jon Hartney by Jon Hartney
August 4, 2023
in Bitcoin, Blockchain, Business, Market
0
Curve-Vyper exploit: The whole story so far
190
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter

Curve Finance pools were targeted by hackers in a reentrancy attack on July 30, sending shockwaves across the DeFi ecosystem. Cointelegraph compiled the week’s events.

The decentralized finance (DeFi) ecosystem has experienced a challenging week after a seismic security incident led to over $61 million being stolen from Curve Finance’s pools, leaving several protocols facing broader contagion risks.

This attack exposed vulnerabilities across DeFi projects and sparked efforts to recover stolen funds over the past few days.

Related articles

UK Sanctions HTX Over Alleged $1.5 Billion Russia-Linked Crypto Flows

UK Sanctions HTX Over Alleged $1.5 Billion Russia-Linked Crypto Flows

June 17, 2026
Circle Launches cirBTC On Ethereum As New 1:1 Bitcoin-Backed DeFi Asset

Circle Launches cirBTC On Ethereum As New 1:1 Bitcoin-Backed DeFi Asset

June 17, 2026

As the community navigates the aftermath of this exploit, Cointelegraph compiled the week’s events, presenting a timeline of what happened since the hack on July 30.

The hack: Curve Finance pools are exploited for over $61 million due to reentrancy vulnerability

Several stable pools on Curve Finance using the Vyper programming language were exploited on July 30, with losses reaching over $61 million (total losses were initially estimated at $47 million). The vulnerability was found on Vyper’s versions 0.2.15, 0.2.16 and 0.3.0.

Several DeFi projects were affected by the attack. Decentralized exchange (DEX) Ellipsis reported that a small number of stable pools with BNB (BNB) were exploited using an old Vyper compiler. Alchemix’s alETH-ETH also witnessed $13.6 million of outflows due to the attack, along with $11.4 million exploited on JPEGd’s pETH-ETH pool and $1.6 million from Metronome’s sETH-ETH pool. Curve Finance CEO Michael Egorov also confirmed that 32 million Curve DAO (CRV) tokens worth over $22 million had been drained from the swap pool.

Curve’s Michael Egorov confirmed the theft of 32 million Curve DAO tokens on July 30. Source: Telegram/LobsterDAO

The BNB Smart Chain (BSC) was also a victim of copycat attacks due to the same vulnerability, with around $73,000 worth of cryptocurrencies on BSC across three exploits being stolen.

Since news of the exploit broke, white hat and black hat hackers have been duking it out on-chain, attempting to disrupt each others’ exploit attempts or efforts to recover funds.

Preliminary investigations found that some versions of the Vyper compiler did not correctly implement the reentrancy guard, which prevents multiple functions from being executed at the same time by locking a contract.

The impact: Vyper vulnerability exposes DeFi ecosystem to stress tests; CRV price plummets

The security incident exposed DeFi protocols to a stress test in the following days, raising concerns about the impact of the exploit on the crypto ecosystem — in particular, because the vulnerability could place all pools with Wrapped Ether (WETH) at risk of attack.

Vyper is a contract programming language designed for the Ethereum Virtual Machine. It is considered one of the most widely used Web3 programming languages, meaning the bug in three of its versions could threaten several other protocols.

The exploit also led to one of the largest ever maximal extractable value (MEV) reward blocks of 584.05 Ether (ETH). According to Ethereum core developer “eric.eth,” the bot noticed an incoming hack in the mempool, reproduced the transaction and front-ran it. “To do so they pay the block producer a lot of ETH to be front of the line,” he explained. MEV bots can see pending liquidation transactions and front-run them to buy the liquidated assets first at a discount.

Today has produced some of the largest MEV reward blocks in Ethereum’s history.

Slot 6,992,273: 584 ETH
Slot 6,993,342: 345 ETH
Slot 6,992,050: 247 ETH
Slot 6,993,346: 51 ETH

— eric.eth (@econoar) July 30, 2023

Curve’s CEO scurries to pay collateralized loans

Threats elsewhere could also cause ripple effects across DeFi. Curve Finance founder Michael Egorov had around $100 million in loans backed by 47% of the circulating supply of the protocol’s native token, CRV.

However, the CRV price dropped nearly 30% following the hack, falling to a low of $0.48 amid fears that Egorov’s collateralized loans would be liquidated.

To reduce his debt position, Egorov sold 39.25 million CRV tokens to several notable DeFi investors, including Justin Sun, Machi Big Brother and DWF Labs, for a total of $15.8 million. The buyers purchased CRV at $0.40 per token, a 25% discount to the market price at the time. In addition, Egorov made partial payments on two loans on Aave and Frax Finance.

CEX price feed prevents Curve price from collapsing

The CRV token price collapsed on the DeFi market due to the significant draining of several pools; however, it was eventually saved by the centralized exchange (CEX) price feed. The CRV price hit $0.086 on DEXs but traded at $0.60 on CEXs, preventing the token’s price from collapsing to zero. 

The ironic incident drew the attention of Binance CEO Changpeng Zhao, who chuckled at the fact that, in the end, it was a CEX price feed that saved the DeFi protocol.

Also reacting to an uncertain environment, Curve’s native stablecoin, crvUSD, briefly depegged on Aug. 3. The algorithmic stablecoin fell by as much as 0.35% before regaining its peg to the United States dollar. Recently launched, crvUSD uses a mechanism for maintaining its peg called the PegKeeper algorithm, which ensures that the crvUSD value is properly backed by collateral while balancing supply and demand.

DeFi community: Ethical hacker retrieves $5.4M for Curve Finance amid exploit

During the crisis, the DeFi community stood by Curve Finance. On July 31, a white hat hacker managed to retrieve around 2,879 Ether worth around $5.4 million from an exploiter and returned the ETH to Curve Finance. Hours later, another ethical hacker seized almost 3,000 ETH and returned the ETH to Curve’s deployer address.

Amid fears of liquidation surrounding Egorov’s loans, Jun Du, the co-founder of Huobi, purchased 10 million CRV for $4 million from Curve’s CEO. Additionally, Aave Chan founder Marc Zeller proposed the Aave Treasury buy $2 million worth of CRV tokens from the protocol. According to the proposal, the acquisition would signal that DeFi players support the health of the ecosystem. 

What about crvUSD? How does its price react to shock events, does it depeg?

Events of recent days felt similar to SVB/USDC situation in some sense. However, crvUSD had just a 0.35% dip, and currently 0.1% from the peg pic.twitter.com/HaMfbkiFSR

— Curve Finance (@CurveFinance) August 3, 2023

Cross-chain lending platform Abracadabra Money also proposed increasing the interest rate on its outstanding loans to manage risks associated with its exposure to CRV. 

The return of funds: Curve, Metronome and Alchemix offering 10% bug bounty; hacker takes it

On Aug. 3, Curve, Metronome and Alchemix jointly announced an initiative to recover stolen funds from the recent exploits of Curve’s pools. The protocols offered a 10% bounty of the seized funds as a reward, urging those responsible for the exploit to step forward and return the remaining 90%, which would bring the bounty close to $7 million.

The offer came with a guarantee of no further legal actions or involvement of law enforcement. “We want to resolve this in a civilized manner,” the protocols wrote to the hacker.

In less than 24 hours, on Aug. 4, the original attacker for the multimillion-dollar exploit apparently accepted the bounty offer and began returning funds stolen a few days earlier. The hacker sent back 4,820.55 Alchemix ETH (alETH), worth approximately $8,889,118, to the Alchemix Finance team, as well as 1 ETH, approximately $1,844, to the Curve Finance team.

The attacker also posted a message that seems to have been directed at the Alchemix and Curve teams, claiming to be willing to return the funds but only because the person didn’t want to “ruin” the projects involved and not because the attacker was caught.

Message sent by the exploiter to the protocols on Aug. 4. Source: Etherscan

A total of $8.9 million worth of cryptocurrency has been returned at the time of writing, equal to roughly 15% of the total amount drained.

Additional reporting by Amaka Nwaokocha, Ezra Reguerra, Martin Young, Nivesh Rustgi, Prashant Jha, Tom Blackstone, and Zhiyuan Sun.

Read Entire Article
Tags: CointelegraphCryptocurrencyInvestmentMining Bitcoin
Share76Tweet48

Related Posts

UK Sanctions HTX Over Alleged $1.5 Billion Russia-Linked Crypto Flows

UK Sanctions HTX Over Alleged $1.5 Billion Russia-Linked Crypto Flows

by Jon Hartney
June 17, 2026
0

The UK has designated HTX under Russia-related sanctions rules, with TRM Labs linking the exchange to alleged flows connected to...

Circle Launches cirBTC On Ethereum As New 1:1 Bitcoin-Backed DeFi Asset

Circle Launches cirBTC On Ethereum As New 1:1 Bitcoin-Backed DeFi Asset

by Jon Hartney
June 17, 2026
0

Circle has launched cirBTC on Ethereum, entering the wrapped Bitcoin market with a 1:1 backed asset aimed at institutional DeFi

Bipartisan CBDC Ban Deal Would Block Fed Digital Dollar Until 2030

Bipartisan CBDC Ban Deal Would Block Fed Digital Dollar Until 2030

by Jon Hartney
June 17, 2026
0

A bipartisan deal in Congress would block the Federal Reserve from issuing a CBDC until the end of 2030, though...

Illinois Crypto Tax Draws Industry Fire After Pritzker Signs Budget Package

Illinois Crypto Tax Draws Industry Fire After Pritzker Signs Budget Package

by Jon Hartney
June 17, 2026
0

Illinois has signed a budget package containing a new digital asset broker transaction tax, drawing sharp criticism from crypto industry

Standard Chartered Sees Uniswap Rising To $100 By 2030 On RWA Growth

Standard Chartered Sees Uniswap Rising To $100 By 2030 On RWA Growth

by Jon Hartney
June 17, 2026
0

Standard Chartered has reportedly set a long-term $100 target for Uniswap by 2030, tied to rapid growth in tokenized real-world

Load More
  • Trending
  • Comments
  • Latest
SUI Price Hits All-Time High – But Questions About Valuation Remain

SUI Price Hits All-Time High – But Questions About Valuation Remain

October 17, 2024
Solana Targets $160 Resistance As TVL Hits New Yearly Highs

Solana Targets $160 Resistance As TVL Hits New Yearly Highs

October 17, 2024
Dogecoin Holder Base Falls To 6-Month Low, But Analyst Believes DOGE Price Is Headed To $10

Dogecoin Holder Base Falls To 6-Month Low, But Analyst Believes DOGE Price Is Headed To $10

October 17, 2024
Bitcoin Price Holds Firm: Can It Power Toward New Gains?

Bitcoin Price Holds Firm: Can It Power Toward New Gains?

October 17, 2024
All aboard! Elon Musk’s Vegas Loop now taking Dogecoin payments

All aboard! Elon Musk’s Vegas Loop now taking Dogecoin payments

0
Crypto owners banned from working on US Government crypto policies

Crypto owners banned from working on US Government crypto policies

0
Korean startup Uprise lost $20M shorting LUNC

Korean startup Uprise lost $20M shorting LUNC

0
Ethereum testnet Merge mostly successful — ‘Hiccups will not delay the Merge.’

Ethereum testnet Merge mostly successful — ‘Hiccups will not delay the Merge.’

0
UK Sanctions HTX Over Alleged $1.5 Billion Russia-Linked Crypto Flows

UK Sanctions HTX Over Alleged $1.5 Billion Russia-Linked Crypto Flows

June 17, 2026
Circle Launches cirBTC On Ethereum As New 1:1 Bitcoin-Backed DeFi Asset

Circle Launches cirBTC On Ethereum As New 1:1 Bitcoin-Backed DeFi Asset

June 17, 2026
Bipartisan CBDC Ban Deal Would Block Fed Digital Dollar Until 2030

Bipartisan CBDC Ban Deal Would Block Fed Digital Dollar Until 2030

June 17, 2026
Illinois Crypto Tax Draws Industry Fire After Pritzker Signs Budget Package

Illinois Crypto Tax Draws Industry Fire After Pritzker Signs Budget Package

June 17, 2026

XBT.Market

This website is an automated news feed powered by the Nebulome cloud system. The site is made possible by YYC TECH Consulting and Alberta Digital Mining Company. As a team with major crypto and bitcoin enthusiasm, we have curated major sources of news, trading and financial data to bring you, our viewer, an unbiased source of truth.

Recent Posts

  • UK Sanctions HTX Over Alleged $1.5 Billion Russia-Linked Crypto Flows June 17, 2026
  • Circle Launches cirBTC On Ethereum As New 1:1 Bitcoin-Backed DeFi Asset June 17, 2026
  • Bipartisan CBDC Ban Deal Would Block Fed Digital Dollar Until 2030 June 17, 2026
  • Illinois Crypto Tax Draws Industry Fire After Pritzker Signs Budget Package June 17, 2026
  • Standard Chartered Sees Uniswap Rising To $100 By 2030 On RWA Growth June 17, 2026

News Categories

  • Bitcoin
  • Blockchain
  • Business
  • Market
  • Uncategorized

Tags

bitcoinMagzine Cointelegraph Cryptocurrency insidebitcoins Investment Mining Bitcoin NewsBTC

Quicklinks

  • Home
  • Coins MarketCap
  • Crypto Exchanges
  • Crypto Calculator
  • Top Gainers and Loser
  • News
  • Contact Us

© 2022 Xbt.Market - Powered by YYC Tech Consulting & ADMCO.

No Result
View All Result
  • Home
  • Coins MarketCap
  • Crypto Exchanges
  • Crypto Calculator
  • Top Gainers and Loser
  • News
  • Contact Us

© 2022 Xbt.Market by Nebulome.

  • Steakhouse EURCV Morpho VaultSteakhouse EURCV Morpho Vault(STEAKEURCV)$0.000000-100.00%
  • FibSwap DEXFibSwap DEX(FIBO)$0.0084659.90%
  • TruFin Staked APTTruFin Staked APT(TRUAPT)$8.020.00%
  • bitcoinBitcoin(BTC)$84,372.003.58%
  • ethereumEthereum(ETH)$1,885.365.68%
  • tetherTether(USDT)$1.000.00%
  • rippleXRP(XRP)$2.186.84%
  • USDEXUSDEX(USDEX)$1.07-0.53%
  • binancecoinBNB(BNB)$617.995.03%
  • Wrapped SOLWrapped SOL(SOL)$143.66-2.32%
  • solanaSolana(SOL)$128.974.23%
  • usd-coinUSDC(USDC)$1.000.01%
  • dogecoinDogecoin(DOGE)$0.1736117.78%
  • cardanoCardano(ADA)$0.687.61%
  • tronTRON(TRX)$0.2342340.79%
  • staked-etherLido Staked Ether(STETH)$1,884.065.48%
  • Gaj FinanceGaj Finance(GAJ)$0.0059271.46%
  • Content BitcoinContent Bitcoin(CTB)$24.482.55%
  • USD OneUSD One(USD1)$1.000.11%
  • wrapped-bitcoinWrapped Bitcoin(WBTC)$84,309.003.84%
  • ToncoinToncoin(TON)$4.157.66%
  • UGOLD Inc.UGOLD Inc.(UGOLD)$3,042.460.08%
  • ParkcoinParkcoin(KPK)$1.101.76%
  • chainlinkChainlink(LINK)$14.027.76%
  • leo-tokenLEO Token(LEO)$9.211.17%
  • stellarStellar(XLM)$0.2743585.70%
  • avalanche-2Avalanche(AVAX)$19.647.71%
  • Wrapped stETHWrapped stETH(WSTETH)$2,256.395.40%
  • USDSUSDS(USDS)$1.00-0.01%
  • SuiSui(SUI)$2.429.03%
  • shiba-inuShiba Inu(SHIB)$0.0000137.71%
  • hedera-hashgraphHedera(HBAR)$0.17284810.00%
  • Yay StakeStone EtherYay StakeStone Ether(YAYSTONE)$2,671.07-2.84%
  • polkadotPolkadot(DOT)$4.257.34%
  • litecoinLitecoin(LTC)$85.265.04%
  • bitcoin-cashBitcoin Cash(BCH)$314.248.23%
  • mantra-daoMANTRA(OM)$6.301.94%
  • Pundi AIFXPundi AIFX(PUNDIAI)$16.000.00%
  • PengPeng(PENG)$0.60-13.59%
  • Bitget TokenBitget Token(BGB)$4.664.95%
  • wethWETH(WETH)$1,884.285.66%
  • Ethena USDeEthena USDe(USDE)$1.00-0.04%
  • Binance Bridged USDT (BNB Smart Chain)Binance Bridged USDT (BNB Smart Chain)(BSC-USD)$1.00-0.18%
  • MurasakiMurasaki(MURA)$4.23-13.71%
  • Black PhoenixBlack Phoenix(BPX)$3.351,000.00%
  • Pi NetworkPi Network(PI)$0.714.53%
  • HyperliquidHyperliquid(HYPE)$13.729.80%
  • Wrapped eETHWrapped eETH(WEETH)$2,003.675.53%
  • WhiteBIT CoinWhiteBIT Coin(WBT)$28.350.76%
  • moneroMonero(XMR)$217.841.31%
  • Zypto TokenZypto Token(ZYPTO)$0.037139-3.47%
  • uniswapUniswap(UNI)$6.217.66%
  • AptosAptos(APT)$5.395.79%
  • PepePepe(PEPE)$0.00000811.37%
  • daiDai(DAI)$1.00-0.01%
  • nearNEAR Protocol(NEAR)$2.635.26%
  • XT.comXT.com(XT)$3.08-1.65%
  • Layer One XLayer One X(L1X)$23.35454.66%
  • sUSDSsUSDS(SUSDS)$1.050.05%
  • okbOKB(OKB)$48.762.12%
  • gatechain-tokenGate(GT)$22.883.58%
  • crypto-com-chainCronos(CRO)$0.1015853.46%
  • Coinbase Wrapped BTCCoinbase Wrapped BTC(CBBTC)$84,342.003.68%
  • MantleMantle(MNT)$0.814.44%
  • Tokenize XchangeTokenize Xchange(TKX)$33.460.86%
  • internet-computerInternet Computer(ICP)$5.517.85%
  • ethereum-classicEthereum Classic(ETC)$17.074.81%
  • OndoOndo(ONDO)$0.817.47%
  • First Digital USDFirst Digital USD(FDUSD)$1.00-0.12%
  • aaveAave(AAVE)$168.6110.19%
  • Aerarium FiAerarium Fi(AERA)$7.14-13.11%
  • Ethena Staked USDeEthena Staked USDe(SUSDE)$1.170.30%
  • BSCEXBSCEX(BSCX)$237.310.49%
  • Official TrumpOfficial Trump(TRUMP)$10.354.36%
  • vechainVeChain(VET)$0.0233636.04%
  • cosmosCosmos Hub(ATOM)$4.538.09%
  • fantomFantom(FTM)$0.70-1.56%
  • BittensorBittensor(TAO)$231.277.72%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
  • EthenaEthena(ENA)$0.3616194.37%
  • render-tokenRender(RENDER)$3.6710.91%
  • filecoinFilecoin(FIL)$2.927.72%
  • CelestiaCelestia(TIA)$3.181.75%
  • Black AgnusBlack Agnus(FTW)$0.000183423.46%
  • Lombard Staked BTCLombard Staked BTC(LBTC)$84,465.004.02%
  • POL (ex-MATIC)POL (ex-MATIC)(POL)$0.2063993.13%
  • KaspaKaspa(KAS)$0.0682239.38%
  • STAUSTAU(STAU)$0.17397910.95%
  • FasttokenFasttoken(FTN)$4.020.01%
  • Sonic (prev. FTM)Sonic (prev. FTM)(S)$0.5212.98%
  • algorandAlgorand(ALGO)$0.1896979.65%
  • ORA CoinORA Coin(ORA)$4.885.92%
  • ArbitrumArbitrum(ARB)$0.3397526.22%
  • Arbitrum Bridged USDT (Arbitrum)Arbitrum Bridged USDT (Arbitrum)(USDT)$1.000.07%
  • GGTKNGGTKN(GGTKN)$0.1121180.75%
  • kucoin-sharesKuCoin(KCS)$11.231.19%
  • Solv Protocol SolvBTCSolv Protocol SolvBTC(SOLVBTC)$84,076.003.32%
  • fetch-aiArtificial Superintelligence Alliance(FET)$0.4856098.68%
  • optimismOptimism(OP)$0.776.43%
  • StoryStory(IP)$4.75-2.68%