According to an August 2 social media post by a member of the protocol’s governing body, the Curve Finance lending protocol has discontinued the governance token reward for select liquidity pools exposed by the July 30 Curve exploit and the August 6 multichain exploit July were affected.
The termination of the rewards was carried out by the decentralized autonomous emergency organization Curve (Curve E-DAO), a committee composed of selected members of the Curve DAO governing body. According to the announcement, pools for alETH+ETH, msETH-ETH, pETH-ETH, crvCRVETH, Arbitrum Tricrypto, and multibtc3CRV were affected. The decision may be overridden in the future by a full vote of the Curve DAO.
The change was announced by Curve E-DAO member Gabriel Shapiro.
ATTENTION FROM A CURVE E-DAO SIGNER:
@CurveFinance’s emergency multisig has ended CRV rewards (meters) for the liquidity pools affected by the recent exploits, including the pools affected by the recent Vyper compiler exploit and the MultiBTC pool, affected by the recent exploits.
— _gabrielShapir0 (@lex_node) August 2, 2023
On July 6th, over $100 million worth of cryptocurrencies were withdrawn from a series of bridges that were part of the Multichain protocol. The Multichain team stated that the withdrawals were “abnormal” and that users should stop using Multichain. Back then, the Curve team warned its users to “leave multichain assets like multiBTC (including the pool)”, implying that its own multibtc3CRV liquidity pool was at risk from the multichain incident.
On July 14, the Multichain team stated that the withdrawals were caused by an unknown individual who gained access to the CEO’s cloud computing account, suggesting the funds were exploited and may never have been returned become.
On July 30, Curve Finance itself became a victim of a re-entry attack. The exploit lost over $47 million worth of cryptocurrencies. The attack affected the alETH, msETH, and pETH pools as they were created using the Vyper protocol that contained the vulnerability. Other Curve pools not created through Vyper were not affected.
Related: Hackers compromise Uniswap founder’s Twitter account to encourage fraud
Despite these exploits, the affected pools still produced Curve DAO (CRV) governance token rewards. This meant users could continue to deposit their tokens into the pools to earn CRV. In the Aug. 8 announcement, Shapiro explained that the emergency DAO has now removed these rewards to “disincentivize further participation in these compromised pools.”
In July and August, investors continued to suffer from hacks and scams. Payment provider Alphapo reportedly lost over $60 million on July 23 after an attacker gained access to its hot wallet private keys. The company has not confirmed the alleged attack, but experts on the chain have argued that the transmissions are abnormal and likely the result of a hack. On July 25, zkSync was also exploited for $3.4 million due to a read-only reentrancy flaw.
Learn Crypto Trading, Yield Farms, Income strategies and more at CrytoAnswers
https://nov.link/cryptoanswers
Comments are closed.