Ultimate magazine theme for WordPress.

Curve Finance pools are exploited due to code vulnerabilities

New Updates, 08/08/23: Exploiter Returns Part of Funds, Curve Finance Places Bounty to Identify Them

Less than a week after several liquidity pools on Curve Finance were exploited in a multi-million dollar scheme, the hacker discovered returned 4,820 alETH and 2,258 ETH to Alchemix, worth around $12.7 million. These transactions were accompanied by a encrypted message, in which the hacker wrote: “I've seen some ridiculous views, so I want to make it clear that I'm paying you back the money, not because you can find me, but because I don't want to ruin your project, maybe it's a lot of money. “For many people, but not for me, I'm smarter than all of you. . .” NFT lending protocol JPEG'd also confirmed receipt of the majority of its stolen funds, valued at approximately $10 million.

On August 6, 2023, Curve Finance announced on Twitter that the set deadline for the hacker to voluntarily return the remaining amount had expired. As a result, the company extended its $1.85 million bounty offer to anyone who could uncover the hacker's identity.

Original post: Curve Finance liquidity pool hack analysis

Several liquidity pools were opened on July 30, 2023 Curve financing was exploitedThis resulted in losses of around $70 million and caused panic in the DeFi ecosystem. These hacks occurred due to a vulnerability in Vyper, a third-party Pythonic programming language for Ethereum smart contracts used by Curve and other decentralized protocols. Several since then White hat hackers and MEV bot operators have helped recover some of the funds, meaning the actual loss in value may be lower than the current reported total value. Below we share what we know about the hack so far.

How did the exploit happen?

Vyper's similarity to Python has made it an attractive entry point for developers into the DeFi ecosystem. According to Vyper, versions 0.2.15, 0.2.16 and 0.3.0 contained issues that left some smart contracts vulnerable to reentry attacks, in which attackers can trick the contracts into miscalculating balances, allowing them to steal funds they hold to steal the protocols of the contracts.

The massive hack began with an exploit of the NFT lending protocol JPEG'd's pETH ETH pool for $12 million. However, it appears to have been this attacker led by a MEV botwhich identified the attacker's desired exploit and executed a similar transaction before the original, which may have been a white hat hacking attack.

Soon thereafter, a series of individual attacks occurred other poolsincluding alETH-ETH from Alchemix DAO for $20 million ($17 million in ETH and $3 million in ERC-20), Metronome DAO's sETH-ETH for $1.6 million and Curve's CRV/ETH pool for $18 million. Curve CEO Michael Egorov then confirmed this telegram that $22 million worth of CRV tokens were withdrawn from Curve's swap pool.

MEV bots were heavily involved in frontline hack attempts on Curve, leading to this largest MEV block rewards in the history of Ethereum. In some cases, MEV bot operators acted as white hats and returned funds withdrawn from Curve in advance of malicious transactions, but the extent of this activity is not yet known. One MEV bot operator in particular, c0ffeebabe.eth, was there productive in superficial exploits. This white hat hacker went to the forefront of exploiters and returned funds in previous incidents like this April 2023 error in the SushiSwap router contract. In the case of Curve, c0ffeebabe.eth successfully leveraged around $5.3 million from its CRV/ETH pool and around $1.6 million from its Metronome msETH pool and later returned the funds to both affected protocols .

We can see some of these movements on the Chain analysis reactor Graphic below:

The aftermath of Curve's heroic deed

After news of the hacks broke, CRV fell by 5%. That decline, along with the risk that malicious hackers holding millions worth of CRV could sell into the token's now illiquid market, sparked fears Contagion effects for some DeFi protocols. Credit protocol AAVE, in particular, appears to be at risk of incurring debt due to Egorov's massive and massive indebtedness very famous Loan position secured by CRV token collateral.

At this time, Curve has not yet provided detailed recovery plans deliberate publicly its users the ability to withdraw funds from Vyper-based pools. We have flagged all addresses relevant to the Curve hacks in Chainalysis products and will continue to provide updates on the situation where possible.

This website contains links to third-party websites that are not under the control of Chainalysis, Inc. or its affiliates (collectively, “Chainalysis”). Access to such information does not imply that Chainalysis is associated with, endorses, approves or recommends the website or its operators, and Chainalysis is not responsible for the products, services or other content hosted therein.

This material is for informational purposes only and is not intended as legal, tax, financial or investment advice. Recipients should consult their own advisors before making such decisions. Chainalysis assumes no responsibility or liability for any decisions made or other acts or omissions in connection with the recipient's use of this material.

Chainalysis does not guarantee or warrant the accuracy, completeness, currentness, suitability or validity of the information in this report and assumes no responsibility for any claims attributable to errors, omissions or other inaccuracies in any portion of this material.

Learn Crypto Trading, Yield Farms, Income strategies and more at CrytoAnswers
https://nov.link/cryptoanswers

Comments are closed.

%d bloggers like this: