New updates 8/8/23: Exploiter returns part of funds, Curve Finance places bounty to identify them
Less than a week after multiple liquidity pools on Curve Finance were exploited in a multi-million dollar scheme, the hacker discovered returned 4,820 alETH and 2,258 ETH to Alchemix, valued at approximately $12.7 million. These transactions were accompanied by a encrypted message, in which the hacker wrote: “I’ve seen some ridiculous views, so I want to clarify that I’m paying you back the money, not because you can find me, but because I don’t want to ruin your project, maybe it’s a lot of money.” “ For many people, but not for me, I’m smarter than all of you. . .” NFT Credit Protocol JPEG’d also confirmed receipt of the bulk of his stolen funds, valued at around $10 million.
On August 6, 2023, Curve Finance announced on Twitter that the specified period for the voluntary return of the remaining amount by the hacker had expired. So the company extended its $1.85 million bounty offer to anyone who could uncover the hacker’s identity.
Original Post: Analyzing the Curve Finance Liquidity Pool Hack
Several liquidity pools were opened on July 30, 2023 curve financing was exploitedThis resulted in approximately $70 million in losses and caused panic in the DeFi ecosystem. These hacks occurred because of a vulnerability in Vyper, a third-party Pythonic programming language for Ethereum smart contracts used by Curve and other decentralized protocols. Since then several White hat hacker and MEV bot operators helped recover some of the funds, meaning actual depreciation may be lower than the total reported as of now. Below we share what we know about the hack so far.
How did the exploit come about?
Vyper’s similarity to Python has made it an attractive entry point for developers into the DeFi ecosystem. According to Vyper, versions 0.2.15, 0.2.16 and 0.3.0 contained issues that left some smart contracts vulnerable to re-entry attacks, where attackers can trick the contracts into miscalculating balances, allowing them to steal funds held by them to steal the protocols of the treaties.
The massive hack started with a $12 million exploit of NFT lending protocol JPEG’d’s pETH ETH pool. However, it seems to have been this attacker led by a MEV botwhich identified the attacker’s desired exploit and performed a similar transaction in front of the original in what may have been a white hat hacking attack.
A series of isolated attacks soon followed other poolsincluding Alchemix DAO’s alETH-ETH for $20 million ($17 million in ETH and $3 million in ERC-20), Metronome DAO’s sETH-ETH for $1.6 million, and Curve’s CRV/ETH pool for $18 million. Curve CEO Michael Egorov then confirmed this telegram that $22 million worth of CRV tokens were withdrawn from Curve’s swap pool.
MEV bots have been heavily involved in surface hack attempts on Curve, leading to this biggest MEV block rewards in the history of Ethereum. In some cases, MEV bot operators acted as white hats and returned funds deducted from Curve in advance of malicious transactions, but the extent of this activity is not yet known. One MEV bot operator in particular, c0ffeebabe.eth, was there productive in surface exploits. This white hat hacker has headed exploiters and returned funds in previous incidents like this April 2023 bug in the SushiSwap router contract. In Curve’s case, c0ffeebabe.eth successfully leveraged around $5.3 million from its CRV/ETH pool and around $1.6 million from its Metronome msETH pool, and later returned the funds to both affected protocols .
We can see some of these movements on the chain analysis reactor Graphic below:
The aftermath of Curve’s exploit
After news of the hacks broke, CRV dropped 5%. That drop, along with the risk that malicious hackers holding millions worth of CRV could sell in the token’s now illiquid market, sparked fears Contagion effects for some DeFi protocols. In particular, the credit protocol AAVE appears to be at risk of incurring debt due to Egorov’s massive and massive debt very famous Credit position secured by CRV token collateral.
At this time, Curve has not provided detailed recovery plans publicly advised its users the ability to withdraw funds from Vyper-based pools. We have flagged all addresses relevant to the Curve hacks in Chainalysis products and will continue to provide updates on the situation where possible.
This website contains links to third party websites that are not under the control of Chainalysis, Inc. or its affiliates (collectively, “Chainalysis”). Access to such information does not imply that Chainalysis is affiliated with, endorses, approves, or recommends the Site or its operators, and Chainalysis is not responsible for any products, services, or other content hosted there.
This material is for informational purposes only and is not intended to constitute legal, tax, financial or investment advice. Recipients should consult their own advisers before making such decisions. Chainalysis assumes no responsibility or liability for any decisions made or other acts or omissions related to the recipient’s use of this material.
Chainalysis does not guarantee or warrant the accuracy, completeness, timeliness, suitability, or validity of any information in this report, and accepts no responsibility for any claim arising out of any error, omission, or other inaccuracy in any portion of this material.
Learn Crypto Trading, Yield Farms, Income strategies and more at CrytoAnswers
https://nov.link/cryptoanswers
Comments are closed.