This morning, Curve Finance said that in addition to several Ethereum pools, an Arbitrum-based liquidity pool may also have been “potentially impacted” over the weekend.
Curve Finance is a popular decentralized exchange (DEX), allowing users to trade similar assets such as Ethereum for Staked Ethereum or Tether's USDT for Circle's USDC. It can be a useful arbitrage tool for many traders when the prices of these assets differ from each other.
Initial reports said the platform was exploited for over $24 million on Sunday. However, blockchain security firm PeckShield has updated the amount stolen to $52 million as the hack is unfolding in real time.
The decentralized exchange team wrote in the tweet that there are three liquidity pools for paired tokens ether (ETH) and Curve governance token CRV, as well as several ERC-20 tokens issued on Alchemix (alETH), Metronome Synth (smETH), and JPEG'd (pETH), were “hacked” due to an “issue in Vyper compiler” versions “.
Vyper is a programming language for writing smart contracts on the Ethereum blockchain. The programming language's core team tweeted this morning that some older versions of the Vyper programming language were vulnerable to exploitation.
PSA: Vyper versions 0.2.15, 0.2.16 and 0.3.0 are vulnerable to incorrect re-entry locks. The investigation is ongoing, but any project based on these versions should contact us immediately.
– Vyper (@vyperlang) July 30, 2023
A lead author of the programming language also took to Twitter and said that the hackers would likely “spend weeks to months trying to find the vulnerability.”
The latest tweet from the Curve team highlighted another domino effect on the Vyper-based liquidity pool when deployed on Layer 2 solution Arbitrum. The team said that Tricrypto, consisting of three tokens: USDC, wBTC and ETH, was “potentially affected.”
The story goes on
The tweet said that while security experts such as auditors and Vyper developers have not yet found a way to perform a “profitable exploit,” the pools remain vulnerable and advised liquidity providers to “leave this one.”
Elsewhere, another BNB chain-based DEX Ellipsis has reported exploitation of stable swap pools on the BNB chain.
A small number of stable pools of BNB using an old Vyper compiler were exploited.
We are assessing the situation and will inform the community of any further findings. https://t.co/pxkhRRSr5w
— Ellipsis (@Ellipsisfi) July 30, 2023
South Korean crypto exchange Upbit announced the temporary suspension of CRV token deposits and withdrawals as a precautionary measure.
“Upbit will continue to monitor this situation and members are advised to pay attention to Curve’s increasing price volatility,” the exchange wrote in the press release.
Learn Crypto Trading, Yield Farms, Income strategies and more at CrytoAnswers
https://nov.link/cryptoanswers
Comments are closed.