- Liquidity pools on Curve Finance were exploited and almost $47 million was drained from the DeFi protocol.
- A vulnerability in versions 0.2.15, 0.2.16 and 0.3.0 of the Vyper programming language led to the hacks.
- Crypto exchange Binance’s BNB smart chain suffered a similar exploit and the attackers stole $73,000.
- In August 2022, Curve Finance suffered another attack that resulted in a $570,000 loss.
Leading decentralized finance (DeFi) platform Curve Finance has been exploited, and according to blockchain security platform BlockSec, nearly $47 million has been exploited from the platform. A vulnerability in the Vyper programming language was cited as the reason for the hacks. Interestingly, crypto exchange Binance’s BNB Smart Chain also faced a similar exploit.
According to Vyper, versions 0.2.15, 0.2.16, and 0.3.0 of the programming language are vulnerable to buggy re-entry locks. All projects using this programming language have been asked to be careful and contact the Vyper team, including Curve Finance.
PSA: Vyper versions 0.2.15, 0.2.16 and 0.3.0 are vulnerable to buggy reentry locks. The investigation is ongoing, but any project based on these versions should contact us immediately.
— Vyper (@vyperlang) July 30, 2023
“The investigation is ongoing, but any project relying on these versions should contact us immediately,” Vyper explained via social media platform X (formerly known as Twitter). Additionally, according to analysis by security company Ancilia, 136 contracts were using Vyper 0.2.15 with re-entry protection, 98 contracts were using Vyper 0.2.16, and 226 contracts were using Vyper 0.3.0.
Furthermore, Curve Finance also confirmed the exploit through its official X account, stating that a number of stablepools using Vyper 0.2.15, including alETH/msETH/pETHalETH/msETH/pETH, were exploited. Other pools, including crvUSD contracts and all associated pools, are unaffected.
A number of stable pools (alETH/msETH/pETH) using Vyper 0.2.15 were exploited due to a buggy re-entry lock. We are evaluating the situation and will update the community on further developments.
Other pools are safe. https://t.co/eWy2d3cDDj
— Curve Finance (@CurveFinance) July 30, 2023
According to the initial analysis done by many people in the crypto space, some versions of the Vyper compiler do not implement re-entry protection correctly. Therefore, the feature that prevents multiple features from running at the same time by locking a contract does not work. Additionally, reentry attacks can potentially strip all funds from a contract. This is the main reason behind the exploit on Curve Finance.
In addition to Curve Finance, Binance’s BNB Smart Chain was also exploited, and the attacker stole more than $73,000 in cryptocurrencies. Attacks on Ethereum have already surpassed the $41 million mark.
Interestingly, Curve Finance suffered another attack in August 2022, resulting in a loss of $570,000. However, Binance helped the DeFi platform recover nearly $450,000 after the hacker attempted to liquidate the assets. Curve revealed that the problem could possibly be due to a hacking of the domain name server (DNS) provider “iwantmyname”.
ParthDubey
A crypto journalist with over three years experience in DeFi, NFT, Metaverse etc. Parth has worked with major media outlets in the crypto and finance worlds, gaining experience and expertise in crypto culture having weathered bear and bull markets over the years .
Latest news
Learn Crypto Trading, Yield Farms, Income strategies and more at CrytoAnswers
https://nov.link/cryptoanswers
Comments are closed.