Vulnerability in Curve Finance’s Vyper code leads to multi-million dollar hacks affecting multiple liquidity pools
Several liquidity pools were opened on July 30, 2023 curve financing was exploitedThis resulted in approximately $70 million in losses and caused panic in the DeFi ecosystem. These hacks occurred because of a vulnerability in Vyper, a third-party Pythonic programming language for Ethereum smart contracts used by Curve and other decentralized protocols. Since then several White hat hacker and MEV bot operators helped recover some of the funds, meaning actual depreciation may be lower than the total reported as of now. Below we share what we know about the hack so far.
How did the exploit come about?
Vyper’s similarity to Python has made it an attractive entry point for developers into the DeFi ecosystem. According to Vyper, versions 0.2.15, 0.2.16 and 0.3.0 contained issues that left some smart contracts vulnerable to re-entry attacks, where attackers can trick the contracts into miscalculating balances, allowing them to steal funds held by them to steal the protocols of the treaties.
The massive hack began with a $12 million exploit of NFT lending protocol JPEG’d’s pETH ETH pool. However, it seems to have been this attacker led by a MEV botwhich identified the attacker’s desired exploit and performed a similar transaction in front of the original in what may have been a white hat hacking attack.
A series of isolated attacks soon followed other poolsincluding Alchemix DAO’s alETH-ETH for $20 million ($17 million in ETH and $3 million in ERC-20), Metronome DAO’s sETH-ETH for $1.6 million, and Curve’s CRV/ETH pool for $18 million. Curve CEO Michael Egorov then confirmed this telegram that $22 million worth of CRV tokens were withdrawn from Curve’s swap pool.
MEV bots have been heavily involved in surface hack attempts on Curve, leading to this biggest MEV block rewards in the history of Ethereum. In some cases, MEV bot operators acted as white hats and returned funds deducted from Curve in advance of malicious transactions, but the extent of this activity is not yet known. One MEV bot operator in particular, c0ffeebabe.eth, was there productive in surface exploits. This white hat hacker has headed exploiters and returned funds in previous incidents like this April 2023 bug in the SushiSwap router contract. In Curve’s case, c0ffeebabe.eth successfully leveraged around $5.3 million from its CRV/ETH pool and around $1.6 million from its Metronome msETH pool, and later returned the funds to both affected protocols .
We can see some of these movements on the chain analysis reactor Graphic below:
The aftermath of Curve’s exploit
After news of the hacks broke, CRV dropped 5%. That drop, along with the risk that malicious hackers holding millions worth of CRV could sell in the token’s now illiquid market, sparked fears Contagion effects for some DeFi protocols. In particular, the AAVE credit protocol appears to be in jeopardy due to Egorov’s massive and massive debt very famous Credit position secured by CRV token collateral.
At this time, Curve has not provided detailed recovery plans publicly advised its users the ability to withdraw funds from Vyper-based pools. We have flagged all addresses relevant to the Curve hacks in Chainalysis products and will continue to provide updates on the situation where possible.
This website contains links to third party websites that are not under the control of Chainalysis, Inc. or its affiliates (collectively, “Chainalysis”). Access to such information does not imply that Chainalysis is affiliated with, endorses, approves, or recommends the Site or its operators, and Chainalysis is not responsible for any products, services, or other content hosted there.
This material is for informational purposes only and is not intended to constitute legal, tax, financial or investment advice. Recipients should consult their own advisors before making such decisions. Chainalysis assumes no responsibility or liability for any decisions made or other acts or omissions related to the recipient’s use of this material.
Chainalysis does not guarantee or warrant the accuracy, completeness, timeliness, suitability, or validity of any information in this report, and accepts no responsibility for any claim arising out of any error, omission, or other inaccuracy in any portion of this material.
Learn Crypto Trading, Yield Farms, Income strategies and more at CrytoAnswers
https://nov.link/cryptoanswers
Comments are closed.