{"investigation":{"slug":"curio","entity_name":"Curio","trust_score":10,"severity_base":null,"score_modifier":0,"confidence":1,"status":"published","content_type":"investigation","summary":"Curio (CurioDAO) is a multi-chain real-world asset (RWA) DeFi protocol that suffered a critical smart contract exploit on March 23, 2024, resulting in approximately $16 million in losses after an attacker exploited a voting-power privilege escalation vulnerability to mint approximately 1 billion unauthorized CGT governance tokens. The protocol had no known third-party security audits prior to the exploit and relied on internal reviews. Curio announced a recovery plan including a new CGT 2.0 token and a phased compensation program, though independent verification of full compensation delivery remains limited.","sections":[{"content":"CurioDAO Association is a multi-chain DeFi platform focused on tokenizing real-world assets (RWAs), including collectible cars, wines, and jewelry. The protocol operates across Ethereum, Binance Smart Chain, Polkadot (Curio Chain), SKALE, and Boba networks. Its flagship product, CurioInvest, allows users to purchase tokens backed by limited-edition collectible cars.\n\nThe protocol's native governance token is CGT (Curio Governance Token), used for voting on protocol decisions via a governance contract derived from MakerDAO's codebase. CurioDAO also seeded sub-DAOs in specific asset verticals, such as FerrariDAO.\n\nCurioInvest was co-founded by Rey Fernando Verboonen, an ETH Zurich graduate with a background in digital assets since 2013, former corporate analyst experience, and an ex-AI startup business lead at a company acquired by Qualcomm. Verboonen is a member of the Forbes Technology Council. The company is incorporated in Switzerland and is supported by Venturelab.","heading":"Background","sources":[{"url":"https://investcurio.medium.com/curiodao-the-future-of-real-assets-2964c789078","name":"","type":"other","credibility":3},{"url":"https://www.venturelab.swiss/Meet-CurioInvest-CEO-Rey-Fernando-Verboonen-and-find-out-how-Wikipedia-helps-him-fall-asleep","name":"","type":"other","credibility":3},{"url":"https://www.crunchbase.com/person/fernando-verboonen","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"On March 23, 2024, CurioDAO's Ethereum-based smart contract was exploited via a critical privilege escalation vulnerability in the protocol's governance (voting power) system. The attack targeted a MakerDAO-derived smart contract at the core of CurioDAO's governance infrastructure.\n\n**Attack Mechanics:**\n\nThe attacker began by acquiring a small quantity of CGT tokens — sufficient to gain a foothold in the governance contract. Using an attack contract, the attacker invoked the `cook` function, which leveraged the `IDSChief` and `IDSPause` contracts — components directly inherited from MakerDAO's governance architecture. By locking these tokens and voting, the attacker gained elevated privileges within the smart contract's permission system.\n\nWith the elevated voting power, the attacker executed the contract's `plot` function, which allowed them to designate a malicious contract as the protocol's exec library. Because the Curio DAO contract allowed `delegatecall` operations to this exec library, the attacker's malicious contract was able to execute arbitrary code with the identity and storage of the Curio DAO contract. This enabled the unauthorized minting of approximately 1 billion CGT tokens.\n\nWeb3 security firm Cyvers characterized the vulnerability as a \"permission access logic vulnerability.\" Hacken's subsequent analysis confirmed the `IDSChief`/`IDSPause` attack vector.\n\n**Financial Impact:**\n\nThe estimated total loss was approximately $16 million. After minting the tokens, the attacker conducted token swaps and cross-chain transfers to obscure the movement of funds. The attacker's address retained approximately 996 billion CGT tokens post-exploit.\n\nOnly Curio's Ethereum operations were affected. Polkadot and Curio Chain contracts were reported as uncompromised.\n\n**Audit Gap:**\n\nMultiple post-mortems and security analyses noted that no known third-party audit of the exploited contracts could be found prior to the incident. Halborn noted that the project relied on internal security reviews rather than external audits. REKT.news similarly reported \"no known audits could be found.\"","heading":"The Exploit","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-curio-hack-march-2024","name":"","type":"other","credibility":3},{"url":"https://rekt.news/curio-rekt","name":"","type":"other","credibility":3},{"url":"https://medium.com/neptune-mutual/analysis-of-the-curio-exploit-1df31252fe66","name":"","type":"other","credibility":3},{"url":"https://cryptonews.com/news/curio-hit-by-16-million-exploit-due-to-voting-power-vulnerability/","name":"","type":"other","credibility":3},{"url":"https://www.cryptotimes.io/2024/03/26/curio-strikes-back-with-cgt-2-0-following-16-million-exploit/","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"On-chain records corroborate the published account of the exploit. The following addresses and transactions have been publicly identified by security researchers:\n\n- **Attacker Address:** `0xdaAa6294C47b5743BDafe0613d1926eE27ae8cf5`\n- **Attack Transaction:** `0x4ff4028b03c3df468197358b99f5160e5709e7fce3884cc8ce818856d058e106`\n\nFollowing the minting, the attacker executed token swaps and conducted cross-chain transfers to obscure the destination of stolen funds. The attacker retained approximately 996 billion minted CGT tokens after the exploit, representing an essentially unlimited inflation of the token supply.\n\nThe on-chain data was compiled and published by security researchers at Hacken and REKT.news. No independent law enforcement seizure or on-chain recovery of funds has been publicly confirmed as of the time of this report.","heading":"On-Chain Evidence","sources":[{"url":"https://rekt.news/curio-rekt","name":"","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-curio-hack-march-2024","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"CurioDAO was co-founded and is led by Rey Fernando Verboonen (CEO, CurioInvest), a Swiss national and ETH Zurich graduate (MSc Business Engineering, BSc Mechatronics). Verboonen has disclosed a background in digital asset investment since 2013, previous roles as a corporate analyst at a CVC PE-owned telecom during its IPO, and as a business lead at an AI startup later acquired by Qualcomm. He is a member of the Forbes Technology Council and has received Swiss Excellence recognition.\n\nThe broader CurioDAO team structure is not extensively documented in public sources. The organization is registered in Switzerland via Curio Capital AG. CurioInvest has been supported by Venturelab, a Swiss startup accelerator.\n\nNo regulatory actions, legal proceedings, or sanctions against team members have been identified in publicly available records as of the time of this report. The team's public communications following the exploit were prompt — a post-mortem was published within two days — though the absence of prior third-party audits represents a significant governance gap.","heading":"Team & Ownership","sources":[{"url":"https://www.venturelab.swiss/Meet-CurioInvest-CEO-Rey-Fernando-Verboonen-and-find-out-how-Wikipedia-helps-him-fall-asleep","name":"","type":"other","credibility":3},{"url":"https://www.crunchbase.com/organization/curio-edc3","name":"","type":"other","credibility":3},{"url":"https://go.curioinvest.com/","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"On March 25, 2024, CurioDAO published a post-mortem and an official recovery strategy. The announced plan included the following components:\n\n**CGT 2.0 Token Launch (within 2 weeks of announcement):**\nA new token, CGT 2.0, was to be issued to replace the compromised CGT token. A pre-exploit snapshot was to be used to determine holder balances, with 100% restoration promised for CGT holders across Ethereum, Binance Smart Chain, SKALE, and Boba networks.\n\n**Liquidity Provider Compensation (four 90-day stages):**\nLiquidity providers impacted by losses in secondary tokens within pools were to receive compensation paid in USDC/USDT. Each stage would deliver 25% of documented losses, with full compensation projected within one year of the exploit.\n\n**Treasury Airdrop:**\nAn airdrop equal to 10% of the CurioDAO Treasury was promised as a bonus to all customers.\n\n**White Hat Bounty:**\nCurio offered 10% of any recovered funds to white hat hackers who assisted in fund recovery.\n\n**Documented Financial Scope:**\nThe team's own post-mortem documented direct losses of approximately $180,000 across networks ($113k Ethereum, $38k BSC, $28k SKALE, $1k Boba), which is substantially lower than the $16 million figure widely cited by external security researchers. This discrepancy may reflect the difference between direct stablecoin/liquidity losses and the market-value impact of the unauthorized token minting.\n\nIndependent verification of whether all four compensation stages have been delivered in full is not available from public sources as of May 2026. No third-party confirmation of completed restitution has been identified.","heading":"Recovery Efforts","sources":[{"url":"https://investcurio.medium.com/curiodaos-recovery-plan-1255427f35de","name":"","type":"other","credibility":3},{"url":"https://www.cryptotimes.io/2024/03/26/curio-strikes-back-with-cgt-2-0-following-16-million-exploit/","name":"","type":"other","credibility":3},{"url":"https://cryptonews.com/news/curio-hit-by-16-million-exploit-due-to-voting-power-vulnerability/","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"**Critical Risks:**\n- The March 2024 exploit demonstrated a fundamental access control failure in a governance contract derived from MakerDAO code. The vulnerability allowed an attacker to gain governance supremacy with a minimal token investment and execute arbitrary contract actions via `delegatecall`.\n- No third-party smart contract audit of the exploited contracts has been identified prior to the incident. Multiple independent security researchers confirmed the absence of any known external audit.\n- The attacker's funds have not been recovered, and no law enforcement action has been publicly confirmed.\n\n**High Risks:**\n- The CGT token supply was catastrophically inflated by approximately 1 billion tokens. Even with a CGT 2.0 replacement, the long-term viability and market credibility of the token are significantly impaired.\n- The discrepancy between the protocol's own loss figures (~$180k) and external researcher estimates (~$16M) has not been publicly reconciled, raising questions about transparency.\n\n**Medium Risks:**\n- Full delivery of the four-stage compensation plan (projected completion within one year of March 2024) has not been independently verified in publicly available sources.\n- The protocol's cross-chain architecture across multiple networks increases its attack surface.\n\n**Mitigating Factors:**\n- The team responded publicly within two days with a post-mortem and compensation plan.\n- Non-Ethereum contracts (Polkadot, Curio Chain) were reported as unaffected.\n- The founding team has publicly verifiable identities and institutional affiliations.\n\n**Overall Assessment:** Curio carries a critical risk rating. The combination of a large, confirmed exploit with no prior external audit, unrecovered funds, and unverified compensation delivery makes this protocol unsuitable for use without substantially more due diligence and confirmation of remediation.","heading":"Risk Assessment","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-curio-hack-march-2024","name":"","type":"other","credibility":3},{"url":"https://rekt.news/curio-rekt","name":"","type":"other","credibility":3},{"url":"https://medium.com/neptune-mutual/analysis-of-the-curio-exploit-1df31252fe66","name":"","type":"other","credibility":3},{"url":"https://investcurio.medium.com/curiodaos-recovery-plan-1255427f35de","name":"","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2024-03-23","event":"Exploit executed on Curio's Ethereum governance contract. Attacker acquires minimal CGT tokens, escalates voting privileges via IDSChief/IDSPause contracts, and mints approximately 1 billion unauthorized CGT tokens. Estimated loss: $16 million.","source":""},{"date":"2024-03-23","event":"CurioDAO Association publicly announces the exploit and halts emergency operations.","source":""},{"date":"2024-03-25","event":"Curio publishes official post-mortem identifying a permission access logic vulnerability in the MakerDAO-derived governance smart contract as the root cause.","source":""},{"date":"2024-03-25","event":"Multiple independent security firms (Hacken, Cyvers, Neptune Mutual, Halborn) publish technical analyses of the exploit, corroborating the attack vector.","source":""},{"date":"2024-03-25","event":"Curio announces recovery plan: CGT 2.0 token launch within 2 weeks, four-stage 90-day LP compensation in USDC/USDT, 10% treasury airdrop, and white hat bounty of 10% of recovered funds.","source":""},{"date":"2024-03-26","event":"Curio announces CGT 2.0 token publicly, pledging 100% restoration for pre-exploit CGT holders across all affected networks.","source":""},{"date":"2025-03-23","event":"Projected completion date of the four-stage, one-year compensation program. Independent verification of full delivery is not available in public sources.","source":""}],"sources_used":[{"url":"https://investcurio.medium.com/curiodao-the-future-of-real-assets-2964c789078","name":"","type":"other","archive_url":"http://web.archive.org/web/20251012072629/https://investcurio.medium.com/curiodao-the-future-of-real-assets-2964c789078","credibility":3,"archive_timestamp":"2025-10-12T07:26:29+00:00"},{"url":"https://www.venturelab.swiss/Meet-CurioInvest-CEO-Rey-Fernando-Verboonen-and-find-out-how-Wikipedia-helps-him-fall-asleep","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-job","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.crunchbase.com/person/fernando-verboonen","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.halborn.com/blog/post/explained-the-curio-hack-march-2024","name":"","type":"other","archive_url":"http://web.archive.org/web/20260609201824/https://www.halborn.com/blog/post/explained-the-curio-hack-march-2024","credibility":3,"archive_timestamp":"2026-06-09T20:18:24+00:00"},{"url":"https://rekt.news/curio-rekt","name":"","type":"other","archive_url":"http://web.archive.org/web/20260313113716/https://rekt.news/curio-rekt","credibility":3,"archive_timestamp":"2026-03-13T11:37:16+00:00"},{"url":"https://medium.com/neptune-mutual/analysis-of-the-curio-exploit-1df31252fe66","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://cryptonews.com/news/curio-hit-by-16-million-exploit-due-to-voting-power-vulnerability/","name":"","type":"other","archive_url":"http://web.archive.org/web/20250905121949/https://cryptonews.com/news/curio-hit-by-16-million-exploit-due-to-voting-power-vulnerability/","credibility":3,"archive_timestamp":"2025-09-05T12:19:49+00:00"},{"url":"https://www.cryptotimes.io/2024/03/26/curio-strikes-back-with-cgt-2-0-following-16-million-exploit/","name":"","type":"other","archive_url":"https://web.archive.org/web/20260829151019/https://www.cryptotimes.io/2024/03/26/curio-strikes-back-with-cgt-2-0-following-16-million-exploit/","credibility":3,"archive_timestamp":"2026-08-29T15:10:19+00:00"},{"url":"https://www.crunchbase.com/organization/curio-edc3","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://go.curioinvest.com/","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:invalid-host-resolution","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://investcurio.medium.com/curiodaos-recovery-plan-1255427f35de","name":"","type":"other","archive_url":"http://web.archive.org/web/20260427094238/https://investcurio.medium.com/curiodaos-recovery-plan-1255427f35de","credibility":3,"archive_timestamp":"2026-04-27T09:42:38+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:34.033577+00:00","updated_at":"2026-09-01T07:15:37.658967+00:00"}}