{"investigation":{"slug":"curve-finance","entity_name":"Curve Finance","trust_score":62,"severity_base":null,"score_modifier":10,"confidence":0.88,"status":"published","content_type":"investigation","summary":"Curve Finance is a major decentralized exchange (DEX) on Ethereum optimized for stablecoin and pegged-asset trading, operating since January 2020. On July 30, 2023, a latent vulnerability in the Vyper smart-contract compiler (versions 0.2.15, 0.2.16, and 0.3.0) was exploited across multiple Curve liquidity pools, draining approximately $70 million and triggering a near-systemic crisis when the resulting CRV price drop threatened to cascade-liquidate founder Michael Egorov's heavily collateralized on-chain loans. Roughly 73% of stolen funds were ultimately recovered or returned, and in December 2023 the Curve DAO voted to disburse approximately $49 million in compensation to affected liquidity providers.","sections":[{"content":"Curve Finance launched in January 2020 as a decentralized exchange liquidity pool on Ethereum, designed specifically for the low-slippage, low-fee trading of stablecoins and similarly pegged assets. Its automated market maker (AMM) algorithm, StableSwap, was authored by founder Michael Egorov and became widely adopted across DeFi as a primitive for stable-asset liquidity. The protocol is governed by CRV token holders via Curve DAO, and by mid-2023 had accumulated a total value locked (TVL) exceeding $3.2 billion across dozens of pools. In 2023, Curve also launched crvUSD, a native decentralized stablecoin utilizing a novel liquidation mechanism called LLAMMA (Lending-Liquidating AMM Algorithm). Curve smart contracts are written in Vyper, a Python-like language for the Ethereum Virtual Machine.","heading":"Protocol Background","sources":[{"url":"https://www.gemini.com/cryptopedia/curve-finance-liquidity-provider-dao","name":"gemini.com","type":"other","credibility":3},{"url":"https://resources.curve.finance/","name":"resources.curve.finance","type":"other","credibility":3},{"url":"https://www.coindesk.com/markets/2023/07/31/a-curve-founders-168m-stash-is-under-stress-creating-a-risk-for-defi-as-a-whole","name":"coindesk.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The July 2023 exploit did not originate from a flaw in Curve's own Solidity or Vyper code, but from a latent defect in the Vyper compiler itself. Vyper versions 0.2.15, 0.2.16, and 0.3.0 contained a broken implementation of reentrancy locks. In these versions, the compiler allocated a separate, unique storage slot for each @nonreentrant decorator encountered during compilation, even when multiple decorators shared the same lock key. As a result, the bytecode generated for contracts using @nonreentrant guards across multiple functions did not actually share a single lock state, making cross-function reentrancy attacks possible despite the developer's intent. The root cause traces to changes made in v0.2.13 to address an unrelated storage slot collision issue; a subsequent fix in v0.2.15 removed a critical guard that verified whether a given nonreentrant key had already been allocated a storage slot, introducing the vulnerability. The defect went undetected for approximately two years — from July 2021 until its exploitation on July 30, 2023. Vyper v0.3.1 corrected the issue by restoring proper key-based slot deduplication. The official post-mortem was published by the Vyper team on HackMD.","heading":"Vyper Compiler Vulnerability: Technical Root Cause","sources":[{"url":"https://hackmd.io/@vyperlang/HJUgNMhs2","name":"hackmd.io","type":"other","credibility":3},{"url":"https://www.certik.com/resources/blog/2qbPMcyJpR5UfoKrcjWxlQ-vyper-incident-anaylsis","name":"certik.com","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-vyper-bug-hack-july-2023","name":"halborn.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Beginning at approximately 9:30 AM ET on July 30, 2023, attackers exploited the Vyper reentrancy vulnerability across a series of Curve stablepools that had been deployed using affected compiler versions. The attack sequence targeted four pools in rapid succession. JPEG'd's pETH/ETH pool (compiled with Vyper 0.2.15) was drained of approximately $11–12 million. Alchemix's alETH/ETH pool was exploited for approximately $20 million ($17 million in ETH and $3 million in ERC-20 tokens). Metronome DAO's msETH/ETH pool lost approximately $1.6 million. Curve's own CRV/ETH pool was attacked twice, with losses totaling approximately $18–22 million across both exploits. The attack pattern in each case involved the attacker depositing tokens, then exploiting the broken reentrancy lock to re-enter the contract during withdrawal, allowing double-counting of balances before the state was updated. Total initial losses across all pools were reported at approximately $69–73 million by various analysts. Chainalysis confirmed the Vyper compiler versions 0.2.15, 0.2.16, and 0.3.0 as the proximate cause.","heading":"July 30, 2023 Exploit: Attack Sequence and Affected Pools","sources":[{"url":"https://www.chainalysis.com/blog/curve-finance-liquidity-pool-hack/","name":"chainalysis.com","type":"other","credibility":3},{"url":"https://hacken.io/discover/curve-finance-liquidity-pools-hack-explained/","name":"hacken.io","type":"other","credibility":3},{"url":"https://blockworks.com/news/curve-suffers-exploit","name":"blockworks.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/vyper-vulnerability-exposes-defi-ecosystem-stress-tests","name":"cointelegraph.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Several white hat actors and MEV bot operators intervened during and after the attack to front-run malicious transactions and recover funds. The pseudonymous operator c0ffeebabe.eth used MEV arbitrage bots to front-run attackers, recovering approximately $5.3 million from the CRV/ETH pool and approximately $1.6 million from the Metronome msETH pool, subsequently returning both sums to the respective protocols. Alchemix's alETH pool attacker returned approximately $12.7 million (4,820 alETH and 2,258 ETH) voluntarily, and later returned additional amounts such that Alchemix was made fully whole. JPEG'd recovered approximately $10 million. Curve Finance initially offered a 10% bounty (approximately $7 million) to the attackers if funds were returned by August 4, 2023. After the deadline passed without full compliance, Curve opened a public bounty of $1.85 million for information leading to the identification and conviction of any remaining exploiter. One attacker left an on-chain message asserting: 'I'm refunding you not because you can find me, it's because I don't want to ruin your project.' By August 7, 2023, approximately 73% of the stolen funds had been recovered or returned, reducing net losses to approximately $19–27 million.","heading":"White Hat Recovery and Bounty","sources":[{"url":"https://www.coindesk.com/tech/2023/08/07/curve-recoups-73-of-hacked-funds-bolstering-crv-sentiment","name":"coindesk.com","type":"other","credibility":3},{"url":"https://www.theblock.co/post/243464/curve-exploit-identity-bounty","name":"theblock.co","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/curve-hack-mev-bot-behind-61m-heist-begins-returning-funds","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://www.chainalysis.com/blog/curve-finance-liquidity-pool-hack/","name":"chainalysis.com","type":"other","credibility":3}],"severity":"medium"},{"content":"A compounding crisis emerged immediately following the exploit as the CRV token price declined more than 20–30% in response to the hack. Curve Finance founder Michael Egorov had accumulated over $100 million in on-chain debt across multiple DeFi lending protocols, collateralized almost entirely by CRV tokens. His largest exposure was an approximately $63 million USDT loan on Aave V2, backed by approximately 34% of the total CRV supply, with a liquidation threshold of $0.3767 per CRV. Additional positions included a $17–19 million loan on Fraxlend and an approximately $18 million loan on Abracadabra. The Fraxlend position was particularly acute because the platform's interest rate mechanism doubles the APY every 12 hours under stress conditions, creating rapidly escalating liquidation pressure regardless of price action. Risk management firm Gauntlet recommended that Aave DAO freeze CRV markets on Aave V2 to limit contagion. CoinDesk reported that Egorov's concentrated CRV position — representing nearly 47% of the circulating supply across all positions — meant that any forced on-chain liquidation would have dumped enormous CRV supply into an already-falling market, potentially triggering cascading liquidations across Aave, Abracadabra, Fraxlend, and Inverse Finance simultaneously. Over the following days, Egorov conducted approximately $42.4 million in over-the-counter (OTC) sales of CRV tokens at $0.40 per token — a significant discount to market — to reduce debt exposure and stabilize his health factors. The broader DeFi ecosystem narrowly avoided the cascade liquidation scenario.","heading":"Systemic Risk: Michael Egorov's Loan Positions","sources":[{"url":"https://www.coindesk.com/markets/2023/07/31/a-curve-founders-168m-stash-is-under-stress-creating-a-risk-for-defi-as-a-whole","name":"coindesk.com","type":"other","credibility":3},{"url":"https://finance.yahoo.com/news/curve-exploit-curve-founder-michael-081342185.html","name":"finance.yahoo.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2023/08/03/curve-founder-still-owes-80m-despite-raising-nearly-30m-in-past-two-days","name":"coindesk.com","type":"other","credibility":3},{"url":"https://247wallst.com/investing/2023/08/01/curve-founder-sells-40m-in-crv-tokens-amid-liquidation-risk/","name":"247wallst.com","type":"other","credibility":3},{"url":"https://unchainedcrypto.com/curve-founders-liquidation-could-trigger-chaos-for-defi/","name":"unchainedcrypto.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The exploit caused immediate and severe disruption to Curve's metrics. TVL fell from approximately $3.26 billion immediately before the hack to $1.72 billion within 24 hours — a decline of approximately 46%. On-chain data confirmed that over $1.58 billion in crypto assets were withdrawn from Curve Finance in the immediate aftermath. The CRV token price fell by more than 20–30% in the days following the exploit, reaching an intraday low of approximately $0.48. User confidence was broadly shaken, and secondary protocols that relied on CRV as collateral or as a liquidity incentive mechanism were forced to implement emergency risk parameter changes. TechCrunch noted that the incident exposed systemic concentration risks in DeFi, particularly around protocols whose governance tokens serve simultaneously as collateral assets and liquidity gauges.","heading":"Market Impact","sources":[{"url":"https://cryptoslate.com/curve-finance-tvl-halved-following-vyper-vulnerability-exploit/","name":"cryptoslate.com","type":"other","credibility":3},{"url":"https://techcrunch.com/2023/08/01/curve-finances-62m-exploit-exposes-larger-issues-for-defi-ecosystem/","name":"techcrunch.com","type":"other","credibility":3},{"url":"https://blockworks.com/news/curve-suffers-exploit","name":"blockworks.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/tech/2023/08/09/as-curve-averts-defi-death-spiral-fiasco-exposes-serious-risks","name":"coindesk.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following months of deliberation and partial fund recovery, the Curve DAO held a governance vote on victim reimbursement. On December 21, 2023, 94% of participating CRV token holders approved a disbursement of approximately $49.2 million to compensate liquidity providers affected by the July 2023 hack. The compensation covered losses in the Curve CRV pool, Alchemix's alETH pool, JPEG'd's pETH pool, and Metronome's msETH pool. The structure included approximately $7.2 million in ETH recovered by white hats and forwarded to the DAO, distributed in full, plus approximately $42 million in CRV tokens (subject to vesting) to cover the unrecovered portions of losses. The calculation methodology also accounted for missed CRV emissions that affected LPs would have received over the intervening months. Cointelegraph reported that the DAO passed the proposal to disburse the compensation.","heading":"DAO Compensation Vote and Victim Reimbursement","sources":[{"url":"https://cointelegraph.com/news/curve-finance-disburse-49-million-compensation-hack-victims","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://coingape.com/curve-finance-community-approves-49m-payout-for-july-hack-victims/","name":"coingape.com","type":"other","credibility":3},{"url":"https://www.outlookmoney.com/cryptocurrency/sec-regrets-errors-related-to-crypto-firm-enforcement-case-curve-finance-to-disburse-49m-in-compensation-to-hack-victims","name":"outlookmoney.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the exploit, the Curve team and the broader DeFi community undertook a review of Vyper compiler version usage across deployed contracts. Vyper released v0.3.1 containing the reentrancy lock fix, and subsequent audit guidance emphasized verifying compiler versions of legacy deployments rather than only reviewing source code. Curve Finance maintains a public security incident report repository on GitHub at curvefi/security-incident-reports. The protocol's newer pool contracts (StableSwap-NG, TriCrypto-NG) were not affected by the exploit as they were compiled with patched Vyper versions. The incident highlighted a category of supply-chain risk in smart contract development — where auditing source code is insufficient if the compiler itself produces incorrect bytecode — that had been previously underappreciated by the industry. Multiple security researchers, including those at Halborn and CertiK, published post-mortems emphasizing the need to verify bytecode and not rely solely on source-level audits.","heading":"Security Posture and Post-Incident Changes","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-vyper-bug-hack-july-2023","name":"halborn.com","type":"other","credibility":3},{"url":"https://www.certik.com/resources/blog/2qbPMcyJpR5UfoKrcjWxlQ-vyper-incident-anaylsis","name":"certik.com","type":"other","credibility":3},{"url":"https://hackmd.io/@vyperlang/HJUgNMhs2","name":"hackmd.io","type":"other","credibility":3},{"url":"https://github.com/curvefi/security-incident-reports","name":"github.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2020","event":"Curve Finance launches on Ethereum mainnet as a stablecoin-optimized DEX.","source":"","date_original":"2020-01-01"},{"date":"2021-07","event":"Vyper v0.2.15 released, inadvertently introducing the reentrancy lock storage-slot bug that would remain undetected for two years.","source":"","date_original":"2021-07-01"},{"date":"2021-11","event":"Vyper v0.2.16 and v0.3.0 released, perpetuating the reentrancy vulnerability.","source":"","date_original":"2021-11-01"},{"date":"2022","event":"Vyper v0.3.1 released, fixing the reentrancy lock defect — but pools already deployed with earlier versions remain vulnerable.","source":"","date_original":"2022-01-01"},{"date":"2023-07-30","event":"July 30, 2023: Attackers begin exploiting Curve Finance pools compiled with vulnerable Vyper versions. JPEG'd pETH/ETH (~$11M), Alchemix alETH/ETH (~$20M), Metronome msETH/ETH (~$1.6M), and Curve CRV/ETH (~$18-22M) pools are drained. Total losses approximately $69-73 million.","source":""},{"date":"2023-07-31","event":"CRV token price falls over 20%. Curve TVL drops from ~$3.26B to ~$1.72B. Egorov's $100M+ in on-chain loans put at risk of liquidation cascade. Gauntlet recommends Aave DAO freeze CRV markets.","source":""},{"date":"2023-08","event":"Curve Finance offers 10% bounty to exploiters if funds are returned by August 4. c0ffeebabe.eth returns ~$5.3M from CRV/ETH pool and ~$1.6M from Metronome pool.","source":"","date_original":"2023-08-01"},{"date":"2023-08","event":"Michael Egorov conducts approximately $42.4 million in OTC CRV token sales at $0.40/token to reduce loan exposure and avoid cascade liquidation.","source":"","date_original":"2023-08-01"},{"date":"2023-08-04","event":"Bounty deadline passes without full fund return from all exploiters. Alchemix attacker begins returning funds voluntarily.","source":""},{"date":"2023-08-06","event":"Curve Finance opens $1.85 million public bounty for information leading to identification and conviction of remaining exploiters.","source":""},{"date":"2023-08-07","event":"Approximately 73% of stolen funds recovered or returned. Curve DAO receives recovered ETH from white hat operations.","source":""},{"date":"2023-12-21","event":"Curve DAO votes 94% in favor to disburse approximately $49.2 million in compensation to affected liquidity providers across CRV, alETH, pETH, and msETH pools.","source":""}],"sources_used":[{"url":"https://www.gemini.com/cryptopedia/curve-finance-liquidity-provider-dao","name":"gemini.com","type":"other","credibility":3},{"url":"https://resources.curve.finance/","name":"resources.curve.finance","type":"other","credibility":3},{"url":"https://www.coindesk.com/markets/2023/07/31/a-curve-founders-168m-stash-is-under-stress-creating-a-risk-for-defi-as-a-whole","name":"coindesk.com","type":"other","credibility":3},{"url":"https://hackmd.io/@vyperlang/HJUgNMhs2","name":"hackmd.io","type":"other","credibility":3},{"url":"https://www.certik.com/resources/blog/2qbPMcyJpR5UfoKrcjWxlQ-vyper-incident-anaylsis","name":"certik.com","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-vyper-bug-hack-july-2023","name":"halborn.com","type":"other","credibility":3},{"url":"https://www.chainalysis.com/blog/curve-finance-liquidity-pool-hack/","name":"chainalysis.com","type":"other","credibility":3},{"url":"https://hacken.io/discover/curve-finance-liquidity-pools-hack-explained/","name":"hacken.io","type":"other","credibility":3},{"url":"https://blockworks.com/news/curve-suffers-exploit","name":"blockworks.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/vyper-vulnerability-exposes-defi-ecosystem-stress-tests","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/tech/2023/08/07/curve-recoups-73-of-hacked-funds-bolstering-crv-sentiment","name":"coindesk.com","type":"other","credibility":3},{"url":"https://www.theblock.co/post/243464/curve-exploit-identity-bounty","name":"theblock.co","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/curve-hack-mev-bot-behind-61m-heist-begins-returning-funds","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://finance.yahoo.com/news/curve-exploit-curve-founder-michael-081342185.html","name":"finance.yahoo.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2023/08/03/curve-founder-still-owes-80m-despite-raising-nearly-30m-in-past-two-days","name":"coindesk.com","type":"other","credibility":3},{"url":"https://247wallst.com/investing/2023/08/01/curve-founder-sells-40m-in-crv-tokens-amid-liquidation-risk/","name":"247wallst.com","type":"other","credibility":3},{"url":"https://unchainedcrypto.com/curve-founders-liquidation-could-trigger-chaos-for-defi/","name":"unchainedcrypto.com","type":"other","credibility":3},{"url":"https://cryptoslate.com/curve-finance-tvl-halved-following-vyper-vulnerability-exploit/","name":"cryptoslate.com","type":"other","credibility":3},{"url":"https://techcrunch.com/2023/08/01/curve-finances-62m-exploit-exposes-larger-issues-for-defi-ecosystem/","name":"techcrunch.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/tech/2023/08/09/as-curve-averts-defi-death-spiral-fiasco-exposes-serious-risks","name":"coindesk.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/curve-finance-disburse-49-million-compensation-hack-victims","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://coingape.com/curve-finance-community-approves-49m-payout-for-july-hack-victims/","name":"coingape.com","type":"other","credibility":3},{"url":"https://www.outlookmoney.com/cryptocurrency/sec-regrets-errors-related-to-crypto-firm-enforcement-case-curve-finance-to-disburse-49m-in-compensation-to-hack-victims","name":"outlookmoney.com","type":"other","credibility":3},{"url":"https://github.com/curvefi/security-incident-reports","name":"github.com","type":"other","credibility":3}],"source_tags":[],"addresses":[],"reviewed":true,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-30T18:32:22.391019+00:00","updated_at":"2026-08-29T01:35:20.768+00:00"}}