Curve Finance Vyper Reentrancy $61M event
Overview
On July 30, 2023, several Curve Finance liquidity pools were drained in an incident initially estimated at around $70 million. The root cause was not in Curve's own logic but in a zero-day bug in the Vyper compiler: versions 0.2.15, 0.2.16 and 0.3.0 produced a storage-slot mismatch that broke the non-reentrant lock, leaving affected pools open to reentrancy. Pools belonging to Alchemix, JPEG'd and Metronome were hit alongside Curve's own CRV/ETH pool. Recoveries by white-hat actors and MEV bots later reduced the net loss to roughly $52 million.
Within the DeFi Intel graph, Curve Finance Vyper Reentrancy $61M connects to 1 tracked entity, most strongly to Curve Finance.
Relations
Top connections in the DeFi Intel knowledge graph (confidence-weighted, 1 of 1 total).
| Relation | Connected entity | Confidence |
|---|---|---|
affected | Curve Finance | 70% |
Frequently asked questions
What caused the July 2023 Curve exploit?
A zero-day vulnerability in the Vyper compiler — versions 0.2.15, 0.2.16 and 0.3.0 — that caused a storage-slot mismatch and disabled the reentrancy guard on affected pools.
How much was lost?
Around $70 million initially, later reduced to roughly $52 million after white-hat rescuers and MEV bots returned funds.
Which pools were affected?
Curve's CRV/ETH pool, drained for over $18.5 million, plus JPEG'd's pETH/ETH pool (about $11.5 million) and Metronome's msETH/WETH pool (over $1.6 million), with Alchemix also affected.
Sources
Facts on this page were verified against the following sources.