DeFi Intel

Curve Finance Vyper Reentrancy $61M event

Event · PageRank 0.0037

Also known as: Curve Vyper Hack

Overview

On July 30, 2023, several Curve Finance liquidity pools were drained in an incident initially estimated at around $70 million. The root cause was not in Curve's own logic but in a zero-day bug in the Vyper compiler: versions 0.2.15, 0.2.16 and 0.3.0 produced a storage-slot mismatch that broke the non-reentrant lock, leaving affected pools open to reentrancy. Pools belonging to Alchemix, JPEG'd and Metronome were hit alongside Curve's own CRV/ETH pool. Recoveries by white-hat actors and MEV bots later reduced the net loss to roughly $52 million.

Within the DeFi Intel graph, Curve Finance Vyper Reentrancy $61M connects to 1 tracked entity, most strongly to Curve Finance.

Relations

Top connections in the DeFi Intel knowledge graph (confidence-weighted, 1 of 1 total).

RelationConnected entityConfidence
affectedCurve Finance70%

Frequently asked questions

What caused the July 2023 Curve exploit?

A zero-day vulnerability in the Vyper compiler — versions 0.2.15, 0.2.16 and 0.3.0 — that caused a storage-slot mismatch and disabled the reentrancy guard on affected pools.

How much was lost?

Around $70 million initially, later reduced to roughly $52 million after white-hat rescuers and MEV bots returned funds.

Which pools were affected?

Curve's CRV/ETH pool, drained for over $18.5 million, plus JPEG'd's pETH/ETH pool (about $11.5 million) and Metronome's msETH/WETH pool (over $1.6 million), with Alchemix also affected.

Sources

Facts on this page were verified against the following sources.