Copied


Curve Finance Announces Refund Plan Following $62 Million Hack

Luisa Crawford   Aug 13, 2023 14:00 0 Min Read


Decentralized finance (DeFi) platform Curve Finance has announced its plan to refund users affected by the recent attack that resulted in a loss of $62 million. The incident, which occurred on July 30, 2023, involved a malicious hacker exploiting security vulnerabilities in Curve Finance's Vyper compiler, specifically targeting versions 0.2.15 to 0.3.0.

Exploiting a Security Vulnerability

The attacker's skillful manipulation of these vulnerabilities led to the targeting of pools including CRV/ETH, alETH/ETH, msETH/ETH, and pETH/ETH, as well as three pools on the Layer-2 scaling network Arbitrum. Experts in the field have emphasized that detecting these security vulnerabilities required a significant amount of skill and resources. One contributor to Viper even stated that the attack was likely planned weeks before execution.

Recovery and Refund

According to official posts from Curve Finance's account, ongoing investigations have made progress, and approximately 79% of the funds have been successfully recovered as of August 11, 2023. The platform also announced that it will evaluate each affected user for refunds to ensure the fair distribution of resources.

In a surprising turn of events, 10% of the stolen assets were offered as a reward to the responsible person behind the attack, and upon accepting this offer, the hacker started refunding the funds. According to on-chain data from Etherscan, the total value of the refunded funds reached 4,821 Ethereum, equivalent to approximately $8,891,578.

Impact on Curve Finance

The attack has had a profound impact on Curve Finance. Data from DefiLlama revealed that the total value of assets locked (TVL) on Curve Finance has dropped to its lowest level in two years, standing at $2.83 billion at the time of writing. This represents a 24% drop since the exploit on July 30.

Furthermore, trading volume on Curve totaled $100 million as of August 10, down from $143 million prior to the hack. Activity on one of Curve's leading pools, ETH/stETH LP, has dwindled since the hack, with trading volume reduced around 70% in the last two weeks.


Image source: Shutterstock

Read More
The Hong Kong Monetary Authority has issued a warning about a fraudulent website posing as OCBC Bank (Hong Kong) Limited, urging public vigilance.
BitMEX has changed the Mark Method for NILUSDTH25 and REDUSDTZ25 to Fair Price marking, effective March 25, 2025, enhancing price accuracy.
BitMEX introduces NILUSDT perpetual swaps, offering traders up to 50x leverage. This new listing enhances trading options on the platform.
Bitcoin remains vulnerable to downward pressure due to tight liquidity conditions and weak investor sentiment, with ETF outflows and cautious market behavior persisting.
Vodafone implements AI-driven solutions using LangChain and LangGraph to optimize data operations and improve performance metrics monitoring and information retrieval across its data centers.
BitMEX announces the introduction of NILUSDT perpetual swap listing, offering traders up to 50x leverage. The NIL token will be available for trading starting March 25, 2024.
Cronos (CRO) Labs has appointed Mirko Zhao as its new leader, succeeding Ken Timsit. Zhao aims to enhance the blockchain’s growth and community engagement.
Cronos (CRO) Labs announces Mirko Zhao as the new Head of Product and Engineering, succeeding Ken Timsit, to lead the blockchain ecosystem's innovative growth.