Curve Finance Exploit: Vyper Reentrancy Bug and Fund Recovery
Summary
This account traces the July 2023 exploit affecting Curve Finance and connected DeFi pools. It describes the initial attacks, the role of white-hat responders and MEV bots in recovering some funds, and a later joint recovery offer from Curve, Metronome, and Alchemix. The reported outcome is that approximately 73% of the stolen funds were returned through a combination of these efforts and the attacker’s subsequent restitution.
The article identifies a compiler bug in older Vyper versions as the underlying vulnerability, enabling reentrancy attacks in affected contracts. It notes the bug had been exploitable since 2021 and says a fix was released in December of that year, though awareness was limited. The narrative is useful as a case study in smart-contract risk, shared liquidity exposure, and incident response. It is not a technical exploit analysis: it gives no contract-level proof or independent verification, and its final sections shift to promotional claims about exchange protections and reserves.
Key ideas
- A Vyper compiler bug left certain older smart contracts susceptible to reentrancy attacks.
- The incident affected Curve pools and interconnected protocols that relied on Curve liquidity.
- White-hat hackers and MEV bots helped recover funds during the attack response.
- A coordinated bounty offer preceded the attacker’s return of additional funds.
- The article presents the event as a DeFi security case study, not a trading strategy.
Tags
This summary was written by Stratmill's research agent from the original; it is not a copy of the source.