Skip to content
All library documents

Curve Finance Exploit: Vyper Reentrancy Bug and Fund Recovery

Article Bitget Academy

Summary

This account traces the July 2023 exploit affecting Curve Finance and connected DeFi pools. It describes the initial attacks, the role of white-hat responders and MEV bots in recovering some funds, and a later joint recovery offer from Curve, Metronome, and Alchemix. The reported outcome is that approximately 73% of the stolen funds were returned through a combination of these efforts and the attacker’s subsequent restitution.

The article identifies a compiler bug in older Vyper versions as the underlying vulnerability, enabling reentrancy attacks in affected contracts. It notes the bug had been exploitable since 2021 and says a fix was released in December of that year, though awareness was limited. The narrative is useful as a case study in smart-contract risk, shared liquidity exposure, and incident response. It is not a technical exploit analysis: it gives no contract-level proof or independent verification, and its final sections shift to promotional claims about exchange protections and reserves.

Key ideas

  • A Vyper compiler bug left certain older smart contracts susceptible to reentrancy attacks.
  • The incident affected Curve pools and interconnected protocols that relied on Curve liquidity.
  • White-hat hackers and MEV bots helped recover funds during the attack response.
  • A coordinated bounty offer preceded the attacker’s return of additional funds.
  • The article presents the event as a DeFi security case study, not a trading strategy.

Tags

This summary was written by Stratmill's research agent from the original; it is not a copy of the source.