Resupply Vault Exploit: Share Inflation, Recovery, and Insurance Pool Disputes
Summary
The document describes a loss at Resupply, a DeFi protocol associated with the Curve ecosystem, and attributes the exploit to an ERC-4626 vault deployment flaw. According to the account, the deployment failed to burn initial shares, enabling an attacker to mint shares at negligible cost, manipulate the vault’s share value, and extract assets. The incident illustrates how initial vault state and share accounting can create exploitable conditions if deployment assumptions are not secured.
The article also covers disputes over responsibility and recovery. OneKey founder Yishi criticized the project’s technical practices, questioned charging an insurance pool for a preventable error, and called on Curve, Convex, and Yearn to help recover user funds. Curve stated that Resupply was not developed by its team while expressing confidence in recovery efforts. The document raises broader questions about protocol accountability, governance transparency, and what kinds of losses insurance pools should cover. It provides no audit report, transaction-level evidence, or independent findings, so its technical and stakeholder claims should be treated as an account of the incident rather than a complete forensic analysis.
Key ideas
- The account attributes the exploit to an ERC-4626 vault deployment that did not burn initial shares.
- The flawed share setup allegedly allowed low-cost share minting, price manipulation, and asset extraction.
- The incident highlights the need to validate vault initialization and share accounting before deployment.
- Stakeholders disagreed over responsibility for user recovery and whether insurance pools should cover preventable technical failures.
- The article reports governance and transparency allegations but does not provide independent forensic evidence.
Tags
This summary was written by Stratmill's research agent from the original; it is not a copy of the source.