ChainBleedv0.1 · open intel
← back to feed·MEV2023-07-30 · 2y ago
Incident · SLOWMIST

Curve Finance

Affected by Vyper Vulnerability
Estimated loss
$25.12M
VERDICT —UNRATED
Verdict pending. Auto-ingested incidents are reviewed before a public verdict is rendered.
▰ METHOD
MEV
MEVBYTECODE CATCHABLEAI SCANNABLE
Root cause

Root-cause analysis not yet published. The incident description below contains all currently available signal — review the attack transaction directly for definitive forensics.

▰ PROOF OF CONCEPT
DEFIHACKLABS
src/test/2023-08/CurveBurner_exp.sol
view forked test on github ↗

Reproducible Foundry test fork from SunWeb3Sec/DeFiHackLabs. Clone the repo, run forge test against the file path above, and replay the exploit against a mainnet fork at the historical block. Use for reproduction only — not for live targets.

Forensic narrative

Curve Finance tweeted that many stablecoin pools (alETH/msETH/pETH) using Vyper 0.2.15 were attacked due to a faulty recursive lock. crvUSD contracts and other fund pools are not affected. As of now, the Curve Finance stablecoin pool hack has caused a cumulative loss of $73.5 million to Alchemix, JPEG'd, MetronomeDAO, deBridge, Ellipsis, and CRV/ETH pools. On August 6, Alchemix tweeted that the Curve Finance hacker had returned all of Alchemix's funds in the Curve pool. On August 19, MetronomeDAO stated that a MEV bot named "c0ffeebabe" had recovered most of the stolen funds and returned them to Metronome. Attack method (per SlowMist): Affected by Vyper Vulnerability. Reported loss: $ 25,123,594.

Primary source
https://www.panewslab.com/zh/sqarticledetails/wu339f1f.html
Sourced from
slowmist
Technical record
chain
protocol
Curve Finance
bug_class
mev
date_occurred
2023-07-30
loss_usd
$25,123,594
source_id
sm:curve-finance::2023-07-30
Related — same bug class· mev
2026-05-01
1mo ago
BSC
LBP
BSC token contract exploit (likely LBP bonding-curve manipulation)
mev
$144.9K
UNRATED
2026-01-05
5mo ago
BSC
OLY token holders
Sandwich attack
mev
$63.4K
UNRATED
2025-12-28
5mo ago
BSC
MSCST
Atomic Sandwich Attack
mev
$129.9K
UNRATED
2025-12-04
6mo ago
ETH
US Permissionless Dollar
"CPIMP" proxy front-run
mev
$1.00M
UNRATED
2025-10-25
7mo ago
GMGN
Sandwich Attack
mev
UNRATED
2025-08-13
10mo ago
ETH
Coinbase
MEV composability attack
mev
$300.0K
UNRATED
ChainBleed — live web3 threat intelligence