Curve Finance Exploit Puts $100M+ Worth of Crypto at Risk; CRV TokenTumbles
Curve, a stablecoin exchange at the heart of decentralized finance (DeFi) on Ethereum, has been the victim of an exploit according to a tweet from the project.
Upwards of $100 million worth of cryptocurrency are at risk to to a “re-entrancy” bug in Vyper, a programming language used to power parts of the Curve system. Several stablecoin pools on the platform — used for pricing and liquidity on a number of different DeFi services — have been drained by hackers so far.
Other projects that use the Vyper programming language could share the same vulnerability.
It was unclear at press time how much had been drained from Curve as a result of the attack. Blocksec, a blockchain auditing firm, estimated the total losses above $28 million in a preliminary analysis.
The heist destabilized trading markets for Curve DAO’s native CRV token, which was down 17% on the day at a price of $0.61. That price action threatened to compound the chaos by potentially forcing a liquidation on the founder of Curve’s $70 million borrowing position on Aave.
This is a developing story.