Back to dashboard
Sunday, July 30, 2023 at 18:00 UTC

Curve Finance

Vyper compiler bug enabled reentrancy across stable pools.

Partial
Funds stolen
$73.00M
Recovered
$52.00M71%
Still outstanding
$21.00M
Chain
Ethereum
Category
DeFi
Attack vector
Reentrancy
Reported by
PeckShield
Incident ID
h2023-3

Exploit & recovery timeline

  1. Jul 30, 2023 · 16:00 UTC
    Attack preparation

    Attacker wallets funded and staged ahead of the reentrancy exploit against Curve Finance.

  2. Jul 30, 2023 · 18:00 UTC
    Exploit executed

    $73.0M drained from Curve Finance on Ethereum via Reentrancy.

  3. Jul 30, 2023 · 19:00 UTC
    Detected by PeckShield

    PeckShield flagged the anomalous transactions and published an initial alert.

  4. Jul 30, 2023 · 22:00 UTC
    Protocol response

    Curve Finance paused affected contracts or withdrawals and began tracing outbound flows.

  5. Jul 31, 2023 · 18:00 UTC
    Funds traced

    Stolen assets followed through mixers, bridges, and exchange deposit addresses.

  6. Aug 6, 2023 · 18:00 UTC
    Partial recovery

    $52.0M of $73.0M recovered (71%); the remainder is still unaccounted for.

  7. Aug 29, 2023 · 18:00 UTC
    Investigation continues

    Remaining funds monitored across chains with exchange partners notified.