On July 30–31, 2023, Curve Finance disclosed that several of its early ETH-based stable pools – including alETH/ETH, msETH/ETH, and pETH/ETH – had been exploited due to a bug in the Vyper smart contract compiler’s reentrancy protection. The affected pools were built with Vyper 0.2.15 (and related vulnerable versions 0.2.16 and 0.3.0), whose malfunctioning nonreentrant lock allowed attackers to repeatedly reenter liquidity functions and drain funds despite nominal reentrancy guards. Curve stated publicly that these specific pools using pure ETH were compromised while “other pools are safe,” and began assessing losses and exposure across the protocol. Subsequent on-chain and forensic analyses linked this incident to a broader vulnerability window in Vyper, introduced between mid‑2021 compiler releases, that left contracts compiled with versions 0.2.15–0.3.0 open to reentrancy when making raw calls to untrusted contracts. Multiple Curve pools and integrated protocols (including Alchemix and JPEG’d) suffered cumulative losses on the order of tens of millions of dollars, with estimates around $50–70 million across all affected pools before partial fund recoveries. The episode highlighted systemic risk from shared tooling in DeFi: a low-level compiler bug, rather than a Curve-specific logic error, propagated to multiple high-value pools, prompting urgent user advisories to withdraw from vulnerable Vyper-based contracts and renewed scrutiny of smart contract language and compiler security across the ecosystem.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on Ethereum

Comments