The incident refers to a specific episode during the July 30–31, 2023 Curve/Alchemix/Metronome exploits, where one of the Alchemix-related exploit addresses tried to present themselves as a whitehat and sent an on‑chain message to a trader who had accidentally made a very profitable trade against the compromised pool. On July 30, 2023, several Curve Finance pools using vulnerable Vyper compiler versions were exploited, including the alETH–ETH pool used by Alchemix, leading to tens of millions of dollars drained across Alchemix, Metronome, and JPEG’d. Multiple attacker-controlled addresses began interacting with the affected pools. In the chaos, at least one independent trader managed to turn 5 ETH into roughly 1,200 alETH by trading against the mispriced, partially drained Alchemix pool, effectively arbitraging the exploit conditions rather than initiating the exploit itself (this trade and its size were highlighted by on‑chain analysts on Twitter/X, including @spreekaway, using Etherscan traces of the Curve alETH pool). Subsequently, one of the exploit-linked addresses posted an on‑chain message claiming to be a whitehat and directed a note to that trader, suggesting that the trader should return the windfall profits and implying those funds were part of the rescued/exploited capital. The message appeared in the broader context of public negotiations where Alchemix, Curve, and Metronome offered exploiters 10% as a bounty in exchange for returning 90% of stolen funds, and at least one exploiter later did return about 4,820 ETH (~$9 million) to Alchemix’s multisig. The exchange with the 5 ETH → 1,200 alETH trader illustrates the blurred line between actual whitehat recovery efforts, blackhat exploitation, and opportunistic third‑party trading in DeFi incidents, and raised questions about who is entitled to abnormal profits generated during an exploit-driven market dislocation.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on Ethereum

Comments