The story refers to the 2023 Curve Finance exploit, in which a vulnerability in the Vyper smart contract language used by several Curve-related liquidity pools led to tens of millions of dollars in losses across DeFi projects including Alchemix and JPEG’d. After the attack, the exploiter began returning funds in stages and, in the case of JPEG’d and Alchemix, recovered most or all of the stolen assets in exchange for a negotiated bounty and assurances that the projects would not pursue legal action if the remaining funds were returned. For JPEG’d, the returned amount was about 5,494–5,495 WETH, with the hacker receiving roughly a 10% bounty of about 610.6 ETH. Alchemix reported the return of 4,820.55 alETH plus 2,259 ETH, and the funds’ return was accompanied by an on-chain message claiming the motive was to avoid harming the project rather than fear of identification. Curve later shifted from a private return offer to a public bounty for information leading to the hacker’s identification after the deadline passed without a full return to Curve itself.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on Ethereum

Comments