OceanAltOceanAlt

Security incident · 2023-07-30

Curve DEX

According to the public DefiLlama incident dataset, Curve DEX (Ethereum) suffered a security incident on 2023-07-30, with about $61.7M reported lost.

Date2023-07-30
Reported loss$61.7M
ChainEthereum
Target typeDeFi Protocol
Technique classReentrancy
TechniqueVyper Compiler Bug
Bridge incidentNo
Within 2023#8 by loss that year, 3.8% of all reported losses that year

How this kind of attack works

The contract sent funds before updating balances, and the attacker re-entered during the transfer to withdraw repeatedly.

Would a pre-payment check have helped

Needs other controls

Reentrancy is a classic contract bug, unrelated to the counterparty; code audits address it.

Other incidents with the same technique

Sources

This page restates public reports and is not OceanAlt's judgment of any party. To report an error, email business@oceanalt.com; we review within 48 hours.

← Back to incidents