Curve Finance Recovers over 70% of Hacked Funds: Report
The hackers who exploited Curve Finance have returned 73% of the tokens stolen from the decentralized finance (DeFi) platform. So far, the amount of tokens returned is estimated at USD $53 million, according to a report...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
The hackers who exploited Curve Finance have returned 73% of the tokens stolen from the decentralized finance (DeFi) platform. So far, the amount of tokens returned is estimated at USD $53 million, according to a report by a blockchain data analytics platform.
About a week ago, Curve Finance, the DeFi platform for stablecoins, was exploited through a reentrancy bug on its smart contracts programming language, Vyper. This action led to price volatility in CRV, the native token of the DeFi platform. Additionally, it prompted the cryptocurrency exchange, Upbit to suspend deposits and withdrawals of the token.
"A number of stablepools (alETH/msETH/pETH) which are using Vyper 0.2.15 have been exploited as a result of a malfunctioning reentrancy lock," a representative from Curve Finance stated. "We are assessing the situation and will update the community as things develop."
White Hat Hackers?
However, according to a post by PeckShield on X social media platform, ethical hackers are beginning to return the spoils. All the tokens, worth USD $22 million, stolen from the lending protocol AlchemixFi have reportedly been returned. This amount comprises 7,258 Ether and 4,821 Alchemix Ether.
On top of that, a trading bot has returned 90% of the tokens worth USD $11.5 million stolen from Jpegd. Similarly, tokens worth USD $6 million and USD $13 million have been recovered, which were stolen from the synthetic protocol Metronome and Curve trading pool, respectively.
Curve Finance’s Bug Bounty
On August 3, the exploited protocols, Curve, Metronome, and Alchemix, announced a bug bounty to incentivize hackers to return the stolen funds. In the statement on Etherscan, the platforms said: "We are offering a 10% bounty of any stolen funds, which are yours to keep if you return the remaining 90%."
Finance Magnates reported that Curve was exploited through a type of attack known as Reentrancy. This vulnerability allows codes from malicious third parties to be executed within a smart contract. Thus, hackers are able to make repeated calls to a blockchain platform and siphon funds.
This article was written by Jared Kirui at www.financemagnates.com.Why this matters
This security story adds another data point to the current market tape and is useful when read alongside nearby source coverage.
Original source
Read on Finance MagnatesRelated market context
BitMart Proposes Court-Backed Plan Offering Users Payouts or Tokens Tied to Its 2021 Hack
BitMart has published a preliminary plan for repaying its users, more than two months after the crypto exchange began winding down...
Florida judge orders Fundsz promoters to pay over $30 million in crypto fraud case
The ruling highlights the critical need for stringent oversight in crypto markets to protect investors and deter fraudulent scheme...
Bitcoin ETFs’ 9-day, $3 billion inflow streak comes to an end as $149 million exits the funds
Meanwhile, U.S. spot Ethereum ETFs saw $59.6 million in net outflows on Wednesday, led by $26.6 million exiting Fidelity's FETH fu...
Dogecoin Gets an EVM App Layer for DeFi and Games as DogeOS Opens Its Public Testnet
DogeOS, an application layer for Dogecoin built by the team behind the MyDoge wallet, opened its public testnet on Wednesday, givi...
CFTC secures over $30 million judgment against defendants in Fundsz fraud case
The CFTC secured a win in court after the agency said two defendants participated in a crypto scheme that they then tried to walk...
Aave’s $50 million lending plan could lose money without a single default
Aave’s proposed institutional lending business would put crypto collateral on both sides of the financing chain. Institutions woul...