Cointime

扫码下载App
iOS & Android

Rising from the Ashes: How Curve Finance's Unbreakable Spirit Triumphed Over a $73 Million Hack

August 7, 2023

Author: CryptoSherry

In a saga reminiscent of mythic rebirth, the realm of decentralized finance (DeFi) witnessed a dramatic upheaval as Curve Finance, a stalwart of the ecosystem, faced a venomous attack that slashed deep into its foundations. Symbolizing a serpent's transformation, the hack uncovered vulnerabilities that sent shockwaves through DeFi, but from the ashes of chaos emerged a story of unwavering resilience and redemption.

Emergence of the Venom: Unveiling the Sinister Vyper Exploit and its Devastating Impact

As if guided by fate, a sinister 0-day exploit targeted the very heart of Curve Finance on a fateful day, much like a snake's deadly bite. The malicious strike, a flaw entrenched within the Vyper programming language, unleashed a ripple effect that echoed across the entire DeFi landscape, inflicting a staggering $73 million blow. The breach jolted the community, rattling trust in Curve Finance and casting a looming shadow over the interconnected web of DeFi protocols. The incident's genesis traced back to a fundamental weakness in the Vyper programming language. Versions 0.2.15, 0.2.16, and 0.3.0 harbored vulnerabilities that made specific smart contracts susceptible to re-entrancy attacks. Capitalizing on these shortcomings, attackers exploited the protocols, manipulating balance calculations and draining funds from affected liquidity pools. The lurking danger went unnoticed, resulting in the exploitation of assets worth $73 million. Among the hardest hit were Curve Finance's own pools, as well as those of JPEG'D, Alchemix, and Metronome.

Curve Finance's Resilience: Innovating Amidst Unprecedented Crisis

In the aftermath of the exploit, an unparalleled battlefield unfolded as whitehat hackers clashed with blackhat exploiters on-chain. Whitehats were unrelenting in their efforts to recover stolen funds, while blackhats sought to exploit value from the compromised pools. In the midst of this chaos, Curve Finance's founder, Michael Egorov, and his team unveiled a groundbreaking response—a bug bounty program extended as an olive branch to the hackers. This audacious move aimed to quell the crisis and reinstate stability by proposing a bold arrangement: a 90% fund return in exchange for a 10% reward. At this moment, based on data from PeckShieldAlert, 73% of the overall amount ($52.3M) has been reimbursed. The remaining value of $19.7M in Ethereum-linked cryptocurrencies has not been returned by the original exploiter of Curve's CRV-ETH pool (address: 0xb752…b324).

Amid worries of potential liquidation risks from Michael's significant CRV collateral across platforms like Aave, quick actions were taken. To avert on-chain liquidation, Curve's founder initiated the sale of 114.025 million CRV to 24 investors via OTC methods, securing $45.61 million. This safeguarded the CRV token from a looming fate.

In the array of lending protocols, one position stood out: Micheal’s Fraxlend loaning. With a $17 million loan and $24 million collateral, it approached almost complete 100% utilization. Fraxlend's setup triggers an automatic interest rate increase, doubling every 12 hours when at full 100% utilization. If left unchecked, this mechanism could have led to exceedingly high APY percentages and potential liquidation.

In a remarkable twist, Michael introduced an innovative gauge—a pioneering initiative rewarding CRV to those who LP’d crvUSD with fFRAX for CRV/FRAX, the receipt token for FRAX lending in the Fraxlend CRV pair. This inventive gauge aimed to incentive FRAX lending, effectively lowering CRV/FRAX utilization.

Embracing a New Dawn: DeFi's Resilience in the Face of Adversity

As the dust settled, contemplation dawned. The events surrounding Curve Finance's triumphant recovery underscored the transformative power of decentralized technologies. While vulnerabilities serve as stark reminders of the ever-evolving nature of DeFi, the ability to adapt, innovate, and unite against adversity remains a hallmark of the industry. DeFi enthusiasts around the world, buoyed by this tale of resilience, continue to champion a future where decentralized finance reshapes the financial landscape with unyielding determination.

评论

所有评论

推荐阅读

  • 比特币矿企Phoenix Group公布Q1财报:净利润6620万美元,同比增长166%

    比特币上市矿企和区块链技术提供商Phoenix Group公布Q1财报,主要内容如下:

  • Pudgy Penguins与乐天战略合作拟拓展韩国市场,地板价7日涨幅3.1%

    NFT 系列“胖企鹅”Pudgy Penguins 近日在 X 平台宣布与韩国零售和娱乐巨头乐天集团(Lotte Group)建立战略合作伙伴关系,以扩大其在韩国及周边地区的市场,后续将公布更多信息。CoinGecko 数据显示,Pudgy Penguins 地板价暂报 11.8 ETH,7 日涨幅为 3.1%。

  • CryptoPunks推出“Super Punk World”数字化身系列

    蓝筹NFT项目CryptoPunks在X平台宣布推出“Super Punk World”,这是该项目首次推出的500个数字化身,灵感来自于标志性的 CryptoPunks 特征与 Super Cool World 属性相结合,据悉该系列后续或将启动拍卖,有关该系列的收藏和拍卖更多细节将很快公布。

  • 灰度GBTC截至5月17日AUM重返190亿美元上方,持仓较前一日增加约59枚BTC

    灰度官方数据显示,截至当地时间5月17日,其现货比特币交易所交易基金GBTC 持有288,954.3969枚 BTC,较前一交易日增加 59.3288枚BTC。 此外,GBTC 的资产管理规模(非公认会计原则)升至19,373,184,484.83美元,流通份额小幅上涨到324,810,100份。

  • Core基金会推出500万美元创新基金

    据CoreDAO在X平台发文称,Core基金会宣布推出500万美元创新基金,该基金目前主要面向印度市场,并且和孟买联邦理工学院以及与一些头部风险投资公司达成战略合作伙伴关系,以支持该国发展创新区块链项目,现阶段该基金已开放项目资金申请。

  • Drift基金会:治理机制正逐步完善,DRIFT系组成部分之一

    Drift 基金会在 X 平台发文表示,DRIFT 代币是治理的一个组成部分,也是赋予社区塑造未来的关键。治理机制正在逐步完善,即将公布更多信息。与此同时,用户可在以下 Solana 生态项目中存入 DRIFT:在 Drift Protocol 存款(将在未来的治理举措和计划中得到承认)、通过 Meteora DLMM 池提供流动性、Kamino 的 DRIFT - JitoSOL vault、marginfi、SolBlaze 多个流动性池等。此前消息,DRIFT 代币空投申领已上线,拟于 8 月 17 日凌晨 2 点结束。

  • 证券时报:DDO数字期权在海外已涨到80美元仍在猖狂销售

    据证券时报披露,鼎益丰办公楼已经全部搬空,所在楼层贴满了关于数字期权DDO的风险告示,目的就是为了警示投资人鼎益丰的数字期权涉嫌违法。记者在现场获取的《鼎道数字期权认购协议书》中看到,每个DDO价值为1美元。投资人此前到期未兑付的合同金额将会重新安排签署新的协议书,即将此前持有的“原始股”股权平移至鼎道数字期权,可持有同等金额的DDO数字代币。 目前DDO数字期权上市交易地在新加坡,鼎益丰一部投资经理古明(化名)称价格从最初的1美元已经上涨到80美元,之前签署平移的投资者全都赚到了,已经涨了很多倍。现在仍然有很多投资者想要投资DDO,客户数量已经达到新高。此前深圳地方金融管理局发布风险提示公告,指出鼎益丰名义开展的有关DDO数字期权业务活动,本质上为虚拟货币的发行、交易行为,属非法金融活动,涉嫌非法集资等行为。

  • 众安当选香港银行公会虚拟银行委员会主席并加入数字人民币跨境试点

    香港金融管理局(金管局)与中国人民银行(人民银行)在数字人民币跨境支付试点领域的合作取得新进展,众安银行宣布当选香港银行公会虚拟银行委员会主席,任期两年,此外众安银行已加入数字人民币跨境试点。 此前香港金管局发起咨询“虚拟银行”将计划更名为“持牌数字银行”,随着粤港澳大湾区的互联互通加速,香港数字银行或将发挥出数字金融优势,为居民提供高效金融服务 。

  • Vitalik:区块链社区扩展不因局限于行业内部,而应着眼于更广泛的外部领域

    5月18日消息,Vitalik Buterin在X平台回应其他用户时表示,扩展是好事,但为什么只能是其他区块链呢?为什么不能是非区块链去中心化空间,还有开源生物技术等等这些领域。 我宁愿看到五个不同的区块链社区更广泛地扩展他们的兴趣,而不是一个内部凝聚力很强,但外部没有任何理解或影响的单一‘加密社区’。

  • 香港金管局正与内地着手研究数字人民币P2P转账技术安排

    香港金管局昨日扩大数字人民币在香港的跨境试点,金管局副总裁李达志指出,数字人民币钱包不是一般的电子钱包,这等同于大家拿着人民币的现钞,目前只能用于零售支付用途,不能用作个人之间(即P2P)转账。 金管局助理总裁(金融基建)鲍克运表示,日后如要推行P2P转账,前提是要落实实名认证安排,此外也有其他法规考虑,金管局与内地正着手研究相关的技术安排。