Ultimate magazine theme for WordPress.

Attackers steal $24 million from multiple DeFi projects in Curve Pool exploits

Several decentralized finance protocols were attacked on Sunday by attackers who stole more than $24 million worth of cryptocurrencies. The attackers exploited a vulnerability in liquidity pools on Curve, the automated market maker platform.

According to Curve on Twitter, the vulnerability was traced to Vyper, a third-party alternative programming language for Ethereum smart contracts. Curve said other liquidity pools that don't use the language are fine.

A number of stable pools (alETH/msETH/pETH) using Vyper 0.2.15 were exploited due to a faulty reentry lock. We are assessing the situation and will inform the community about further developments.

Other pools are safe. https://t.co/eWy2d3cDDj

— Curve Finance (@CurveFinance) July 30, 2023

Liquidity pools are smart contracts that hold tokens and can provide liquidity to crypto markets in a way that does not rely on financial intermediaries. But as several projects learned Sunday, a small mistake can result in significant losses.

According to a decentralized financial security firm, $11 million worth of cryptocurrency was stolen from the NFT lending protocol JPEG Decurity. JPEG'd was among the first to identify a problem with its pool on Curve.

“There was an attack,” JPEG wrote said on twitter. “We addressed the issue as soon as it was brought to our attention […] The problem seems to be related to the curve pool.”

JPEG'd allows users to deposit NFTs as collateral for loans. In terms of assets deposited in JPEG, the protocol has one Total value locked (TVL) of around $32 million. JPEG said the code responsible for custody of NFTs and government funds would not be affected.

According to data from CoinGecko, the protocol’s governance token JPEG was down 23% as of this writing. On Sunday, the coin hit an all-time low of $0.000347.

The story goes on

In a now-deleted tweet, Curve initially described the vulnerability as a common, read-only “re-entry” attack that could have been avoided. A reentry attack occurs when a smart contract interacts with another contract, which in turn relies on the first contract before full execution.

Reentry vulnerabilities allow an attacker to pack multiple calls into a single function and cause a smart contract to calculate false balances. One of the most famous examples of this was this $55 million DAO 2016 Hack on Ethereum.

However, Curve responded to a Twitter account that later repeated the deleted statement saying its first impression was wrong.

“Yes, not read-only,” Curve said, adding that there was “no wrongdoing on the part of the projects that integrated or even the users of Vyper.”

Yes, not read-only. No wrongdoing on the part of the projects that integrated here, or even the users of Vyper

— Curve Finance (@CurveFinance) July 30, 2023

Reentry attacks are an all-too-common vector for attackers to steal protocols, said Meir Dolev, co-founder and CTO of cybersecurity firm Cyvers Decipher.

“They’re pretty common,” Dolev said. “And it is possible to avoid them through proper design and development.”

The problem wasn't specific to JPEG. Not long after the NFT lending protocol was exploited, Alchemix and Metronome DAO similarly lost $13.6 million and $1.6 million, respectively, he said.

Alchemix accepted on Twitter that it was actively working to resolve an issue with its liquidity pool. MetronomeDAO said On Twitter, the investigation into the incident is still ongoing and describes the attack as “part of a broader series of exploits.”

In the case of JPEG, the attacker was attacked by a Maximum Extractable Value (MEV) bot, Dolev said. The bot identified the potential attacker's transaction and paid a fee to execute a similar transaction in front of him.

Vyper said on Twitter that the programming language's compiler was down. When a developer finishes writing the code, it is compiled from a human-readable format into a form that computers can run.

This prevented reentry guards — protections included in the project's code that were intended to protect against reentry attacks — from working, Dolev said.

“In some versions, the compiler couldn’t compile it correctly,” Dolev said. “There are some errors or failures.”

Learn Crypto Trading, Yield Farms, Income strategies and more at CrytoAnswers
https://nov.link/cryptoanswers

Comments are closed.

%d bloggers like this: