{"id":55625,"date":"2023-07-31T04:01:14","date_gmt":"2023-07-31T08:01:14","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=55625"},"modified":"2023-07-31T04:38:51","modified_gmt":"2023-07-31T08:38:51","slug":"curve-finance-crv-token-tanks-16-due-to-defi-exploit","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/curve-finance-crv-token-tanks-16-due-to-defi-exploit\/","title":{"rendered":"Curve Finance (CRV) Token Tanks 16% Due to Defi Exploit"},"content":{"rendered":"\n<p>According to the initial report, the exploit in Curve Finance's Vyper programming language resulted in losses of<a href=\"https:\/\/coinscreed.com\/staging\/allianceblock-defi-project-experiences-multi-million-dollar-hack.html\" target=\"_blank\" rel=\"noreferrer noopener\"> <em>$24<\/em> million dollars.<\/a><\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/07\/CURVE-1024x576.jpg\" alt=\"\" class=\"wp-image-55627\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/07\/CURVE-1024x576.jpg 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/07\/CURVE-300x169.jpg 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/07\/CURVE-768x432.jpg 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/07\/CURVE-750x422.jpg 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/07\/CURVE-1140x641.jpg 1140w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/07\/CURVE.jpg 1200w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Curve Finance (CRV) Token Tanks 16% Due to Defi Exploit<\/figcaption><\/figure>\n\n\n\n<p>Curve DAO (CRV), the native cryptocurrency of one of the leading decentralized finance exchanges, has experienced a price collapse following a significant exploit on the DeFi platform caused by a programming language vulnerability.<\/p>\n\n\n\n<p>Like other DeFi projects in the cryptocurrency space, Curve Finance relies on various decentralized applications constructed on <a href=\"https:\/\/www.investopedia.com\/terms\/b\/blockchain.asp#:~:text=Blockchain%20is%20a%20type%20of,has%20been%20as%20a%20ledger.\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">blockchain technology<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a>. Curve tweeted on Sunday, July 30, that the vulnerability affected a specific variant of its Vyper programming language. It stated:<\/p>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-28f84493 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:100%\">\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><em>A number of stablepools (alETH\/msETH\/pETH) using Vyper 0.2.15 have been exploited as a result of a malfunctioning reentrancy lock. We are assessing the situation and will update the community as things develop. Other pools are safe.<\/em><\/p>\n<\/blockquote>\n<\/div>\n<\/div>\n\n\n\n<blockquote class=\"twitter-tweet\"><p lang=\"en\" dir=\"ltr\">PSA: Vyper versions 0.2.15, 0.2.16 and 0.3.0 are vulnerable to malfunctioning reentrancy locks. The investigation is ongoing but any project relying on these versions should immediately reach out to us.<\/p>&mdash; Vyper (@vyperlang) <a href=\"https:\/\/twitter.com\/vyperlang\/status\/1685692973051498497?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">July 30, 2023<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote>\n\n\n\n<p>Curve Finance provided additional clarification by underscoring the primary cause of the issue, which was the combination of the affected Vyper version and the use of pure ETH. In addition, they specified that crvUSD contracts and associated pools are unaffected.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-curve-finance-crv-exploit\">Curve Finance (CRV) Exploit<\/h2>\n\n\n\n<p>The Curve DAO (CRV) price experienced significant selling pressure following the disclosure of the exploit. At the time of publication, the CRV token is trading 16% lower at $0.6135 with a market valuation of $545 million.<\/p>\n\n\n\n<p>BlockSec, a corporation that verifies the security of crypto software, estimates that the hack has resulted in losses exceeding $40 million. According to Tarun Chitra, CEO of Gauntlet, a company that evaluates crypto risks, the perpetrator stole approximately $20 million worth of CRV (a crypto token) and a version of Ether (another cryptocurrency).<\/p>\n\n\n\n<p>After Uniswap, Curve Finance is the largest DeFi exchange. Aave, a decentralized lender, employs CRV as collateral. Additionally, Chitra from Gauntlet stated that they had not observed any indications of &#8220;bad loans&#8221; on the Aave platform due to the decline in CRV. <\/p>\n\n\n\n<p>According to <a href=\"https:\/\/www.coingecko.com\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CoinGecko <span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a>data, the value of Aave's token has decreased by roughly 4% over the past 24 hours.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>According to the initial report, the exploit in Curve Finance&#8217;s Vyper programming language resulted in losses of $24 million dollars. Curve DAO (CRV), the native cryptocurrency of one of the leading decentralized finance exchanges, has experienced a price collapse following a significant exploit on the DeFi platform caused by a programming language vulnerability. Like other [&hellip;]<\/p>\n","protected":false},"author":53,"featured_media":55627,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21,73],"tags":[15511,15512,15510],"class_list":["post-55625","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","category-defi-news","tag-crv-token","tag-curve-dao-2","tag-curve-finance-2"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/07\/CURVE.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/55625","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/53"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=55625"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/55625\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/55627"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=55625"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=55625"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=55625"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}