{"id":56077,"date":"2023-08-07T09:15:01","date_gmt":"2023-08-07T13:15:01","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=56077"},"modified":"2023-08-07T09:21:54","modified_gmt":"2023-08-07T13:21:54","slug":"curve-finance-offers-1-85m-bounty-for-crypto-thief","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/curve-finance-offers-1-85m-bounty-for-crypto-thief\/","title":{"rendered":"Curve Finance Offers $1.85M Bounty for Crypto Thief"},"content":{"rendered":"\n<p><a href=\"https:\/\/coinscreed.com\/staging\/curve-finance-crv-token-tanks-16-due-to-defi-exploit.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Curve Finance<\/a>, a DeFi platform hacked for over $60 million last week, has announced a public bounty of $1.85 million for anyone who can identify the hacker and help bring them to justice. The bounty comes after the hacker refused to return the stolen funds to Curve and mocked the project.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img fetchpriority=\"high\" decoding=\"async\" width=\"813\" height=\"457\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/08\/curve-finance-bounty.jpg\" alt=\"Curve Finance Offers $1.85M Bounty for Crypto Thief\" class=\"wp-image-56084\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/08\/curve-finance-bounty.jpg 813w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/08\/curve-finance-bounty-300x169.jpg 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/08\/curve-finance-bounty-768x432.jpg 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/08\/curve-finance-bounty-750x422.jpg 750w\" sizes=\"(max-width: 813px) 100vw, 813px\" \/><\/figure>\n\n\n\n<p>Curve Finance is a decentralized exchange that allows users to swap stablecoins and earn interest. On August 2, a hacker exploited the platform and used a flash loan attack to drain over <strong>$60 million<\/strong> worth of crypto from several pools. <\/p>\n\n\n\n<p>The hacker also targeted other DeFi projects that used Curve's pools, such as <a href=\"https:\/\/alchemix.fi\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Alchemix<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a> and<a href=\"https:\/\/jpegd.io\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"> JPEGd.<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>\n\n\n\n<p>Following the attack, Curve offered the hacker a <strong>10% bug bounty<\/strong> for returning the assets by August 6. Alchemix and JPEGd also supported the offer, which promised not to pursue any legal actions against the hacker if they cooperated. <\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">The deadline for the CRV\/ETH exploiter passes<a href=\"https:\/\/t.co\/VphQ0bfYr2\" target=\"_blank\">https:\/\/t.co\/VphQ0bfYr2<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> <a href=\"https:\/\/t.co\/x8LP9Tx4rs\" target=\"_blank\">pic.twitter.com\/x8LP9Tx4rs<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>&mdash; Curve Finance (@CurveFinance) <a href=\"https:\/\/twitter.com\/CurveFinance\/status\/1688221472815284224?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">August 6, 2023<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>The offer was meant to incentivize the hacker to return the funds and avoid further damage to the <a href=\"https:\/\/coinscreed.com\/staging\/crypto-industry-opposes-us-secs-defi-regulation-plan.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">DeFi ecosystem.<\/a><\/p>\n\n\n\n<p>However, the hacker only partially accepted the offer, <a href=\"https:\/\/etherscan.io\/tx\/0x0af1d34ec0bb67a99f0148863558e4c84804349415801874876a17f85e4290e1\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">returning some of the funds<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> to Alchemix and JPEGd, but not to Curve. <\/p>\n\n\n\n<p>The hacker also sent a message to the projects, claiming that they were not afraid of being caught and that they were smarter than all of them. <\/p>\n\n\n\n<p>The hacker said that they did not want to ruin the projects but that the money was insignificant to them.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-curve-s-public-hunt-for-the-hacker-announced\">Curve's Public Hunt for the Hacker Announced<\/h3>\n\n\n\n<p>As the deadline for the voluntary return of funds passed, Curve decided to take a different approach and announced a public bounty of <strong>$1.85 million <\/strong>for anyone who could identify the hacker in a way that led to a conviction in the courts. <\/p>\n\n\n\n<p>The bounty is equivalent to <strong>10% <\/strong>of the remaining exploited funds, currently worth about <strong>$18.5 million.<\/strong><\/p>\n\n\n\n<p>Curve stated that it would continue to pursue the hacker and that it would use all legal means to recover the funds and bring the criminal to justice. <\/p>\n\n\n\n<p>Curve also urged anyone with information about the hacker to contact them via their <a href=\"https:\/\/curve.fi\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">website<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> or <a href=\"https:\/\/twitter.com\/CurveFinance\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Twitter account.<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>\n\n\n\n<p>The bounty announcement was met with mixed reactions from the crypto community, with some applauding Curve's efforts and others doubting its effectiveness. <\/p>\n\n\n\n<p>Some also suggested that Curve should focus more on improving its security and auditing its code rather than chasing after the hacker.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">DeFi Platforms' Challenge<\/h3>\n\n\n\n<p>The Curve Finance hack is one of the latest incidents highlighting the challenges and risks facing the DeFi sector, which has grown rapidly in popularity and value in recent years.<\/p>\n\n\n\n<p>DeFi platforms aim to provide decentralized and permissionless alternatives to conventional financial services, such as lending, borrowing, trading, and investing.<\/p>\n\n\n\n<p>However, DeFi platforms are also susceptible to threats, such as <strong>smart contract bugs, flash loan attacks, oracle manipulation, and regulatory uncertainty. <\/strong><\/p>\n\n\n\n<p>According to <a href=\"https:\/\/www.defipulse.com\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">DeFi Pulse,<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> a website that tracks DeFi data, there have been over <strong>$500 million losses<\/strong> due to hacks and exploits in DeFi platforms since 2019.<\/p>\n\n\n\n<p>DeFi platforms are continuously working to enhance their security and resilience, as well as collaborating with external auditors and researchers. <\/p>\n\n\n\n<p>However, as long as there are vulnerabilities and incentives for hackers, DeFi platforms must remain vigilant and prepared for potential attacks.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Curve Finance, a DeFi platform hacked for over $60 million last week, has announced a public bounty of $1.85 million for anyone who can identify the hacker and help bring them to justice. The bounty comes after the hacker refused to return the stolen funds to Curve and mocked the project. Curve Finance is a [&hellip;]<\/p>\n","protected":false},"author":44,"featured_media":56084,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[73],"tags":[1514,11067,197,1496],"class_list":["post-56077","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-defi-news","tag-bounty","tag-curve-finance","tag-defi","tag-hack"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/08\/curve-finance-bounty.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/56077","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/44"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=56077"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/56077\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/56084"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=56077"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=56077"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=56077"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}