CryptoReal
CASE FILE — Jul 25, 2023

Conic Finance Loses $4.2M in Back-to-Back Curve Pool Exploits

Lightning does strike twice. Conic Finance was hit by two separate exploits on the same Friday, losing a combined $4.2 million across its ETH and crvUSD omnipools.

Conic's omnipools work by accepting single-asset deposits and then spreading that capital across a variety of Curve pools so depositors can earn LP rewards.

News of the first attack, which drained $3.3 million from the ETH omnipool, prompted a quick acknowledgment from the Conic team. After a second incident followed, the project opted to shut down every pool entirely.

The first exploit relied on the same read-only reentrancy flaw that has repeatedly plagued DeFi over the past year, previously surfacing at Sturdy Finance, Midas Capital, and dForce Network, among others.

Notably, both exploit transactions were themselves frontrun. In the second incident, the party who intercepted the funds — an MEV botreturned 90% of its gains (81 ETH) the following day.

The bulk of the funds taken in the first attack — over 1,700 ETH — remains sitting in the wallet belonging to that exploit's frontrunner, leaving some possibility that the funds could eventually be recovered. That optimism is tempered by the fact that BlockSec had already flagged the same address as the "LadyPepe Token Exploiter" prior to this incident.

(Technical credit: BlockSec and Conic Finance's post-mortem.)

Mechanically, the first attack manipulated token pricing through the well-documented read-only reentrancy pattern. Security researcher pcaversaccio summarized the mechanism as follows:

TL;DR: Due to a read-only reentrancy vulnerability in the oracle contract CurveLPOracleV2, the attacker can reenter rETH-f.totalSupply() (and other tokens like steCRV) and thus can manipulate the prices accordingly. Thus, the attacker can withdraw more than deposited.

A more thorough technical walkthrough is available in Daniel Von Fange's thread.

Auditing firm Peckshield noted that its original audit report had actually flagged a comparable read-only reentrancy concern — but the vulnerable CurveLPOracleV2 contract was introduced afterward, outside the scope of that review:

FWIW, our audit identifies a similar read-only reentrancy issue. However, the same issue is introduced in the newly introduced CurveLPOracleV2 contract, which was not part of the audit scope.

Sums referenced in this case file

Conic developer 0xWicket later explained that reentrancy protection did technically exist in the contract but failed to trigger because of a mix-up between the ETH placeholder address and the WETH token address:

We are currently in the process of writing a post-mortem. The root cause of this being exploitable was our assumption that ETH was treated as address 0xeee... by Curve, while it uses the the WETH address for V2 pools. Our reentrancy protection failed to trigger because of that

First attack — addresses and transactions:

The second exploit was structurally simpler and financially far less severe, though it did significant damage to Conic's credibility. Per Conic's own post-mortem, it amounted to a form of sandwich attack against imbalanced pools, executed via a repeated loop:

Exchange crvUSD to USDC in the Curve pool

Deposit crvUSD into Conic

Exchange USDC to crvUSD in the Curve pool

Withdraw from Conic

Repeat steps above

The post-mortem elaborated:

The attacker would benefit from the exchanges in the Curve pool by exchanging at a favorable rate. While we did have some mechanism in place to ensure we did not interact with imbalanced Curve pools, the bounds that we had set were not tight enough and allowed the attacker to slowly drain funds from the pool.

A total of approx. $934,000 was stolen from the crvUSD Omnipool, giving the attacker a profit of approx. $300,000.

Second attack — addresses and transactions:

Beyond Conic itself, the wider Curve ecosystem felt the fallout. The Curve team stepped in to warn users of the risk and pointed liquidity farmers toward safer alternatives.

Before this incident, Conic had been among the most anticipated DeFi launches earlier in the year, with some commentators suggesting it could become this cycle's answer to CVX or Yearn.

CNC, the project's token, had been trading around $6 before the hack. The first exploit triggered a roughly 35% price decline, and the token fell further to just $1.72 after the second attack. It has since stabilized near $2.75 — still less than half its pre-incident value.

The TVL data tells a similar story, with less than a third of Conic's pre-hack total value locked remaining after Friday's events.

Whether a protocol that entered the year with such high expectations can recover from being hit twice in a single day remains to be seen.

Conic Finance
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.