CryptoReal
CASE FILE — Mar 26, 2024

Curio's Ethereum Governance Contract Drained of $16M in Voting-Power Exploit

Curio, a project built to connect traditional finance and decentralized finance through tokenized real-world assets, saw roughly $16 million siphoned from its Ethereum-based governance contract over a spring weekend in March 2024.

On March 23, 2024, the CurioDAO Association confirmed that its voting protocol had been exploited through a smart contract derived from a fork of MakerDAO's codebase. The team was quick to note that the breach was confined to the Ethereum side of the ecosystem — the Polkadot side and the Curio Chain contracts were reported to remain untouched.

Security firm Hacken published a breakdown of how the attack unfolded. According to Hacken, the attacker used the "cook" function of a purpose-built attack contract to abuse the "IDSChief" and "IDSPause" contracts, combining governance manipulation with a mass token-minting scheme.

The mechanics: the attacker first bought up a modest amount of CGT, Curio's governance token — enough to inflate their voting weight inside the protocol's contract. By locking those tokens and casting votes, they secured enough control to trigger a delegate call into a malicious contract of their own design.

From there, the exploit went beyond simple minting and governance abuse. The attacker ran the freshly minted tokens through a series of swaps and cross-chain transfers, a pattern suggesting a deliberate attempt to spread the funds across multiple platforms and chains and obscure their trail.

The attacker's wallet — 0xdaAa6294C47b5743BDafe0613d1926eE27ae8cf5 — carried out the exploit in a transaction visible on-chain: 0x4ff4028b03c3df468197358b99f5160e5709e7fce3884cc8ce818856d058e106. A visual breakdown of the attack path is available via Metasleuth.

As of reporting, the attacker still held an estimated 996 billion CGT. Because the token trades with limited liquidity, pinning down the real value of that holding — and therefore the full scope of the loss beyond the headline $16 million — remains difficult.

On March 25, CurioDAO published a recovery plan built around two stages. First, the team will retire the vulnerable CGT token and issue a successor, CGT 2.0. Second, a compensation program tied to the paired asset in the affected liquidity pools will roll out across four consecutive 90-day stages.

The team also committed to patching the access-control flaw that allowed voting power to be manipulated, saying the fix would undergo rigorous testing before deployment. Beyond that immediate patch, Curio said it plans broader security upgrades — tighter access controls, a code audit, and additional validation layers meant to head off similar attacks in the future.

Notably, no public audit of Curio's contracts could be found, and the recovery plan itself suggests the team has largely been handling security internally, leaning on in-house expertise and general best practices rather than third-party review.

To help recover funds, CurioDAO is offering white hat hackers a share of anything retrieved — 10% of proceeds recovered during the first week, dropping to 5% thereafter, with the offer open through May 25.

Taken together, the incident cost Curio roughly $16 million and effectively forced the retirement of its original governance token, with CGT 2.0 and the staged compensation program positioned as the remedy. The attacker's continued hold on 996 billion CGT, combined with the multi-chain swaps already observed, leaves open the question of what happens to those funds next — and whether an in-house approach to security, rather than independent audits, was ever equal to the risk.

Curio
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.