CryptoReal
CASE FILE — Jul 31, 2023

Vyper Compiler Bug Drains $69M Across Curve and Dependent Protocols

Curve Finance re-entered the leaderboard of major DeFi losses on July 30, 2023, with a figure roughly 100 times larger than its earlier appearance tied to a 2022 DNS hijack.

Across the affected pools, total losses reached $69 million, spread across several protocols that rely on Curve for liquidity in their ETH-pegged assets:

  • JPEG'D lost $11.5M from its pETH/ETH pool.
  • Alchemix lost $20.5M from its alETH/ETH pool, though $11.5M of that was subsequently recovered.
  • Metronome lost $1.6M from its msETH-ETH pool; the attack transaction was frontrun by the MEV bot 0xc0ffeebabe.
  • Curve's own CRV/ETH pool lost $24.2M, with $5.4M of that also frontrun by 0xc0ffeebabe, who promptly returned the funds.
  • Smaller losses hit dBridge ($25k, from dormant LPs that had not migrated) and the BSC-based Curve fork Ellipsis ($69k).

PeckShield flagged the JPEG'd exploit first. Once Alchemix was hit as well, the wider DeFi community began to take notice. Early speculation — including an initial, dismissive assumption from Curve itself — pointed to yet another instance of the read-only reentrancy bug that had troubled the sector for months, but that assumption did not hold up, and Curve's tweet suggesting as much was deleted once the true scope became apparent.

As the picture became clearer, Curve stated that only the alETH, msETH and pETH pools were affected, adding: "Other pools are safe." That reassurance didn't hold for long — Curve's own CRV/ETH pool was subsequently drained as well, for a reported $24.3M.

Credit for piecing together the cause goes to Vyper, Ancilia, Chaofan Shou, and Tayvano.

The initial suspicion was the same read-only reentrancy issue that had already damaged several protocols in recent months, including Conic Finance and EraLend. This time, however, the vulnerable contracts weren't external projects consuming a Curve pool as a price oracle — the Curve pools themselves were the target.

The actual root cause turned out to be a zero-day bug in the compiler for certain older versions of Vyper, the language used to write Curve's contracts. Specifically, a misalignment between storage slots used by two functions — add_liquidity and remove_liquidity — broke the nonreentrant guard meant to prevent exactly this scenario. That flaw let the attacker(s) re-enter a transaction between the two calls, manipulate LP token prices, and drain the pool.

Any pool holding native ETH and compiled with Vyper versions 0.2.15, 0.2.16, or 0.3.0 was exposed. The bug had existed since 2021 and was apparently fixed by chance in version 0.3.1, since no deliberate remediation had been undertaken at the time.

Sums referenced in this case file

Attacker addresses and transactions:

Even without a proven method of exploiting it, Curve recommended that users withdraw from the Tricrypto pool on Arbitrum as a precaution. By contrast, the stETH/ETH pool, holding more than $400M in TVL despite running an older Vyper version, was confirmed unaffected.

While the situation unfolded, whitehat actors scrambled to secure at-risk funds, though they were repeatedly beaten to it by the attackers. Even so, around $17 million was ultimately saved, and the Metronome-related funds appeared likely to be returned, with 0xc0ffeebabe having already set aside 1,000 ETH in a transaction toward that end.

Not everyone was satisfied with how the response played out. Some in the community criticized what they viewed as premature disclosure of the vulnerability — specifically naming the at-risk version numbers — while mitigation efforts were still underway. BlockSec drew criticism for reaching out to Curve publicly over Twitter, but the firm maintained it had done so only after all exploitable pools had already been drained. Curve contributor banteg summed up the frustration bluntly: "you don't tweet live vulns before they are fully mitigated."

The affected tokens took a hit in the aftermath: JPEG fell as much as 45% before settling around -20%; pETH dropped as much as 85% before settling near -40%; ALCX fell under 10%; alETH dropped roughly 20%; and CRV was down about 15% at the time of writing, having touched a low of $0.60.

CRV's price mattered beyond the exploit itself because of Curve founder Michael Egorov's own financial position. Although the attacker had not, at that point, dumped the CRV obtained from the exploit onto the open market, the possibility worried observers given how leveraged Egorov's holdings were. He had reportedly borrowed a combined $107.2 million in stablecoins against $284 million worth of CRV collateral, spread across multiple DeFi lending platforms. A sufficiently large CRV price decline threatened a liquidation cascade that could have compounded the damage well beyond the exploit itself. Setting aside debate over whether the underlying incentives were healthy, Egorov appeared to be actively managing the exposure, though he remained under pressure from rising interest costs.

Some traders — MEV bots among them — profited from the disorder, including notable MEV block rewards captured during the chaos, and were subsequently encouraged to return funds voluntarily — an appeal reportedly made by the alETH attacker themselves, read by some as a hint that funds might eventually be returned to Alchemix.

Curve stated plainly that the other affected protocols bore no fault, though where responsibility ultimately lies is less clear-cut. A compiler-level bug of this kind is unsettling for the whole ecosystem, since it sits beneath the layer that any individual protocol audit would typically examine.

The incident does highlight one strength of the space: the open, transparent way such incidents get dissected in public, a contrast noted with how comparable failures unfold in traditional finance. It also exposes a blind spot — most security attention in the industry goes toward Solidity, leaving a Vyper-level flaw like this one undetected for years before it was finally exploited. Part of the issue may be incentive-driven: auditing individual projects pays well, but that work generally assumes the underlying language is sound, and with no token tied to the language itself, funding for scrutiny of that base layer tends to lag. With 59 contracts reportedly exposed to this bug, the risk of a comparable flaw surfacing in Solidity — given its far larger footprint — is not trivial.

This attack also stood out for its method. Rather than settling for smaller gains from the well-known read-only reentrancy pattern, the attacker(s) dug into a much deeper layer of the stack to find an opening — a level of persistence that has drawn comparisons to the patience associated with state-sponsored hacking groups. It's equally possible the bug was found by accident, since it's hard to reconcile painstaking research into such a deeply buried flaw with the fact that the exploit ultimately got frontrun during execution.

Either way, the episode is being read as a prompt to rethink priorities. Larger protocols with substantial treasuries — and correspondingly large amounts to lose — may find it worthwhile to fund in-house specialists focused on maintaining and researching core infrastructure. Whether that investment materializes is another question, given that capital in the space tends to gravitate toward speculative upside rather than the unglamorous work of hardening foundational tooling.

CurveVyper
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.