CryptoReal
CASE FILE — Feb 13, 2023

Read-Only Reentrancy Strikes Again as dForce Loses $3.65M Across Two L2s

dForce Network suffered a combined $3.65 million loss in a coordinated attack that hit its deployments on both Arbitrum and Optimism simultaneously.

The strike began just after 11pm UTC on a Thursday, when an attacker exploited the same reentrancy flaw on both chains in quick succession — draining roughly $1.9 million from the Arbitrum deployment and $1.7 million from Optimism.

Outside observers flagged the activity first, with dForce acknowledging the breach about an hour and a half afterward. In a follow-up statement, the team said all vaults had been paused and assured users:

Users' funds supplied to dForce Lending and other vaults are SAFE.

The situation improved days later when the attacker sent back the entire haul to dForce's multisig wallets.

Notably, this is not a novel exploit class — the same read-only reentrancy issue was recently behind the Midas Capital incident, and before that hit Market.xyz. As was noted in coverage of the Midas case, reporting on losses tied to a previously documented issue is particularly frustrating — raising the question of how much more DeFi capital this bug will claim before it's fully stamped out.

Credit for tracking the incident goes to SlowMist and Peckshield.

Mechanically, the attacker used flash-loaned capital to deposit into Curve's wstETH/ETH pool, then placed the resulting LP tokens into dForce's wstETHCRV-gauge vault. By invoking the pool's remove_liquidity function, the attacker's contract was able to exploit the reentrancy gap to distort the virtual price — a value dForce relies on as an oracle input for pricing wstETHCRV-gauge tokens. That manipulated price then let the attacker profit by liquidating other users whose positions were collateralized with wstETHCRV-gauge tokens.

Sums referenced in this case file

Exploiter address (active on Optimism, Arbitrum, and Ethereum): 0xe0d551017c0111ac11108641771897aa33b2817c

Optimism attack transaction: 0x6c197621…

Arbitrum attack transaction: 0x5db5c240…

This vulnerability class has been documented for close to a year. ChainSecurity's post-mortem report states that on April 14 (2022), the firm warned Curve and affected integrators about a read-only reentrancy issue in certain Curve pools, specifically noting that the output of get_virtual_price could be manipulated by reentering the function during a liquidity removal.

Curve had already published a mitigation: calling any function protected by the nonreentrant lock — with removing zero liquidity being the cheapest option — closes the gap.

Tracing the attacker's funding: the Ethereum mainnet address was seeded via Railgun, and from there the Optimism and Arbitrum addresses were funded through Synapse.

In an effort to recover funds, dForce sent bounty offers embedded in transaction input data directly to the attacker on both chains (Optimism tx, Arbitrum tx). The attacker eventually responded, and days later dForce confirmed that the stolen funds had been returned to its multisigs, adding that affected users would be made whole and that details of the reimbursement process would follow shortly.

This is far from dForce's first brush with disaster. Long before rekt.news existed — back in April 2020 — dForce lost $25 million to an exploit targeting an ERC-777 token flaw, with affected users reportedly made whole a few days after that incident too.

Zooming out, this attack lands amid a broader surge in Layer 2 adoption. Optimism remains the only major Ethereum L2 with its own token among the leading networks, and OP's recent all-time high reflects that growing traction. Increased usage and rising TVL, however, inevitably draw the attention of bad actors looking to cash in. Airdrop farmers have become a fixture across these networks — mostly benign, if opportunistic. But speculators chasing token distributions aren't the only ones circling L2 ecosystems in search of the next opportunity.

L2-specific incidents have so far been relatively rare compared to mainnet — prior examples include the Wintermute, Lodestar, and Treasure DAO cases — but that count is expected to climb as more attackers turn their attention to these environments. This dForce incident is unlikely to be the last L2-related entry to land on the leaderboard.

ArbitrumOptimismdForce Network
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.